pfSense kayıtları
pfsense üreticisine ait 31 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %6,5
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')14
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-287 Improper Authentication1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-36 Absolute Path Traversal1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
31 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
61Bu hafta | CVE-2021-41282Silahlaştırılmış | diag_routes.php in pfSense 2.5.2 allows sed data injection.pfsense · pfsense · CWE-74 | Yüksek8,8 | — | %87,1 | 1 Mar 2022 |
45Planlayın | CVE-2016-10709Silahlaştırılmış | pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php grpfsense · pfsense · CWE-78 | Yüksek8,8 | — | %33,7 | 22 Oca 2018 |
44Planlayın | CVE-2022-40624Kavram kanıtı | pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different pfsense · pfblockerng · CWE-78 | Kritik9,8 | — | %17,1 | 20 Ara 2022 |
42Planlayın | CVE-2023-27100Kavram kanıtı | Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CEnetgate · pfsense plus · CWE-307 | Kritik9,8 | — | %9,8 | 22 Mar 2023 |
40Planlayın | CVE-2023-29974İstismar yok | An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.pfsense · pfsense · CWE-521 | Kritik9,8 | — | %1,8 | 8 Kas 2023 |
39İzleyin | CVE-2025-69691İstismar yok | Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php.pfsense · pfsense · CWE-284 | Kritik9,9 | — | %0,7 | 8 May 2026 |
36İzleyin | CVE-2025-69690Kavram kanıtı | Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the pfsense · pfsense · CWE-502 | Kritik9,1 | — | %0,8 | 8 May 2026 |
32İzleyin | CVE-2021-27933İstismar yok | pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.pfsense · pfsense · CWE-79 | Orta6,1 | — | %26,6 | 28 Nis 2021 |
31İzleyin | CVE-2020-19678İstismar yok | Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensipfsense · pfsense · CWE-22 | Yüksek7,5 | — | %3,5 | 6 Nis 2023 |
31İzleyin | CVE-2011-4197İstismar yok | etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constrpfsense · pfsense · CWE-264 | Yüksek7,5 | — | %1,9 | 3 Oca 2012 |
29İzleyin | CVE-2023-29975İstismar yok | An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.pfsense · pfsense · CWE-287 | Yüksek7,2 | — | %1,7 | 9 Kas 2023 |
27İzleyin | CVE-2025-53392Kavram kanıtı | In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directpfsense · pfsense · CWE-36 | Orta6,5 | — | %1,8 | 28 Haz 2025 |
27İzleyin | CVE-2022-21132İstismar yok | Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0pfsense · pfsense-pkg-wireguard · CWE-22 | Orta6,5 | — | %1,8 | 10 Mar 2022 |
26İzleyin | CVE-2025-34176İstismar yok | Netgate pfSense CE Suricata Package v7.0.8_2 Directory Traversal Information Disclosurepfsense · pfsense · CWE-22 | Orta5,3 | — | %16,0 | 9 Eyl 2025 |
25İzleyin | CVE-2025-34175İstismar yok | Netgate pfSense CE Suricata package v7.0.8_2 Reflected Cross-Site Scriptingpfsense · pfsense · CWE-79 | Orta5,1 | — | %15,5 | 9 Eyl 2025 |
25İzleyin | CVE-2019-18667İstismar yok | /usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payloapfsense · pfsense-pkg-freeradius3 · CWE-79 | Orta6,1 | — | %4,0 | 2 Kas 2019 |
25İzleyin | CVE-2021-20729İstismar yok | Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus softwarepfsense · pfsense · CWE-79 | Orta6,1 | — | %2,9 | 31 Mar 2022 |
25İzleyin | CVE-2022-42247İstismar yok | pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component.pfsense · pfsense · CWE-79 | Orta6,1 | — | %2,7 | 3 Eki 2022 |
24İzleyin | CVE-2014-4696İstismar yok | Multiple open redirect vulnerabilities in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to redirect usepfsense · suricata package | Orta5,8 | — | %2,1 | 2 Tem 2014 |
24İzleyin | CVE-2014-4695İstismar yok | Multiple open redirect vulnerabilities in the Snort package before 3.0.13 for pfSense through 2.1.4 allow remote attackers to redirect userspfsense · snort package | Orta5,8 | — | %2,1 | 2 Tem 2014 |
24İzleyin | CVE-2022-23993İstismar yok | /usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSSpfsense · pfsense · CWE-79 | Orta6,1 | — | %1,5 | 26 Oca 2022 |
23İzleyin | CVE-2025-34174İstismar yok | Netgate pfSense CE Status_Traffic_Totals Package v2.3.2_7 Stored Cross-Site Scriptingpfsense · pfsense · CWE-79 | Orta5,1 | — | %10,5 | 9 Eyl 2025 |
23İzleyin | CVE-2020-26693İstismar yok | A stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which allows an authenticated attacker to execute arbitpfsense · pfsense · CWE-79 | Orta5,4 | — | %5,3 | 1 Haz 2021 |
21İzleyin | CVE-2025-34178İstismar yok | Netgate pfSense CE Suricata package v7.0.8_2 Stored Cross-Site Scriptingpfsense · pfsense · CWE-79 | Orta5,1 | — | %3,9 | 9 Eyl 2025 |
21İzleyin | CVE-2025-34173İstismar yok | Netgate pfSense CE Snort package v4.1.6_25 Directory Traversal Information Disclosurepfsense · pfsense · CWE-22 | Orta5,3 | — | %0,9 | 9 Eyl 2025 |
- CVE-2021-4128261Bu hafta
diag_routes.php in pfSense 2.5.2 allows sed data injection.
