Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2018-20799
In pfSense 2.4.4_1, blocking of source IP addresses on the basis of failed HTTPS authentication is inconsistent with blocking of source IP addresses …
Pfsense
Patch available
MEDIUM 6.1
CVE-2019-8953EPSS 52%
The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.ph…
Haproxy
0.59_16+
HIGH 7.2
CVE-2018-4019EPSS 49%
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request…
Pfsense
No fix yet
HIGH 7.2
CVE-2018-4020EPSS 49%
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request…
Pfsense
No fix yet
HIGH 7.2
CVE-2018-4021EPSS 72%
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request…
Pfsense
No fix yet
HIGH 8.8
CVE-2018-16055EPSS 11%
An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to its passi…
Pfsense
2.4.4+
HIGH 8.8
CVE-2017-1000479EPSS 33%
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, b…
Pfsense
16.1.16+
MEDIUM 6.8
CVE-2015-2295EPSS 66%
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attacker…
Pfsense
after 2.2
HIGH 7.8
CVE-2015-1414
Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of serv…
Pfsense
Mitigation only
MEDIUM 5.8
CVE-2014-4695
Multiple open redirect vulnerabilities in the Snort package before 3.0.13 for pfSense through 2.1.4 allow remote attackers to redirect users to arbit…
Pfsense
after 3.0.12
MEDIUM 5.8
CVE-2014-4696
Multiple open redirect vulnerabilities in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to redirect users to arb…
Pfsense
after 2.1.4
MEDIUM 6.8
CVE-2014-4691
Session fixation vulnerability in pfSense before 2.1.4 allows remote attackers to hijack web sessions via a firewall login cookie.
Pfsense
after 2.1.3
MEDIUM 6.5
CVE-2014-4688EPSS 7%
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_dns.php in a Create Alias act…
Pfsense
after 2.1.3
MEDIUM 5.0
CVE-2014-4689
Absolute path traversal vulnerability in pkg_edit.php in pfSense before 2.1.4 allows remote attackers to read arbitrary XML files via a full pathname…
Pfsense
after 2.1.3
MEDIUM 5.0
CVE-2014-4690
Multiple directory traversal vulnerabilities in pfSense before 2.1.4 allow (1) remote attackers to read arbitrary .info files via a crafted path in t…
Pfsense
after 2.1.3