Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.9
CVE-2025-69691
Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only …
Pfsense
Mitigation only
CRITICAL 9.1
CVE-2025-69690
Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_rebo…
Pfsense
No fix yet
MEDIUM 6.5
CVE-2025-53392
In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory trave…
Pfsense
No fix yet
HIGH 7.2
CVE-2023-29975
An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.
Pfsense
Mitigation only
CRITICAL 9.8
CVE-2023-29974
An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.
Pfsense
No fix yet
HIGH 8.8
CVE-2021-41282EPSS 87%
diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the fire…
Pfsense
No fix yet
MEDIUM 6.1
CVE-2021-27933EPSS 27%
pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.
Pfsense
No fix yet