YüksekCVSS 8,8SilahlaştırılmışEPSS %87pfsense · pfsense1 Mar 2022
- CVE-2016-1070945Planlayın
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php gr
YüksekCVSS 8,8SilahlaştırılmışEPSS %34pfsense · pfsense22 Oca 2018
- CVE-2022-4062444Planlayın
pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different
KritikCVSS 9,8Kavram kanıtıEPSS %17pfsense · pfblockerng20 Ara 2022
- CVE-2023-2710042Planlayın
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE
KritikCVSS 9,8Kavram kanıtıEPSS %10netgate · pfsense plus22 Mar 2023
- CVE-2023-2997440Planlayın
An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.
KritikCVSS 9,8İstismar yokEPSS %2pfsense · pfsense8 Kas 2023
- CVE-2025-6969139İzleyin
Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php.
KritikCVSS 9,9İstismar yokEPSS %1pfsense · pfsense8 May 2026
- CVE-2025-6969036İzleyin
Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the
KritikCVSS 9,1Kavram kanıtıEPSS %1pfsense · pfsense8 May 2026
- CVE-2021-2793332İzleyin
pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.
OrtaCVSS 6,1İstismar yokEPSS %27pfsense · pfsense28 Nis 2021
- CVE-2020-1967831İzleyin
Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensi
YüksekCVSS 7,5İstismar yokEPSS %3pfsense · pfsense6 Nis 2023
- CVE-2011-419731İzleyin
etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constr
YüksekCVSS 7,5İstismar yokEPSS %2pfsense · pfsense3 Oca 2012
- CVE-2023-2997529İzleyin
An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.
YüksekCVSS 7,2İstismar yokEPSS %2pfsense · pfsense9 Kas 2023
- CVE-2025-5339227İzleyin
In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath direct
OrtaCVSS 6,5Kavram kanıtıEPSS %2pfsense · pfsense28 Haz 2025
- CVE-2022-2113227İzleyin
Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0
OrtaCVSS 6,5İstismar yokEPSS %2pfsense · pfsense-pkg-wireguard10 Mar 2022
- CVE-2025-3417626İzleyin
Netgate pfSense CE Suricata Package v7.0.8_2 Directory Traversal Information Disclosure
OrtaCVSS 5,3İstismar yokEPSS %16pfsense · pfsense9 Eyl 2025
- CVE-2025-3417525İzleyin
Netgate pfSense CE Suricata package v7.0.8_2 Reflected Cross-Site Scripting
OrtaCVSS 5,1İstismar yokEPSS %16pfsense · pfsense9 Eyl 2025
- CVE-2019-1866725İzleyin
/usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payloa
OrtaCVSS 6,1İstismar yokEPSS %4pfsense · pfsense-pkg-freeradius32 Kas 2019
- CVE-2021-2072925İzleyin
Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software
OrtaCVSS 6,1İstismar yokEPSS %3pfsense · pfsense31 Mar 2022
- CVE-2022-4224725İzleyin
pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component.
OrtaCVSS 6,1İstismar yokEPSS %3pfsense · pfsense3 Eki 2022
- CVE-2014-469624İzleyin
Multiple open redirect vulnerabilities in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to redirect use
OrtaCVSS 5,8İstismar yokEPSS %2pfsense · suricata package2 Tem 2014
- CVE-2014-469524İzleyin
Multiple open redirect vulnerabilities in the Snort package before 3.0.13 for pfSense through 2.1.4 allow remote attackers to redirect users
OrtaCVSS 5,8İstismar yokEPSS %2pfsense · snort package2 Tem 2014
- CVE-2022-2399324İzleyin
/usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS
OrtaCVSS 6,1İstismar yokEPSS %2pfsense · pfsense26 Oca 2022
- CVE-2025-3417423İzleyin
Netgate pfSense CE Status_Traffic_Totals Package v2.3.2_7 Stored Cross-Site Scripting
OrtaCVSS 5,1İstismar yokEPSS %10pfsense · pfsense9 Eyl 2025
- CVE-2020-2669323İzleyin
A stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which allows an authenticated attacker to execute arbit
OrtaCVSS 5,4İstismar yokEPSS %5pfsense · pfsense1 Haz 2021
- CVE-2025-3417821İzleyin
Netgate pfSense CE Suricata package v7.0.8_2 Stored Cross-Site Scripting
OrtaCVSS 5,1İstismar yokEPSS %4pfsense · pfsense9 Eyl 2025
- CVE-2025-3417321İzleyin
Netgate pfSense CE Snort package v4.1.6_25 Directory Traversal Information Disclosure
OrtaCVSS 5,3İstismar yokEPSS %1pfsense · pfsense9 Eyl 2025