Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2025-69691 Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only … Pfsense Mitigation only Fix from $2,3002026-05-08 CRITICAL 9.1 CVE-2025-69690 Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_rebo… Pfsense No fix yet Fix from $2,3002026-05-08 MEDIUM 5.4 CVE-2025-34177 In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before b… Pfsense 2.8.0+ Fix from $1,6002025-09-09 MEDIUM 5.4 CVE-2025-34178 In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before b… Pfsense 2.8.0+ Fix from $1,6002025-09-09 MEDIUM 6.1 CVE-2025-34175EPSS 16% In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-r… Pfsense 2.8.0+ Fix from $1,6002025-09-09 MEDIUM 5.4 CVE-2025-34174EPSS 10% In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric value or sanitized of HTM… Pfsense 2.8.0+ Fix from $1,6002025-09-09 MEDIUM 6.1 CVE-2025-34172 In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET … Pfsense 2.8.0+ Fix from $1,6002025-09-09 MEDIUM 6.5 CVE-2025-53392 In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory trave… Pfsense No fix yet Fix from $1,6002025-06-28 HIGH 7.2 CVE-2023-29975 An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification. Pfsense Mitigation only Fix from $1,9502023-11-09 CRITICAL 9.8 CVE-2023-29974 An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements. Pfsense No fix yet Fix from $2,3002023-11-08 HIGH 7.5 CVE-2020-19678 Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensitive info… Pfsense Patch available Fix from $1,9502023-04-06 CRITICAL 9.8 CVE-2023-27100EPSS 10% Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software… Pfsense Patch available Fix from $2,3002023-03-22 CRITICAL 9.8 CVE-2022-40624EPSS 17% pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerabi… Pfblockerng 2.1.4_27+ Fix from $2,3002022-12-20 MEDIUM 6.1 CVE-2022-42247 pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component. This vulnerability allows attackers… Pfsense Patch available Fix from $1,6002022-10-03 MEDIUM 6.1 CVE-2021-20729 Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions… Pfsense after 21.05 Fix from $1,6002022-03-31 MEDIUM 6.5 CVE-2022-21132 Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0.1.6 vers… Pfsense Pkg Wireguard 0.1.5_4+ Fix from $1,6002022-03-10 HIGH 8.8 CVE-2021-41282EPSS 87% diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the fire… Pfsense No fix yet Fix from $1,9502022-03-01 MEDIUM 6.1 CVE-2022-23993 /usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS. Pfsense 2.6.0 / 22.01+ Fix from $1,6002022-01-26 MEDIUM 5.4 CVE-2020-26693EPSS 5% A stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which allows an authenticated attacker to execute arbitrary web … Pfsense Patch available Fix from $1,6002021-06-01 MEDIUM 6.1 CVE-2021-27933EPSS 27% pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field. Pfsense No fix yet Fix from $1,6002021-04-28 MEDIUM 6.1 CVE-2019-18667 /usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payload as pass… Pfsense Pkg Freeradius3 0.15.7_3+ Fix from $1,6002019-11-02 HIGH 8.8 CVE-2016-10709EPSS 34% pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php graph param… Pfsense after 2.2.6 Fix from $1,9502018-01-22 HIGH 7.5 CVE-2011-4197 etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, whi… Pfsense after 2.0 Fix from $1,9502012-01-03