Перейти к содержимому
Noroxi

Записи Netgate

59 опубликованных записей вендора netgate.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
3 · 5,1 %
Pre-auth RCE
6
С записью об исправлении
5,1 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

59 записей
  • CVE-2022-31814
    67На этой неделе

    pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP H

    КритическаяCVSS 9,8Готовый эксплойтEPSS 92 %

    netgate · pfblockerng5 сент. 2022 г.

  • CVE-2023-27253
    62На этой неделе

    A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbi

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 90 %

    netgate · pfsense17 мар. 2023 г.

  • CVE-2023-48123
    55В плане

    An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafte

    ВысокаяCVSS 8,8Proof of conceptEPSS 68 %

    netgate · pfsense6 дек. 2023 г.

  • CVE-2023-42326
    54В плане

    An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php

    ВысокаяCVSS 8,8Proof of conceptEPSS 64 %

    netgate · pfsense14 нояб. 2023 г.

  • CVE-2023-48795
    51В плане

    The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas

    СредняяCVSS 5,9Proof of conceptEPSS 93 %

    ssh · ssh18 дек. 2023 г.

  • CVE-2019-16667
    51В плане

    diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands.

    ВысокаяCVSS 8,8Proof of conceptEPSS 55 %

    netgate · pfsense26 сент. 2019 г.

  • CVE-2018-4021
    50В плане

    An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS

    ВысокаяCVSS 7,2Эксплойта нетEPSS 72 %

    netgate · pfsense3 дек. 2018 г.

  • CVE-2015-2295
    47В плане

    Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote

    СредняяCVSS 6,8Proof of conceptEPSS 66 %

    netgate · pfsense10 апр. 2015 г.

  • CVE-2017-1000479
    45В плане

    pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrar

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 32 %

    netgate · pfsense3 янв. 2018 г.

  • CVE-2024-46538
    43В плане

    A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload

    СредняяCVSS 4,8Proof of conceptEPSS 82 %

    netgate · pfsense22 окт. 2024 г.

  • CVE-2018-4019
    43В плане

    An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS

    ВысокаяCVSS 7,2Эксплойта нетEPSS 49 %

    netgate · pfsense3 дек. 2018 г.

  • CVE-2018-4020
    43В плане

    An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS

    ВысокаяCVSS 7,2Эксплойта нетEPSS 49 %

    netgate · pfsense3 дек. 2018 г.

  • CVE-2022-29273
    42В плане

    pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.

    СредняяCVSS 6,1Эксплойта нетEPSS 60 %

    netgate · pfsense22 февр. 2023 г.

  • CVE-2019-12347
    42В плане

    In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accoun

    СредняяCVSS 6,1Proof of conceptEPSS 59 %

    netgate · pfsense29 мая 2019 г.

  • CVE-2023-27100
    42В плане

    Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE

    КритическаяCVSS 9,8Proof of conceptEPSS 10 %

    netgate · pfsense plus22 мар. 2023 г.

  • CVE-2019-16701
    41В плане

    pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing sh

    ВысокаяCVSS 8,8Proof of conceptEPSS 20 %

    netgate · pfsense25 сент. 2019 г.

  • CVE-2019-12585
    41В плане

    Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    apcupsd · apcupsd2 июн. 2019 г.

  • CVE-2019-8953
    40В плане

    The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_lis

    СредняяCVSS 6,1Proof of conceptEPSS 52 %

    netgate · haproxy20 февр. 2019 г.

  • CVE-2019-16915
    40В плане

    An issue was discovered in pfSense through 2.4.4-p3.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    netgate · pfsense26 сент. 2019 г.

  • CVE-2024-54780
    39Наблюдать

    Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due

    ВысокаяCVSS 8,8Эксплойта нетEPSS 12 %

    netgate · pfsense ce14 мая 2025 г.

  • CVE-2023-42325
    38Наблюдать

    Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the sta

    СредняяCVSS 5,4Эксплойта нетEPSS 58 %

    netgate · pfsense14 нояб. 2023 г.

  • CVE-2023-42327
    38Наблюдать

    Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the get

    СредняяCVSS 5,4Эксплойта нетEPSS 55 %

    netgate · pfsense14 нояб. 2023 г.

  • CVE-2018-16055
    38Наблюдать

    An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to

    ВысокаяCVSS 8,8Эксплойта нетEPSS 11 %

    netgate · pfsense26 сент. 2018 г.

  • CVE-2020-21487
    38Наблюдать

    Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via th

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    netgate · pfsense4 апр. 2023 г.

  • CVE-2022-26019
    36Наблюдать

    Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software

    ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %

    netgate · pfsense31 мар. 2022 г.