Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Pfsense MEDIUM 5.4
CVE-2023-42325EPSS 58%

Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_…

No fix yet
Fix from $1,600 2023-11-14
Pfsense MEDIUM 5.4
CVE-2023-42327EPSS 55%

Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getservicepr…

No fix yet
Fix from $1,600 2023-11-14
Pfsense HIGH 8.8
CVE-2019-16667EPSS 55%

diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs b…

No fix yet
Fix from $1,950 2019-09-26
Pfsense MEDIUM 6.1
CVE-2019-12949

In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker…

No fix yet
Fix from $1,600 2019-06-25
Pfsense HIGH 7.2
CVE-2018-4019EPSS 49%

An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request…

No fix yet
Fix from $1,950 2018-12-03
Pfsense HIGH 7.2
CVE-2018-4020EPSS 49%

An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request…

No fix yet
Fix from $1,950 2018-12-03
Pfsense HIGH 7.2
CVE-2018-4021EPSS 72%

An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request…

No fix yet
Fix from $1,950 2018-12-03
Pfsense HIGH 7.8
CVE-2015-1414

Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2015-02-27