Pi-hole

Pi-hole

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 46.72%
  • Veröffentlicht 03.07.2025 19:46:49
  • Zuletzt bearbeitet 01.10.2025 14:08:35

An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, the domain parameter is not properly sanitized, allowing an attacker to append OS commands to the doma...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 19.08.2024 02:15:04
  • Zuletzt bearbeitet 10.10.2025 15:26:42

Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier reportedly does "not consider the bug a security issue" but the specific motivation for letting arbitrar...

Exploit
  • EPSS 58.18%
  • Veröffentlicht 05.07.2024 19:15:09
  • Zuletzt bearbeitet 02.10.2025 13:07:15

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior to 5.18.3 allows an authenticated user to make internal requests to the server via the `gravity_Downl...

Exploit
  • EPSS 5.58%
  • Veröffentlicht 27.03.2024 19:15:48
  • Zuletzt bearbeitet 10.10.2025 17:34:48

The Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-side software. A vulnerability has been discovered in Pihole that allows an authenticated user on the platform to read internal server files ...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 04.08.2021 18:15:09
  • Zuletzt bearbeitet 21.11.2024 06:07:45

Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the function to add domains to blocklists or allowlists is vulnerable to a stored cross-...

Exploit
  • EPSS 61.05%
  • Veröffentlicht 04.08.2021 18:15:09
  • Zuletzt bearbeitet 21.11.2024 06:07:34

Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the `validDomainWildcard` preg_match filter allows a malicious character through that ca...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 15.04.2021 16:15:14
  • Zuletzt bearbeitet 21.11.2024 06:01:07

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHu...

Exploit
  • EPSS 11.36%
  • Veröffentlicht 14.04.2021 22:15:12
  • Zuletzt bearbeitet 21.11.2024 06:01:07

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole core. See the referenced GitHub security advisory for details.

Exploit
  • EPSS 0.17%
  • Veröffentlicht 18.02.2021 20:15:12
  • Zuletzt bearbeitet 21.11.2024 05:27:39

Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack agai...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 18.02.2021 20:15:12
  • Zuletzt bearbeitet 21.11.2024 05:27:39

Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value and inject it to a victim. After the victim logs in...