Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Opnsense CRITICAL 9.1
CVE-2026-45158

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configu…

Fix: 26.1.8+
Fix from $2,300 2026-05-13
Opnsense CRITICAL 9.1
CVE-2026-44193

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user …

Fix: 26.1.7+
Fix from $2,300 2026-05-13
Opnsense CRITICAL 9.1
CVE-2026-44194EPSS 6%

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsens…

Fix: 26.1.8+
Fix from $2,300 2026-05-13
Opnsense MEDIUM 6.5
CVE-2026-44195

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler allows an unauthenticated at…

Fix: 26.1.7+
Fix from $1,600 2026-05-13
Opnsense HIGH 8.2
CVE-2026-34578

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector passes the login username direct…

Fix: 26.1.6+
Fix from $1,950 2026-04-09
Opnsense HIGH 8.1
CVE-2026-30868

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.4, multiple OPNsense MVC API endpoints perform state‑changing operations but…

Fix: 26.1.4+
Fix from $1,950 2026-03-11
Opnsense MEDIUM 6.1
CVE-2019-25374

OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploiting the passthrough…

No fix yet
Fix from $1,600 2026-02-15
Opnsense MEDIUM 6.1
CVE-2019-25375

OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting…

No fix yet
Fix from $1,600 2026-02-15
Opnsense MEDIUM 6.1
CVE-2019-25376

OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting…

No fix yet
Fix from $1,600 2026-02-15
Opnsense MEDIUM 6.1
CVE-2019-25377

OPNsense 19.1 contains a reflected cross-site scripting vulnerability in the system_advanced_sysctl.php endpoint that allows attackers to inject mali…

No fix yet
Fix from $1,600 2026-02-15
Opnsense MEDIUM 5.4
CVE-2019-25373

OPNsense 19.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting craf…

No fix yet
Fix from $1,600 2026-02-15
Opnsense MEDIUM 6.1
CVE-2019-25370

OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input t…

No fix yet
Fix from $1,600 2026-02-15
Opnsense MEDIUM 6.1
CVE-2019-25371

OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting…

No fix yet
Fix from $1,600 2026-02-15
Opnsense MEDIUM 6.1
CVE-2019-25372

OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting…

No fix yet
Fix from $1,600 2026-02-15
Opnsense MEDIUM 5.4
CVE-2019-25368

OPNsense 19.1 contains multiple cross-site scripting vulnerabilities in the diag_backup.php endpoint that allow attackers to inject malicious scripts…

No fix yet
Fix from $1,600 2026-02-15
Opnsense MEDIUM 5.4
CVE-2019-25369

OPNsense 19.1 contains a stored cross-site scripting vulnerability in the system_advanced_sysctl.php endpoint that allows attackers to inject persist…

No fix yet
Fix from $1,600 2026-02-15
Opnsense CRITICAL 9.1
CVE-2025-50989EPSS 8%

OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). …

Fix: 25.1.8+
Fix from $2,300 2025-08-27
Opnsense CRITICAL 9.8
CVE-2023-27152

DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.

No fix yet
Fix from $2,300 2023-10-23
Opnsense MEDIUM 5.4
CVE-2023-44275

OPNsense before 23.7.5 allows XSS via the index.php column_count parameter to the Lobby Dashboard.

Fix: 23.7.5+
Fix from $1,600 2023-09-28
Opnsense MEDIUM 5.4
CVE-2023-44276

OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.

Fix: 23.7.5+
Fix from $1,600 2023-09-28
Opnsense CRITICAL 9.8
CVE-2023-39004

Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attac…

Fix: 23.7+
Fix from $2,300 2023-08-09
Opnsense CRITICAL 9.8
CVE-2023-39008

A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 2…

Fix: 23.7+
Fix from $2,300 2023-08-09
Opnsense CRITICAL 9.6
CVE-2023-39007

/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in ap…

Fix: 23.7+
Fix from $2,300 2023-08-09
Opnsense HIGH 7.5
CVE-2023-39005

Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.

Fix: 23.7+
Fix from $1,950 2023-08-09
Opnsense MEDIUM 5.4
CVE-2023-39006

The Crash Reporter (crash_reporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 mishandles input sanit…

Fix: 23.7+
Fix from $1,600 2023-08-09
Opnsense CRITICAL 9.8
CVE-2023-39001

A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow…

Fix: 23.7+
Fix from $2,300 2023-08-09
Opnsense HIGH 7.5
CVE-2023-39003

OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp.

Fix: 23.7+
Fix from $1,950 2023-08-09
Opnsense HIGH 7.2
CVE-2023-38997

A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allo…

Fix: 23.7+
Fix from $1,950 2023-08-09
Opnsense MEDIUM 6.5
CVE-2023-38999

A Cross-Site Request Forgery (CSRF) in the System Halt API (/system/halt) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.…

Fix: 23.7+
Fix from $1,600 2023-08-09
Opnsense MEDIUM 6.1
CVE-2023-38998

An open redirect in the Login page of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to redirect a victim…

Fix: 23.7+
Fix from $1,600 2023-08-09