Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Registry Cleaner HIGH 7.8
CVE-2016-20057

NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to esc…

Fix: after 16.0.205
Fix from $1,950 2026-04-04
Amiti Antivirus HIGH 7.8
CVE-2016-20058

Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allow…

Fix: after 23.0.305
Fix from $1,950 2026-04-04
Pfsense Ce HIGH 8.8
CVE-2024-54780EPSS 12%

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to impro…

Fix: 2.8.0 / 25.03+
Fix from $1,950 2025-05-14
Pfsense Ce MEDIUM 5.4
CVE-2024-57273

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configura…

Fix: 2.8.0 / 25.03+
Fix from $1,600 2025-05-14
Pfsense Ce MEDIUM 5.4
CVE-2024-54779EPSS 8%

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.

Fix: 2.8.0 / 25.03+
Fix from $1,600 2025-05-14
Pfsense HIGH 8.8
CVE-2023-48123EPSS 68%

An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request…

Fix: after 23.05.1
Fix from $1,950 2023-12-06
Pfsense HIGH 8.8
CVE-2023-42326EPSS 64%

An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and inter…

Fix: after 23.05.1
Fix from $1,950 2023-11-14
Pfsense MEDIUM 5.4
CVE-2023-42325EPSS 58%

Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_…

No fix yet
Fix from $1,600 2023-11-14
Pfsense MEDIUM 5.4
CVE-2023-42327EPSS 55%

Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getservicepr…

No fix yet
Fix from $1,600 2023-11-14
Pfsense CRITICAL 9.6
CVE-2020-21487

Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFol…

Patch available
Fix from $2,300 2023-04-04
Pfsense HIGH 8.8
CVE-2023-27253EPSS 90%

A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary com…

Patch available
Fix from $1,950 2023-03-17
Pfsense MEDIUM 6.1
CVE-2022-29273EPSS 60%

pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.

Fix: 22.05+
Fix from $1,600 2023-02-22
Pfsense MEDIUM 6.1
CVE-2020-21219

Cross Site Scripting (XSS) vulnerability in Netgate pf Sense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 allows remote attackers to to run arbitr…

Patch available
Fix from $1,600 2022-12-15
Pfblockerng CRITICAL 9.8
CVE-2022-31814EPSS 88%

pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host heade…

Fix: after 2.1.4_26
Fix from $2,300 2022-09-05
Pfsense HIGH 8.8
CVE-2022-24299

Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software version…

Fix: 2.6.0 / 22.01+
Fix from $1,950 2022-03-31
Pfsense HIGH 8.8
CVE-2022-26019

Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions …

Fix: 2.6.0 / 22.01+
Fix from $1,950 2022-03-31
Pfsense MEDIUM 5.4
CVE-2020-19201

A Stored Cross-Site Scripting (XSS) vulnerability was found in status_filter_reload.php, a page in the pfSense software WebGUI, on Netgate pfSense ve…

Fix: after 2.4.4
Fix from $1,600 2021-07-12
Pfsense MEDIUM 5.4
CVE-2020-19203

An authenticated Cross-Site Scripting (XSS) vulnerability was found in widgets/widgets/wake_on_lan_widget.php, a component of the pfSense software We…

Fix: 2.4.4+
Fix from $1,600 2021-07-12
Pfsense MEDIUM 6.1
CVE-2020-10797

An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version. After passing inputs to the command and…

Fix: 2.4.5+
Fix from $1,600 2020-04-29
Pfsense MEDIUM 5.4
CVE-2020-11457EPSS 9%

pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user.

Fix: 2.4.5+
Fix from $1,600 2020-04-01
Pfsense HIGH 8.8
CVE-2019-16667EPSS 55%

diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs b…

No fix yet
Fix from $1,950 2019-09-26
Pfsense CRITICAL 9.8
CVE-2019-16915

An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e…

Fix: 2.4.4+
Fix from $2,300 2019-09-26
Pfsense MEDIUM 6.1
CVE-2019-16914

An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without …

Fix: 2.4.4+
Fix from $1,600 2019-09-26
Pfsense HIGH 8.8
CVE-2019-16701EPSS 20%

pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metac…

Fix: 2.4.4+
Fix from $1,950 2019-09-25
Pfsense MEDIUM 6.1
CVE-2019-12949

In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker…

No fix yet
Fix from $1,600 2019-06-25
Pfsense CRITICAL 9.8
CVE-2019-12585EPSS 5%

Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.

Fix: 2.4.4+
Fix from $2,300 2019-06-03
Pfsense MEDIUM 6.1
CVE-2019-12584

Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php.

Fix: 2.4.4+
Fix from $1,600 2019-06-03
Pfsense MEDIUM 6.1
CVE-2019-12347EPSS 59%

In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edi…

Patch available
Fix from $1,600 2019-05-29
Pfsense HIGH 7.2
CVE-2019-11816

Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authenticated users to escalate pr…

Fix: 19.1.8+
Fix from $1,950 2019-05-20
Pfsense HIGH 7.5
CVE-2018-20798

The expiretable configuration in pfSense 2.4.4_1 establishes block durations that are incompatible with the block durations implemented by sshguard, …

Patch available
Fix from $1,950 2019-03-01