Netgate

Pfsense

53 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 28.06.2025 00:00:00
  • Zuletzt bearbeitet 30.06.2025 18:38:23

In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, an...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 14.05.2025 00:00:00
  • Zuletzt bearbeitet 23.06.2025 14:50:34

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups,...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 14.05.2025 00:00:00
  • Zuletzt bearbeitet 23.06.2025 14:51:38

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.

Exploit
  • EPSS 0.72%
  • Veröffentlicht 14.05.2025 00:00:00
  • Zuletzt bearbeitet 13.06.2025 13:03:51

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacke...

Exploit
  • EPSS 67.49%
  • Veröffentlicht 22.10.2024 17:15:03
  • Zuletzt bearbeitet 30.10.2024 20:45:35

A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php.

  • EPSS 65.33%
  • Veröffentlicht 06.12.2023 20:15:07
  • Zuletzt bearbeitet 21.11.2024 08:31:07

An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.

  • EPSS 83.32%
  • Veröffentlicht 14.11.2023 05:15:08
  • Zuletzt bearbeitet 21.11.2024 08:22:26

An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.

Exploit
  • EPSS 48.31%
  • Veröffentlicht 14.11.2023 04:15:07
  • Zuletzt bearbeitet 21.11.2024 08:22:26

Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.

Exploit
  • EPSS 48.31%
  • Veröffentlicht 14.11.2023 04:15:07
  • Zuletzt bearbeitet 21.11.2024 08:22:26

Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page.

  • EPSS 0.53%
  • Veröffentlicht 04.04.2023 15:15:08
  • Zuletzt bearbeitet 13.02.2025 17:15:25

Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.