Pi-hole

Pi-hole

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.13%
  • Veröffentlicht 11.05.2026 20:21:38
  • Zuletzt bearbeitet 13.05.2026 16:16:45

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to before Core 6.4.2 and FTL 6.6.1, two shell scripts executed as root by systemd (pihole-FTL-prestart.sh and pihole-FTL-posts...

  • EPSS 0.22%
  • Veröffentlicht 06.04.2026 15:02:19
  • Zuletzt bearbeitet 09.04.2026 18:18:28

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.4 has a local privilege-escalation vulnerability allows code execution as root from the low-privilege pihole account. Important context: the pihole ac...

Exploit
  • EPSS 4.97%
  • Veröffentlicht 03.07.2025 19:46:49
  • Zuletzt bearbeitet 01.10.2025 14:08:35

An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, the domain parameter is not properly sanitized, allowing an attacker to append OS commands to the doma...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 19.08.2024 02:15:04
  • Zuletzt bearbeitet 10.10.2025 15:26:42

Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier reportedly does "not consider the bug a security issue" but the specific motivation for letting arbitrar...

Exploit
  • EPSS 2.83%
  • Veröffentlicht 05.07.2024 19:15:09
  • Zuletzt bearbeitet 02.10.2025 13:07:15

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior to 5.18.3 allows an authenticated user to make internal requests to the server via the `gravity_Downl...

Exploit
  • EPSS 1.41%
  • Veröffentlicht 27.03.2024 19:15:48
  • Zuletzt bearbeitet 10.10.2025 17:34:48

The Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-side software. A vulnerability has been discovered in Pihole that allows an authenticated user on the platform to read internal server files ...

Exploit
  • EPSS 0.79%
  • Veröffentlicht 04.08.2021 18:15:09
  • Zuletzt bearbeitet 21.11.2024 06:07:45

Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the function to add domains to blocklists or allowlists is vulnerable to a stored cross-...

Exploit
  • EPSS 60.18%
  • Veröffentlicht 04.08.2021 18:15:09
  • Zuletzt bearbeitet 21.11.2024 06:07:34

Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the `validDomainWildcard` preg_match filter allows a malicious character through that ca...

Exploit
  • EPSS 0.67%
  • Veröffentlicht 15.04.2021 16:15:14
  • Zuletzt bearbeitet 21.11.2024 06:01:07

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHu...

Exploit
  • EPSS 1.86%
  • Veröffentlicht 14.04.2021 22:15:12
  • Zuletzt bearbeitet 06.04.2026 15:17:04

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole core. See the referenced GitHub security advisory for details.