Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-45158 OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configu… Opnsense 26.1.8+ Fix from $2,3002026-05-13 CRITICAL 9.1 CVE-2026-44193 OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user … Opnsense 26.1.7+ Fix from $2,3002026-05-13 CRITICAL 9.1 CVE-2026-44194EPSS 6% OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsens… Opnsense 26.1.8+ Fix from $2,3002026-05-13 MEDIUM 6.5 CVE-2026-44195 OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler allows an unauthenticated at… Opnsense 26.1.7+ Fix from $1,6002026-05-13 HIGH 8.2 CVE-2026-34578 OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector passes the login username direct… Opnsense 26.1.6+ Fix from $1,9502026-04-09 HIGH 8.1 CVE-2026-30868 OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.4, multiple OPNsense MVC API endpoints perform state‑changing operations but… Opnsense 26.1.4+ Fix from $1,9502026-03-11 MEDIUM 6.1 CVE-2019-25374 OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploiting the passthrough… Opnsense No fix yet Fix from $1,6002026-02-15 MEDIUM 6.1 CVE-2019-25375 OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting… Opnsense No fix yet Fix from $1,6002026-02-15 MEDIUM 6.1 CVE-2019-25376 OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting… Opnsense No fix yet Fix from $1,6002026-02-15 MEDIUM 6.1 CVE-2019-25377 OPNsense 19.1 contains a reflected cross-site scripting vulnerability in the system_advanced_sysctl.php endpoint that allows attackers to inject mali… Opnsense No fix yet Fix from $1,6002026-02-15 MEDIUM 5.4 CVE-2019-25373 OPNsense 19.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting craf… Opnsense No fix yet Fix from $1,6002026-02-15 MEDIUM 6.1 CVE-2019-25370 OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input t… Opnsense No fix yet Fix from $1,6002026-02-15 MEDIUM 6.1 CVE-2019-25371 OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting… Opnsense No fix yet Fix from $1,6002026-02-15 MEDIUM 6.1 CVE-2019-25372 OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting… Opnsense No fix yet Fix from $1,6002026-02-15 MEDIUM 5.4 CVE-2019-25368 OPNsense 19.1 contains multiple cross-site scripting vulnerabilities in the diag_backup.php endpoint that allow attackers to inject malicious scripts… Opnsense No fix yet Fix from $1,6002026-02-15 MEDIUM 5.4 CVE-2019-25369 OPNsense 19.1 contains a stored cross-site scripting vulnerability in the system_advanced_sysctl.php endpoint that allows attackers to inject persist… Opnsense No fix yet Fix from $1,6002026-02-15 CRITICAL 9.1 CVE-2025-50989EPSS 8% OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). … Opnsense 25.1.8+ Fix from $2,3002025-08-27 CRITICAL 9.8 CVE-2023-27152 DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication. Opnsense No fix yet Fix from $2,3002023-10-23 MEDIUM 5.4 CVE-2023-44275 OPNsense before 23.7.5 allows XSS via the index.php column_count parameter to the Lobby Dashboard. Opnsense 23.7.5+ Fix from $1,6002023-09-28 MEDIUM 5.4 CVE-2023-44276 OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard. Opnsense 23.7.5+ Fix from $1,6002023-09-28 CRITICAL 9.8 CVE-2023-39004 Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attac… Opnsense 23.7+ Fix from $2,3002023-08-09 CRITICAL 9.8 CVE-2023-39008 A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 2… Opnsense 23.7+ Fix from $2,3002023-08-09 CRITICAL 9.6 CVE-2023-39007 /ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in ap… Opnsense 23.7+ Fix from $2,3002023-08-09 HIGH 7.5 CVE-2023-39005 Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2. Opnsense 23.7+ Fix from $1,9502023-08-09 MEDIUM 5.4 CVE-2023-39006 The Crash Reporter (crash_reporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 mishandles input sanit… Opnsense 23.7+ Fix from $1,6002023-08-09 CRITICAL 9.8 CVE-2023-39001 A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow… Opnsense 23.7+ Fix from $2,3002023-08-09 HIGH 7.5 CVE-2023-39003 OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp. Opnsense 23.7+ Fix from $1,9502023-08-09 HIGH 7.2 CVE-2023-38997 A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allo… Opnsense 23.7+ Fix from $1,9502023-08-09 MEDIUM 6.5 CVE-2023-38999 A Cross-Site Request Forgery (CSRF) in the System Halt API (/system/halt) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.… Opnsense 23.7+ Fix from $1,6002023-08-09 MEDIUM 6.1 CVE-2023-38998 An open redirect in the Login page of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to redirect a victim… Opnsense 23.7+ Fix from $1,6002023-08-09