Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.9
CVE-2025-69691
Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only …
Pfsense
Mitigation only
CRITICAL 9.1
CVE-2025-69690
Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_rebo…
Pfsense
No fix yet
MEDIUM 5.4
CVE-2025-34177
In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before b…
Pfsense
2.8.0+
MEDIUM 5.4
CVE-2025-34178
In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before b…
Pfsense
2.8.0+
MEDIUM 6.1
CVE-2025-34175EPSS 16%
In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-r…
Pfsense
2.8.0+
MEDIUM 5.4
CVE-2025-34174EPSS 10%
In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric value or sanitized of HTM…
Pfsense
2.8.0+
MEDIUM 6.1
CVE-2025-34172
In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET …
Pfsense
2.8.0+
MEDIUM 6.5
CVE-2025-53392
In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory trave…
Pfsense
No fix yet
HIGH 7.2
CVE-2023-29975
An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.
Pfsense
Mitigation only
CRITICAL 9.8
CVE-2023-29974
An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.
Pfsense
No fix yet
HIGH 7.5
CVE-2020-19678
Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensitive info…
Pfsense
Patch available
CRITICAL 9.8
CVE-2023-27100EPSS 10%
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software…
Pfsense
Patch available
CRITICAL 9.8
CVE-2022-40624EPSS 17%
pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerabi…
Pfblockerng
2.1.4_27+
MEDIUM 6.1
CVE-2022-42247
pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component. This vulnerability allows attackers…
Pfsense
Patch available
MEDIUM 6.1
CVE-2021-20729
Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions…
Pfsense
after 21.05
MEDIUM 6.5
CVE-2022-21132
Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0.1.6 vers…
Pfsense Pkg Wireguard
0.1.5_4+
HIGH 8.8
CVE-2021-41282EPSS 87%
diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the fire…
Pfsense
No fix yet
MEDIUM 6.1
CVE-2022-23993
/usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS.
Pfsense
2.6.0 / 22.01+
MEDIUM 5.4
CVE-2020-26693EPSS 5%
A stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which allows an authenticated attacker to execute arbitrary web …
Pfsense
Patch available
MEDIUM 6.1
CVE-2021-27933EPSS 27%
pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.
Pfsense
No fix yet
MEDIUM 6.1
CVE-2019-18667
/usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payload as pass…
Pfsense Pkg Freeradius3
0.15.7_3+
HIGH 8.8
CVE-2016-10709EPSS 34%
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php graph param…
Pfsense
after 2.2.6
HIGH 7.5
CVE-2011-4197
etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, whi…
Pfsense
after 2.0