Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pfsense HIGH 7.5
CVE-2018-20799

In pfSense 2.4.4_1, blocking of source IP addresses on the basis of failed HTTPS authentication is inconsistent with blocking of source IP addresses …

Patch available
Fix from $1,950 2019-03-01
Haproxy MEDIUM 6.1
CVE-2019-8953EPSS 52%

The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.ph…

Fix: 0.59_16+
Fix from $1,600 2019-02-20
Pfsense HIGH 7.2
CVE-2018-4019EPSS 49%

An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request…

No fix yet
Fix from $1,950 2018-12-03
Pfsense HIGH 7.2
CVE-2018-4020EPSS 49%

An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request…

No fix yet
Fix from $1,950 2018-12-03
Pfsense HIGH 7.2
CVE-2018-4021EPSS 72%

An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request…

No fix yet
Fix from $1,950 2018-12-03
Pfsense HIGH 8.8
CVE-2018-16055EPSS 11%

An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to its passi…

Fix: 2.4.4+
Fix from $1,950 2018-09-26
Pfsense HIGH 8.8
CVE-2017-1000479EPSS 33%

pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, b…

Fix: 16.1.16+
Fix from $1,950 2018-01-03
Pfsense MEDIUM 6.8
CVE-2015-2295EPSS 66%

Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attacker…

Fix: after 2.2
Fix from $1,600 2015-04-10
Pfsense HIGH 7.8
CVE-2015-1414

Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2015-02-27
Pfsense MEDIUM 5.8
CVE-2014-4695

Multiple open redirect vulnerabilities in the Snort package before 3.0.13 for pfSense through 2.1.4 allow remote attackers to redirect users to arbit…

Fix: after 3.0.12
Fix from $1,600 2014-07-02
Pfsense MEDIUM 5.8
CVE-2014-4696

Multiple open redirect vulnerabilities in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to redirect users to arb…

Fix: after 2.1.4
Fix from $1,600 2014-07-02
Pfsense MEDIUM 6.8
CVE-2014-4691

Session fixation vulnerability in pfSense before 2.1.4 allows remote attackers to hijack web sessions via a firewall login cookie.

Fix: after 2.1.3
Fix from $1,600 2014-07-02
Pfsense MEDIUM 6.5
CVE-2014-4688EPSS 7%

pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_dns.php in a Create Alias act…

Fix: after 2.1.3
Fix from $1,600 2014-07-02
Pfsense MEDIUM 5.0
CVE-2014-4689

Absolute path traversal vulnerability in pkg_edit.php in pfSense before 2.1.4 allows remote attackers to read arbitrary XML files via a full pathname…

Fix: after 2.1.3
Fix from $1,600 2014-07-02
Pfsense MEDIUM 5.0
CVE-2014-4690

Multiple directory traversal vulnerabilities in pfSense before 2.1.4 allow (1) remote attackers to read arbitrary .info files via a crafted path in t…

Fix: after 2.1.3
Fix from $1,600 2014-07-02