Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.4
CVE-2019-25399
IPFire 2.21 Core Update 127 contains multiple stored cross-site scripting vulnerabilities in the extrahd.cgi script that allow attackers to inject ma…
Ipfire
No fix yet
MEDIUM 6.1
CVE-2019-25398
IPFire 2.21 Core Update 127 contains multiple cross-site scripting vulnerabilities in the ovpnmain.cgi script that allow attackers to inject maliciou…
Ipfire
No fix yet
MEDIUM 5.4
CVE-2019-25400
IPFire 2.21 Core Update 127 contains multiple reflected cross-site scripting vulnerabilities in the fwhosts.cgi script that allow attackers to inject…
Ipfire
No fix yet
MEDIUM 6.1
CVE-2019-25396
IPFire 2.21 Core Update 127 contains a reflected cross-site scripting vulnerability in the updatexlrator.cgi script that allows attackers to inject m…
Ipfire
No fix yet
MEDIUM 6.1
CVE-2019-25397
IPFire 2.21 Core Update 127 contains multiple reflected cross-site scripting vulnerabilities in the hosts.cgi script that allow attackers to inject m…
Ipfire
No fix yet
MEDIUM 5.4
CVE-2025-34317
IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…
Ipfire
after 2.29
HIGH 8.8
CVE-2025-34311EPSS 14%
IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary …
Ipfire
2.29+
HIGH 8.8
CVE-2025-34312
IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary …
Ipfire
2.29+
MEDIUM 5.4
CVE-2025-34308
IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…
Ipfire
2.29+
MEDIUM 5.4
CVE-2025-34309EPSS 5%
IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…
Ipfire
2.29+
MEDIUM 5.4
CVE-2025-34310
IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…
Ipfire
2.29+
MEDIUM 5.4
CVE-2025-34313
IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…
Ipfire
2.29+
MEDIUM 5.4
CVE-2025-34314
IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…
Ipfire
2.29+
MEDIUM 5.4
CVE-2025-34315
IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…
Ipfire
2.29+
MEDIUM 5.4
CVE-2025-34316
IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…
Ipfire
2.29+
MEDIUM 6.5
CVE-2025-34304
IPFire versions prior to 2.29 (Core Update 198) contain a SQL injection vulnerability that allows an authenticated attacker to manipulate the SQL que…
Ipfire
2.29+
MEDIUM 5.4
CVE-2025-34301EPSS 5%
IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…
Ipfire
2.29+
MEDIUM 5.4
CVE-2025-34302
IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…
Ipfire
2.29+
MEDIUM 5.4
CVE-2025-34303
IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…
Ipfire
2.29+
MEDIUM 5.4
CVE-2025-34305
IPFire versions prior to 2.29 (Core Update 198) contain multiple stored cross-site scripting (XSS) vulnerabilities caused by a bug in the cleanhtml()…
Ipfire
2.29+
MEDIUM 5.4
CVE-2025-34306
IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…
Ipfire
2.29+
MEDIUM 5.4
CVE-2025-34307
IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…
Ipfire
2.29+
MEDIUM 5.4
CVE-2025-50975
IPFire 2.29 web-based firewall interface (firewall.cgi) fails to sanitize several rule parameters such as PROT, SRC_PORT, TGT_PORT, dnatport, key, ru…
Ipfire
No fix yet
MEDIUM 6.1
CVE-2025-50976
IPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK, and TLS_HOSTNAME query param…
Ipfire
No fix yet
MEDIUM 6.5
CVE-2025-50974
The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorporating p…
Ipfire
No fix yet
MEDIUM 5.4
CVE-2020-19204
An authenticated Stored Cross-Site Scriptiong (XSS) vulnerability exists in Lightning Wire Labs IPFire 2.21 (x86_64) - Core Update 130 in the "routin…
Ipfire
Patch available
MEDIUM 6.1
CVE-2020-21142
Cross Site Scripting (XSS) vulnerabilty in IPFire 2.23 via the IPfire web UI in the mail.cgi.
Ipfire
Patch available
MEDIUM 5.4
CVE-2020-19202
An authenticated Stored XSS (Cross-site Scripting) exists in the "captive.cgi" Captive Portal via the "Title of Login Page" text box or "TITLE" param…
Ipfire
No fix yet
HIGH 8.8
CVE-2021-33393EPSS 59%
lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It might be owned by an unprivi…
Ipfire
2.25+
HIGH 8.8
CVE-2018-16232EPSS 8%
An authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi. This allows an authenticated us…
Ipfire
Patch available