Skip to main content

Vendor/product archive

netgate / pfsense CVEs

Beta · best-effort

49 CVEs tagged to netgate / pfsense3 Critical, 16 High, 30 Medium, 0 Low, 0 Unrated.

CVE-2024-46538

Published Oct 22, 2024

A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48123

Published Dec 6, 2023

An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php fil…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-42326

Published Nov 14, 2023

An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-42327

Published Nov 14, 2023

Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-42325

Published Nov 14, 2023

Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-27253

Published Mar 17, 2023

A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the con…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29273

Published Feb 22, 2023

pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-21219

Published Dec 15, 2022

Cross Site Scripting (XSS) vulnerability in Netgate pf Sense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 allows remote attackers to to run arbitrary code via the RootFolder fi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26019

Published Mar 31, 2022

Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remot…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24299

Published Mar 31, 2022

Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a rem…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-19203

Published Jul 12, 2021

An authenticated Cross-Site Scripting (XSS) vulnerability was found in widgets/widgets/wake_on_lan_widget.php, a component of the pfSense software WebGUI, on version 2.4.4-p2 and…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-19201

Published Jul 12, 2021

A Stored Cross-Site Scripting (XSS) vulnerability was found in status_filter_reload.php, a page in the pfSense software WebGUI, on Netgate pfSense version 2.4.4-p2 and earlier. Th…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10797

Published Apr 29, 2020

An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version. After passing inputs to the command and executing this command, the $…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11457

Published Apr 1, 2020

pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16667

Published Sep 26, 2019

diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produce…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16915

Published Sep 26, 2019

An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pa…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-16914

Published Sep 26, 2019

An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without sanitization.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16701

Published Sep 25, 2019

pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12949

Published Jun 25, 2019

In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker can leverage XSS to upload ar…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12585

Published Jun 3, 2019

Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12347

Published May 29, 2019

In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. The vulnerabilit…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11816

Published May 20, 2019

Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authenticated users to escalate privileges to administrator via…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20799

Published Mar 1, 2019

In pfSense 2.4.4_1, blocking of source IP addresses on the basis of failed HTTPS authentication is inconsistent with blocking of source IP addresses on the basis of failed SSH aut…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 49 CVEsPage 1 of 2