Записи Netgate
59 опубликованных записей вендора netgate.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 5,1 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 5,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')27
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-428 Unquoted Search Path or Element2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
59 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
67На этой неделе | CVE-2022-31814Готовый эксплойт | pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Hnetgate · pfblockerng · CWE-78 | Критическая9,8 | — | 91,9 % | 5 сент. 2022 г. |
62На этой неделе | CVE-2023-27253Готовый эксплойт | A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbinetgate · pfsense · CWE-91 | Высокая8,8 | — | 89,5 % | 17 мар. 2023 г. |
55В плане | CVE-2023-48123Proof of concept | An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a craftenetgate · pfsense | Высокая8,8 | — | 67,8 % | 6 дек. 2023 г. |
54В плане | CVE-2023-42326Proof of concept | An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php netgate · pfsense · CWE-77 | Высокая8,8 | — | 64,0 % | 14 нояб. 2023 г. |
51В плане | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Средняя5,9 | — | 93,3 % | 18 дек. 2023 г. |
51В плане | CVE-2019-16667Proof of concept | diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands.netgate · pfsense · CWE-352 | Высокая8,8 | — | 54,5 % | 26 сент. 2019 г. |
50В плане | CVE-2018-4021Эксплойта нет | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POSnetgate · pfsense · CWE-78 | Высокая7,2 | — | 72,2 % | 3 дек. 2018 г. |
47В плане | CVE-2015-2295Proof of concept | Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remotenetgate · pfsense · CWE-352 | Средняя6,8 | — | 65,7 % | 10 апр. 2015 г. |
45В плане | CVE-2017-1000479Готовый эксплойт | pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrarnetgate · pfsense · CWE-352 | Высокая8,8 | — | 31,7 % | 3 янв. 2018 г. |
43В плане | CVE-2024-46538Proof of concept | A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payloadnetgate · pfsense · CWE-79 | Средняя4,8 | — | 81,6 % | 22 окт. 2024 г. |
43В плане | CVE-2018-4019Эксплойта нет | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POSnetgate · pfsense · CWE-78 | Высокая7,2 | — | 48,7 % | 3 дек. 2018 г. |
43В плане | CVE-2018-4020Эксплойта нет | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POSnetgate · pfsense · CWE-78 | Высокая7,2 | — | 48,7 % | 3 дек. 2018 г. |
42В плане | CVE-2022-29273Эксплойта нет | pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.netgate · pfsense · CWE-79 | Средняя6,1 | — | 59,6 % | 22 февр. 2023 г. |
42В плане | CVE-2019-12347Proof of concept | In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accounnetgate · pfsense · CWE-79 | Средняя6,1 | — | 58,6 % | 29 мая 2019 г. |
42В плане | CVE-2023-27100Proof of concept | Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CEnetgate · pfsense plus · CWE-307 | Критическая9,8 | — | 9,8 % | 22 мар. 2023 г. |
41В плане | CVE-2019-16701Proof of concept | pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shnetgate · pfsense · CWE-78 | Высокая8,8 | — | 19,6 % | 25 сент. 2019 г. |
41В плане | CVE-2019-12585Эксплойта нет | Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_statusapcupsd · apcupsd · CWE-78 | Критическая9,8 | — | 5,0 % | 2 июн. 2019 г. |
40В плане | CVE-2019-8953Proof of concept | The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_lisnetgate · haproxy · CWE-79 | Средняя6,1 | — | 52,2 % | 20 февр. 2019 г. |
40В плане | CVE-2019-16915Эксплойта нет | An issue was discovered in pfSense through 2.4.4-p3.netgate · pfsense · CWE-22 | Критическая9,8 | — | 3,7 % | 26 сент. 2019 г. |
39Наблюдать | CVE-2024-54780Эксплойта нет | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget duenetgate · pfsense ce · CWE-94 | Высокая8,8 | — | 12,4 % | 14 мая 2025 г. |
38Наблюдать | CVE-2023-42325Эксплойта нет | Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the stanetgate · pfsense · CWE-79 | Средняя5,4 | — | 57,9 % | 14 нояб. 2023 г. |
38Наблюдать | CVE-2023-42327Эксплойта нет | Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getnetgate · pfsense · CWE-79 | Средняя5,4 | — | 55,4 % | 14 нояб. 2023 г. |
38Наблюдать | CVE-2018-16055Эксплойта нет | An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to netgate · pfsense · CWE-78 | Высокая8,8 | — | 11,2 % | 26 сент. 2018 г. |
38Наблюдать | CVE-2020-21487Эксплойта нет | Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via thnetgate · pfsense · CWE-79 | Критическая9,6 | — | 0,7 % | 4 апр. 2023 г. |
36Наблюдать | CVE-2022-26019Эксплойта нет | Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software netgate · pfsense · CWE-22 | Высокая8,8 | — | 4,5 % | 31 мар. 2022 г. |
- CVE-2022-3181467На этой неделе
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP H
КритическаяCVSS 9,8Готовый эксплойтEPSS 92 %netgate · pfblockerng5 сент. 2022 г.
