İçeriğe atla
Noroxi

Opnsense kayıtları

opnsense üreticisine ait 36 yayımlanmış kayıt.

Tüm kayıtlar

36 kayıt
  • CVE-2023-39001
    40Planlayın

    A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.

    KritikCVSS 9,8İstismar yokEPSS %4

    opnsense · opnsense9 Ağu 2023

  • CVE-2023-39008
    40Planlayın

    A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition

    KritikCVSS 9,8İstismar yokEPSS %3

    opnsense · opnsense9 Ağu 2023

  • CVE-2025-50989
    39İzleyin

    OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_ed

    KritikCVSS 9,1İstismar yokEPSS %8

    opnsense · opnsense27 Ağu 2025

  • CVE-2023-39007
    39İzleyin

    /ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAct

    KritikCVSS 9,6Kavram kanıtıEPSS %3

    opnsense · opnsense9 Ağu 2023

  • CVE-2023-39004
    39İzleyin

    Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 al

    KritikCVSS 9,8İstismar yokEPSS %1

    opnsense · opnsense9 Ağu 2023

  • CVE-2023-27152
    39İzleyin

    DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentica

    KritikCVSS 9,8İstismar yokEPSS %1

    opnsense · opnsense23 Eki 2023

  • CVE-2026-44193
    36İzleyin

    OPNsense: RCE via XMLRPC endpoint using `opnsense.restore_config_section` method

    KritikCVSS 9,1İstismar yokEPSS %1

    opnsense · opnsense13 May 2026

  • CVE-2026-45158
    36İzleyin

    OPNsense: Command Injection via Attacker-Controlled DHCP Config

    KritikCVSS 9,1İstismar yokEPSS %1

    opnsense · opnsense13 May 2026

  • CVE-2026-44194
    36İzleyin

    OPNsense: RCE on user managment

    KritikCVSS 9,1İstismar yokEPSS %1

    opnsense · opnsense13 May 2026

  • CVE-2026-34578
    32İzleyin

    OPNsense has an LDAP Injection via Unsanitized Username in Authentication

    YüksekCVSS 8,2İstismar yokEPSS %0

    opnsense · opnsense9 Nis 2026

  • CVE-2026-30868
    32İzleyin

    Cross-Site Request Forgery (CSRF) in opnsense/core

    YüksekCVSS 8,1İstismar yokEPSS %0

    opnsense · opnsense11 Mar 2026

  • CVE-2023-39003
    30İzleyin

    OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /t

    YüksekCVSS 7,5İstismar yokEPSS %1

    opnsense · opnsense9 Ağu 2023

  • CVE-2023-39005
    30İzleyin

    Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.

    YüksekCVSS 7,5İstismar yokEPSS %1

    opnsense · opnsense9 Ağu 2023

  • CVE-2019-11816
    29İzleyin

    Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authenticated users to es

    YüksekCVSS 7,2İstismar yokEPSS %3

    opnsense · opnsense20 May 2019

  • CVE-2023-38997
    28İzleyin

    A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Business Edition before 23

    YüksekCVSS 7,2İstismar yokEPSS %1

    opnsense · opnsense9 Ağu 2023

  • CVE-2018-18958
    26İzleyin

    OPNsense 18.7.x before 18.7.7 has Incorrect Access Control.

    OrtaCVSS 6,5İstismar yokEPSS %1

    opnsense · opnsense17 Haz 2019

  • CVE-2023-38999
    26İzleyin

    A Cross-Site Request Forgery (CSRF) in the System Halt API (/system/halt) of OPNsense Community Edition before 23.7 and Business Edition bef

    OrtaCVSS 6,5İstismar yokEPSS %0

    opnsense · opnsense9 Ağu 2023

  • CVE-2026-44195
    26İzleyin

    OPNsense: Authentication lockout bypass

    OrtaCVSS 6,5İstismar yokEPSS %0

    opnsense · opnsense13 May 2026

  • CVE-2020-23015
    25İzleyin

    An open redirect issue was discovered in OPNsense through 20.1.5.

    OrtaCVSS 6,1Kavram kanıtıEPSS %3

    opnsense · opnsense3 May 2021

  • CVE-2021-42770
    24İzleyin

    A Cross-site scripting (XSS) vulnerability was discovered in OPNsense before 21.7.4 via the LDAP attribute return in the authentication test

    OrtaCVSS 6,1İstismar yokEPSS %1

    opnsense · opnsense8 Kas 2021

  • CVE-2023-39002
    24İzleyin

    A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and Busi

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    opnsense · opnsense9 Ağu 2023

  • CVE-2023-38998
    24İzleyin

    An open redirect in the Login page of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to redirect

    OrtaCVSS 6,1İstismar yokEPSS %1

    opnsense · opnsense9 Ağu 2023

  • CVE-2023-39000
    24İzleyin

    A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense Community Edition before 23.7 an

    OrtaCVSS 6,1İstismar yokEPSS %1

    opnsense · opnsense9 Ağu 2023

  • CVE-2023-44275
    21İzleyin

    OPNsense before 23.7.5 allows XSS via the index.php column_count parameter to the Lobby Dashboard.

    OrtaCVSS 5,4İstismar yokEPSS %1

    opnsense · opnsense28 Eyl 2023

  • CVE-2023-44276
    21İzleyin

    OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.

    OrtaCVSS 5,4İstismar yokEPSS %1

    opnsense · opnsense28 Eyl 2023