İçeriğe atla
Noroxi

pfSense kayıtları

pfsense üreticisine ait 31 yayımlanmış kayıt.

Tüm kayıtlar

31 kayıt
  • CVE-2021-41282
    61Bu hafta

    diag_routes.php in pfSense 2.5.2 allows sed data injection.

    YüksekCVSS 8,8SilahlaştırılmışEPSS %87

    pfsense · pfsense1 Mar 2022

  • CVE-2016-10709
    45Planlayın

    pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php gr

    YüksekCVSS 8,8SilahlaştırılmışEPSS %34

    pfsense · pfsense22 Oca 2018

  • CVE-2022-40624
    44Planlayın

    pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different

    KritikCVSS 9,8Kavram kanıtıEPSS %17

    pfsense · pfblockerng20 Ara 2022

  • CVE-2023-27100
    42Planlayın

    Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE

    KritikCVSS 9,8Kavram kanıtıEPSS %10

    netgate · pfsense plus22 Mar 2023

  • CVE-2023-29974
    40Planlayın

    An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.

    KritikCVSS 9,8İstismar yokEPSS %2

    pfsense · pfsense8 Kas 2023

  • CVE-2025-69691
    39İzleyin

    Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php.

    KritikCVSS 9,9İstismar yokEPSS %1

    pfsense · pfsense8 May 2026

  • CVE-2025-69690
    36İzleyin

    Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the

    KritikCVSS 9,1Kavram kanıtıEPSS %1

    pfsense · pfsense8 May 2026

  • CVE-2021-27933
    32İzleyin

    pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.

    OrtaCVSS 6,1İstismar yokEPSS %27

    pfsense · pfsense28 Nis 2021

  • CVE-2020-19678
    31İzleyin

    Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensi

    YüksekCVSS 7,5İstismar yokEPSS %3

    pfsense · pfsense6 Nis 2023

  • CVE-2011-4197
    31İzleyin

    etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constr

    YüksekCVSS 7,5İstismar yokEPSS %2

    pfsense · pfsense3 Oca 2012

  • CVE-2023-29975
    29İzleyin

    An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.

    YüksekCVSS 7,2İstismar yokEPSS %2

    pfsense · pfsense9 Kas 2023

  • CVE-2025-53392
    27İzleyin

    In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath direct

    OrtaCVSS 6,5Kavram kanıtıEPSS %2

    pfsense · pfsense28 Haz 2025

  • CVE-2022-21132
    27İzleyin

    Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0

    OrtaCVSS 6,5İstismar yokEPSS %2

    pfsense · pfsense-pkg-wireguard10 Mar 2022

  • CVE-2025-34176
    26İzleyin

    Netgate pfSense CE Suricata Package v7.0.8_2 Directory Traversal Information Disclosure

    OrtaCVSS 5,3İstismar yokEPSS %16

    pfsense · pfsense9 Eyl 2025

  • CVE-2025-34175
    25İzleyin

    Netgate pfSense CE Suricata package v7.0.8_2 Reflected Cross-Site Scripting

    OrtaCVSS 5,1İstismar yokEPSS %16

    pfsense · pfsense9 Eyl 2025

  • CVE-2019-18667
    25İzleyin

    /usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payloa

    OrtaCVSS 6,1İstismar yokEPSS %4

    pfsense · pfsense-pkg-freeradius32 Kas 2019

  • CVE-2021-20729
    25İzleyin

    Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software

    OrtaCVSS 6,1İstismar yokEPSS %3

    pfsense · pfsense31 Mar 2022

  • CVE-2022-42247
    25İzleyin

    pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component.

    OrtaCVSS 6,1İstismar yokEPSS %3

    pfsense · pfsense3 Eki 2022

  • CVE-2014-4696
    24İzleyin

    Multiple open redirect vulnerabilities in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to redirect use

    OrtaCVSS 5,8İstismar yokEPSS %2

    pfsense · suricata package2 Tem 2014

  • CVE-2014-4695
    24İzleyin

    Multiple open redirect vulnerabilities in the Snort package before 3.0.13 for pfSense through 2.1.4 allow remote attackers to redirect users

    OrtaCVSS 5,8İstismar yokEPSS %2

    pfsense · snort package2 Tem 2014

  • CVE-2022-23993
    24İzleyin

    /usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS

    OrtaCVSS 6,1İstismar yokEPSS %2

    pfsense · pfsense26 Oca 2022

  • CVE-2025-34174
    23İzleyin

    Netgate pfSense CE Status_Traffic_Totals Package v2.3.2_7 Stored Cross-Site Scripting

    OrtaCVSS 5,1İstismar yokEPSS %10

    pfsense · pfsense9 Eyl 2025

  • CVE-2020-26693
    23İzleyin

    A stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which allows an authenticated attacker to execute arbit

    OrtaCVSS 5,4İstismar yokEPSS %5

    pfsense · pfsense1 Haz 2021

  • CVE-2025-34178
    21İzleyin

    Netgate pfSense CE Suricata package v7.0.8_2 Stored Cross-Site Scripting

    OrtaCVSS 5,1İstismar yokEPSS %4

    pfsense · pfsense9 Eyl 2025

  • CVE-2025-34173
    21İzleyin

    Netgate pfSense CE Snort package v4.1.6_25 Directory Traversal Information Disclosure

    OrtaCVSS 5,3İstismar yokEPSS %1

    pfsense · pfsense9 Eyl 2025