Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2021-29449
Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discover…
Pi Hole
after 5.2.4
MEDIUM 5.4
CVE-2020-35591
Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious …
Pi Hole
No fix yet
MEDIUM 5.4
CVE-2020-35592
Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or HTML due to …
Pi Hole
No fix yet
MEDIUM 6.1
CVE-2020-35659
The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indirectly query DNS with a malici…
Pi Hole
5.2.2+
HIGH 7.8
CVE-2020-12620
Pi-hole 4.4 allows a user able to write to /etc/pihole/dns-servers.conf to escalate privileges through command injection (shell metacharacters after …
Pi Hole
5.0+
HIGH 7.8
CVE-2020-14162
An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core script as root without a passw…
Pi Hole
5.1+
HIGH 7.8
CVE-2020-14971
Pi-hole through 5.0 allows code injection in piholedhcp (the Static DHCP Leases section) by modifying Teleporter backup files and then restoring them…
Pi Hole
after 5.0
HIGH 7.2
CVE-2020-8816 KEVEPSS 78%
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
Pi Hole
after 4.3.2
HIGH 8.8
CVE-2020-11108EPSS 78%
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution …
Pi Hole
after 4.4
HIGH 8.8
CVE-2019-13051EPSS 12%
Pi-Hole 4.3 allows Command Injection.
Pi Hole
Patch available