Vulnerability index

Browse CVEs

31 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ipfire MEDIUM 6.4
CVE-2019-25399

IPFire 2.21 Core Update 127 contains multiple stored cross-site scripting vulnerabilities in the extrahd.cgi script that allow attackers to inject ma…

No fix yet
Fix from $1,600 2026-02-18
Ipfire MEDIUM 6.1
CVE-2019-25398

IPFire 2.21 Core Update 127 contains multiple cross-site scripting vulnerabilities in the ovpnmain.cgi script that allow attackers to inject maliciou…

No fix yet
Fix from $1,600 2026-02-18
Ipfire MEDIUM 5.4
CVE-2019-25400

IPFire 2.21 Core Update 127 contains multiple reflected cross-site scripting vulnerabilities in the fwhosts.cgi script that allow attackers to inject…

No fix yet
Fix from $1,600 2026-02-18
Ipfire MEDIUM 6.1
CVE-2019-25396

IPFire 2.21 Core Update 127 contains a reflected cross-site scripting vulnerability in the updatexlrator.cgi script that allows attackers to inject m…

No fix yet
Fix from $1,600 2026-02-18
Ipfire MEDIUM 6.1
CVE-2019-25397

IPFire 2.21 Core Update 127 contains multiple reflected cross-site scripting vulnerabilities in the hosts.cgi script that allow attackers to inject m…

No fix yet
Fix from $1,600 2026-02-18
Ipfire MEDIUM 5.4
CVE-2025-34317

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…

Fix: after 2.29
Fix from $1,600 2025-10-28
Ipfire HIGH 8.8
CVE-2025-34311EPSS 14%

IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary …

Fix: 2.29+
Fix from $1,950 2025-10-28
Ipfire HIGH 8.8
CVE-2025-34312

IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary …

Fix: 2.29+
Fix from $1,950 2025-10-28
Ipfire MEDIUM 5.4
CVE-2025-34308

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…

Fix: 2.29+
Fix from $1,600 2025-10-28
Ipfire MEDIUM 5.4
CVE-2025-34309EPSS 5%

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…

Fix: 2.29+
Fix from $1,600 2025-10-28
Ipfire MEDIUM 5.4
CVE-2025-34310

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…

Fix: 2.29+
Fix from $1,600 2025-10-28
Ipfire MEDIUM 5.4
CVE-2025-34313

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…

Fix: 2.29+
Fix from $1,600 2025-10-28
Ipfire MEDIUM 5.4
CVE-2025-34314

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…

Fix: 2.29+
Fix from $1,600 2025-10-28
Ipfire MEDIUM 5.4
CVE-2025-34315

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…

Fix: 2.29+
Fix from $1,600 2025-10-28
Ipfire MEDIUM 5.4
CVE-2025-34316

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…

Fix: 2.29+
Fix from $1,600 2025-10-28
Ipfire MEDIUM 6.5
CVE-2025-34304

IPFire versions prior to 2.29 (Core Update 198) contain a SQL injection vulnerability that allows an authenticated attacker to manipulate the SQL que…

Fix: 2.29+
Fix from $1,600 2025-10-28
Ipfire MEDIUM 5.4
CVE-2025-34301EPSS 5%

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…

Fix: 2.29+
Fix from $1,600 2025-10-28
Ipfire MEDIUM 5.4
CVE-2025-34302

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…

Fix: 2.29+
Fix from $1,600 2025-10-28
Ipfire MEDIUM 5.4
CVE-2025-34303

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…

Fix: 2.29+
Fix from $1,600 2025-10-28
Ipfire MEDIUM 5.4
CVE-2025-34305

IPFire versions prior to 2.29 (Core Update 198) contain multiple stored cross-site scripting (XSS) vulnerabilities caused by a bug in the cleanhtml()…

Fix: 2.29+
Fix from $1,600 2025-10-28
Ipfire MEDIUM 5.4
CVE-2025-34306

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…

Fix: 2.29+
Fix from $1,600 2025-10-28
Ipfire MEDIUM 5.4
CVE-2025-34307

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to in…

Fix: 2.29+
Fix from $1,600 2025-10-28
Ipfire MEDIUM 5.4
CVE-2025-50975

IPFire 2.29 web-based firewall interface (firewall.cgi) fails to sanitize several rule parameters such as PROT, SRC_PORT, TGT_PORT, dnatport, key, ru…

No fix yet
Fix from $1,600 2025-08-26
Ipfire MEDIUM 6.1
CVE-2025-50976

IPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK, and TLS_HOSTNAME query param…

No fix yet
Fix from $1,600 2025-08-26
Ipfire MEDIUM 6.5
CVE-2025-50974

The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorporating p…

No fix yet
Fix from $1,600 2025-08-26
Ipfire MEDIUM 5.4
CVE-2020-19204

An authenticated Stored Cross-Site Scriptiong (XSS) vulnerability exists in Lightning Wire Labs IPFire 2.21 (x86_64) - Core Update 130 in the "routin…

Patch available
Fix from $1,600 2021-07-12
Ipfire MEDIUM 6.1
CVE-2020-21142

Cross Site Scripting (XSS) vulnerabilty in IPFire 2.23 via the IPfire web UI in the mail.cgi.

Patch available
Fix from $1,600 2021-06-28
Ipfire MEDIUM 5.4
CVE-2020-19202

An authenticated Stored XSS (Cross-site Scripting) exists in the "captive.cgi" Captive Portal via the "Title of Login Page" text box or "TITLE" param…

No fix yet
Fix from $1,600 2021-06-17
Ipfire HIGH 8.8
CVE-2021-33393EPSS 59%

lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It might be owned by an unprivi…

Fix: 2.25+
Fix from $1,950 2021-06-09
Ipfire HIGH 8.8
CVE-2018-16232EPSS 8%

An authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi. This allows an authenticated us…

Patch available
Fix from $1,950 2018-10-17