Перейти к содержимому
Noroxi

Записи pfSense

31 опубликованных записей вендора pfsense.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
2 · 6,5 %
Pre-auth RCE
3
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

31 записей
  • CVE-2021-41282
    61На этой неделе

    diag_routes.php in pfSense 2.5.2 allows sed data injection.

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 87 %

    pfsense · pfsense1 мар. 2022 г.

  • CVE-2016-10709
    45В плане

    pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php gr

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 34 %

    pfsense · pfsense22 янв. 2018 г.

  • CVE-2022-40624
    44В плане

    pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different

    КритическаяCVSS 9,8Proof of conceptEPSS 17 %

    pfsense · pfblockerng20 дек. 2022 г.

  • CVE-2023-27100
    42В плане

    Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE

    КритическаяCVSS 9,8Proof of conceptEPSS 10 %

    netgate · pfsense plus22 мар. 2023 г.

  • CVE-2023-29974
    40В плане

    An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    pfsense · pfsense8 нояб. 2023 г.

  • CVE-2025-69691
    39Наблюдать

    Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php.

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    pfsense · pfsense8 мая 2026 г.

  • CVE-2025-69690
    36Наблюдать

    Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the

    КритическаяCVSS 9,1Proof of conceptEPSS 1 %

    pfsense · pfsense8 мая 2026 г.

  • CVE-2021-27933
    32Наблюдать

    pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.

    СредняяCVSS 6,1Эксплойта нетEPSS 27 %

    pfsense · pfsense28 апр. 2021 г.

  • CVE-2020-19678
    31Наблюдать

    Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensi

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    pfsense · pfsense6 апр. 2023 г.

  • CVE-2011-4197
    31Наблюдать

    etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constr

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    pfsense · pfsense3 янв. 2012 г.

  • CVE-2023-29975
    29Наблюдать

    An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.

    ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %

    pfsense · pfsense9 нояб. 2023 г.

  • CVE-2025-53392
    27Наблюдать

    In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath direct

    СредняяCVSS 6,5Proof of conceptEPSS 2 %

    pfsense · pfsense28 июн. 2025 г.

  • CVE-2022-21132
    27Наблюдать

    Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    pfsense · pfsense-pkg-wireguard10 мар. 2022 г.

  • CVE-2025-34176
    26Наблюдать

    Netgate pfSense CE Suricata Package v7.0.8_2 Directory Traversal Information Disclosure

    СредняяCVSS 5,3Эксплойта нетEPSS 16 %

    pfsense · pfsense9 сент. 2025 г.

  • CVE-2025-34175
    25Наблюдать

    Netgate pfSense CE Suricata package v7.0.8_2 Reflected Cross-Site Scripting

    СредняяCVSS 5,1Эксплойта нетEPSS 16 %

    pfsense · pfsense9 сент. 2025 г.

  • CVE-2019-18667
    25Наблюдать

    /usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payloa

    СредняяCVSS 6,1Эксплойта нетEPSS 4 %

    pfsense · pfsense-pkg-freeradius32 нояб. 2019 г.

  • CVE-2021-20729
    25Наблюдать

    Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software

    СредняяCVSS 6,1Эксплойта нетEPSS 3 %

    pfsense · pfsense31 мар. 2022 г.

  • CVE-2022-42247
    25Наблюдать

    pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component.

    СредняяCVSS 6,1Эксплойта нетEPSS 3 %

    pfsense · pfsense3 окт. 2022 г.

  • CVE-2014-4696
    24Наблюдать

    Multiple open redirect vulnerabilities in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to redirect use

    СредняяCVSS 5,8Эксплойта нетEPSS 2 %

    pfsense · suricata package2 июл. 2014 г.

  • CVE-2014-4695
    24Наблюдать

    Multiple open redirect vulnerabilities in the Snort package before 3.0.13 for pfSense through 2.1.4 allow remote attackers to redirect users

    СредняяCVSS 5,8Эксплойта нетEPSS 2 %

    pfsense · snort package2 июл. 2014 г.

  • CVE-2022-23993
    24Наблюдать

    /usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS

    СредняяCVSS 6,1Эксплойта нетEPSS 2 %

    pfsense · pfsense26 янв. 2022 г.

  • CVE-2025-34174
    23Наблюдать

    Netgate pfSense CE Status_Traffic_Totals Package v2.3.2_7 Stored Cross-Site Scripting

    СредняяCVSS 5,1Эксплойта нетEPSS 10 %

    pfsense · pfsense9 сент. 2025 г.

  • CVE-2020-26693
    23Наблюдать

    A stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which allows an authenticated attacker to execute arbit

    СредняяCVSS 5,4Эксплойта нетEPSS 5 %

    pfsense · pfsense1 июн. 2021 г.

  • CVE-2025-34178
    21Наблюдать

    Netgate pfSense CE Suricata package v7.0.8_2 Stored Cross-Site Scripting

    СредняяCVSS 5,1Эксплойта нетEPSS 4 %

    pfsense · pfsense9 сент. 2025 г.

  • CVE-2025-34173
    21Наблюдать

    Netgate pfSense CE Snort package v4.1.6_25 Directory Traversal Information Disclosure

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    pfsense · pfsense9 сент. 2025 г.