- CVE-2023-2725362На этой неделе
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbi
ВысокаяCVSS 8,8Готовый эксплойтEPSS 90 %netgate · pfsense17 мар. 2023 г.
- CVE-2023-4812355В плане
An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafte
ВысокаяCVSS 8,8Proof of conceptEPSS 68 %netgate · pfsense6 дек. 2023 г.
- CVE-2023-4232654В плане
An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php
ВысокаяCVSS 8,8Proof of conceptEPSS 64 %netgate · pfsense14 нояб. 2023 г.
- CVE-2023-4879551В плане
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
СредняяCVSS 5,9Proof of conceptEPSS 93 %ssh · ssh18 дек. 2023 г.
- CVE-2019-1666751В плане
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands.
ВысокаяCVSS 8,8Proof of conceptEPSS 55 %netgate · pfsense26 сент. 2019 г.
- CVE-2018-402150В плане
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS
ВысокаяCVSS 7,2Эксплойта нетEPSS 72 %netgate · pfsense3 дек. 2018 г.
- CVE-2015-229547В плане
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote
СредняяCVSS 6,8Proof of conceptEPSS 66 %netgate · pfsense10 апр. 2015 г.
- CVE-2017-100047945В плане
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrar
ВысокаяCVSS 8,8Готовый эксплойтEPSS 32 %netgate · pfsense3 янв. 2018 г.
- CVE-2024-4653843В плане
A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload
СредняяCVSS 4,8Proof of conceptEPSS 82 %netgate · pfsense22 окт. 2024 г.
- CVE-2018-401943В плане
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS
ВысокаяCVSS 7,2Эксплойта нетEPSS 49 %netgate · pfsense3 дек. 2018 г.
- CVE-2018-402043В плане
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS
ВысокаяCVSS 7,2Эксплойта нетEPSS 49 %netgate · pfsense3 дек. 2018 г.
- CVE-2022-2927342В плане
pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
СредняяCVSS 6,1Эксплойта нетEPSS 60 %netgate · pfsense22 февр. 2023 г.
- CVE-2019-1234742В плане
In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accoun
СредняяCVSS 6,1Proof of conceptEPSS 59 %netgate · pfsense29 мая 2019 г.
- CVE-2023-2710042В плане
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE
КритическаяCVSS 9,8Proof of conceptEPSS 10 %netgate · pfsense plus22 мар. 2023 г.
- CVE-2019-1670141В плане
pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing sh
ВысокаяCVSS 8,8Proof of conceptEPSS 20 %netgate · pfsense25 сент. 2019 г.
- CVE-2019-1258541В плане
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %apcupsd · apcupsd2 июн. 2019 г.
- CVE-2019-895340В плане
The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_lis
СредняяCVSS 6,1Proof of conceptEPSS 52 %netgate · haproxy20 февр. 2019 г.
- CVE-2019-1691540В плане
An issue was discovered in pfSense through 2.4.4-p3.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %netgate · pfsense26 сент. 2019 г.
- CVE-2024-5478039Наблюдать
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due
ВысокаяCVSS 8,8Эксплойта нетEPSS 12 %netgate · pfsense ce14 мая 2025 г.
- CVE-2023-4232538Наблюдать
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the sta
СредняяCVSS 5,4Эксплойта нетEPSS 58 %netgate · pfsense14 нояб. 2023 г.
- CVE-2023-4232738Наблюдать
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the get
СредняяCVSS 5,4Эксплойта нетEPSS 55 %netgate · pfsense14 нояб. 2023 г.
- CVE-2018-1605538Наблюдать
An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to
ВысокаяCVSS 8,8Эксплойта нетEPSS 11 %netgate · pfsense26 сент. 2018 г.
- CVE-2020-2148738Наблюдать
Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via th
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %netgate · pfsense4 апр. 2023 г.
- CVE-2022-2601936Наблюдать
Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %netgate · pfsense31 мар. 2022 г.