Vulnerability index

Browse CVEs

40 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pi Hole HIGH 7.8
CVE-2021-29449

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discover…

Fix: after 5.2.4
Fix from $1,950 2021-04-14
Pi Hole MEDIUM 5.4
CVE-2020-35591

Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious …

No fix yet
Fix from $1,600 2021-02-18
Pi Hole MEDIUM 5.4
CVE-2020-35592

Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or HTML due to …

No fix yet
Fix from $1,600 2021-02-18
Pi Hole MEDIUM 6.1
CVE-2020-35659

The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indirectly query DNS with a malici…

Fix: 5.2.2+
Fix from $1,600 2020-12-24
Pi Hole HIGH 7.8
CVE-2020-12620

Pi-hole 4.4 allows a user able to write to /etc/pihole/dns-servers.conf to escalate privileges through command injection (shell metacharacters after …

Fix: 5.0+
Fix from $1,950 2020-07-30
Pi Hole HIGH 7.8
CVE-2020-14162

An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core script as root without a passw…

Fix: 5.1+
Fix from $1,950 2020-07-30
Pi Hole HIGH 7.8
CVE-2020-14971

Pi-hole through 5.0 allows code injection in piholedhcp (the Static DHCP Leases section) by modifying Teleporter backup files and then restoring them…

Fix: after 5.0
Fix from $1,950 2020-06-23
Pi Hole HIGH 7.2
CVE-2020-8816 KEVEPSS 78%

Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

Fix: after 4.3.2
Fix from $1,950 2020-05-29
Pi Hole HIGH 8.8
CVE-2020-11108EPSS 78%

The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution …

Fix: after 4.4
Fix from $1,950 2020-05-11
Pi Hole HIGH 8.8
CVE-2019-13051EPSS 12%

Pi-Hole 4.3 allows Command Injection.

Patch available
Fix from $1,950 2019-10-09