Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2016-20057
NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to esc…
Registry Cleaner
after 16.0.205
HIGH 7.8
CVE-2016-20058
Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allow…
Amiti Antivirus
after 23.0.305
HIGH 8.8
CVE-2024-54780EPSS 12%
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to impro…
Pfsense Ce
2.8.0 / 25.03+
MEDIUM 5.4
CVE-2024-57273
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configura…
Pfsense Ce
2.8.0 / 25.03+
MEDIUM 5.4
CVE-2024-54779EPSS 8%
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.
Pfsense Ce
2.8.0 / 25.03+
HIGH 8.8
CVE-2023-48123EPSS 68%
An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request…
Pfsense
after 23.05.1
HIGH 8.8
CVE-2023-42326EPSS 64%
An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and inter…
Pfsense
after 23.05.1
MEDIUM 5.4
CVE-2023-42325EPSS 58%
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_…
Pfsense
No fix yet
MEDIUM 5.4
CVE-2023-42327EPSS 55%
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getservicepr…
Pfsense
No fix yet
CRITICAL 9.6
CVE-2020-21487
Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFol…
Pfsense
Patch available
HIGH 8.8
CVE-2023-27253EPSS 90%
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary com…
Pfsense
Patch available
MEDIUM 6.1
CVE-2022-29273EPSS 60%
pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
Pfsense
22.05+
MEDIUM 6.1
CVE-2020-21219
Cross Site Scripting (XSS) vulnerability in Netgate pf Sense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 allows remote attackers to to run arbitr…
Pfsense
Patch available
CRITICAL 9.8
CVE-2022-31814EPSS 88%
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host heade…
Pfblockerng
after 2.1.4_26
HIGH 8.8
CVE-2022-24299
Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software version…
Pfsense
2.6.0 / 22.01+
HIGH 8.8
CVE-2022-26019
Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions …
Pfsense
2.6.0 / 22.01+
MEDIUM 5.4
CVE-2020-19201
A Stored Cross-Site Scripting (XSS) vulnerability was found in status_filter_reload.php, a page in the pfSense software WebGUI, on Netgate pfSense ve…
Pfsense
after 2.4.4
MEDIUM 5.4
CVE-2020-19203
An authenticated Cross-Site Scripting (XSS) vulnerability was found in widgets/widgets/wake_on_lan_widget.php, a component of the pfSense software We…
Pfsense
2.4.4+
MEDIUM 6.1
CVE-2020-10797
An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version. After passing inputs to the command and…
Pfsense
2.4.5+
MEDIUM 5.4
CVE-2020-11457EPSS 9%
pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user.
Pfsense
2.4.5+
HIGH 8.8
CVE-2019-16667EPSS 55%
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs b…
Pfsense
No fix yet
CRITICAL 9.8
CVE-2019-16915
An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e…
Pfsense
2.4.4+
MEDIUM 6.1
CVE-2019-16914
An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without …
Pfsense
2.4.4+
HIGH 8.8
CVE-2019-16701EPSS 20%
pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metac…
Pfsense
2.4.4+
MEDIUM 6.1
CVE-2019-12949
In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker…
Pfsense
No fix yet
CRITICAL 9.8
CVE-2019-12585EPSS 5%
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.
Pfsense
2.4.4+
MEDIUM 6.1
CVE-2019-12584
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php.
Pfsense
2.4.4+
MEDIUM 6.1
CVE-2019-12347EPSS 59%
In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edi…
Pfsense
Patch available
HIGH 7.2
CVE-2019-11816
Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authenticated users to escalate pr…
Pfsense
19.1.8+
HIGH 7.5
CVE-2018-20798
The expiretable configuration in pfSense 2.4.4_1 establishes block durations that are incompatible with the block durations implemented by sshguard, …
Pfsense
Patch available