CVE-2025-34087
- EPSS 46.72%
- Veröffentlicht 03.07.2025 19:46:49
- Zuletzt bearbeitet 01.10.2025 14:08:35
An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, the domain parameter is not properly sanitized, allowing an attacker to append OS commands to the doma...
CVE-2024-44069
- EPSS 0.11%
- Veröffentlicht 19.08.2024 02:15:04
- Zuletzt bearbeitet 10.10.2025 15:26:42
Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier reportedly does "not consider the bug a security issue" but the specific motivation for letting arbitrar...
CVE-2024-34361
- EPSS 58.18%
- Veröffentlicht 05.07.2024 19:15:09
- Zuletzt bearbeitet 02.10.2025 13:07:15
Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior to 5.18.3 allows an authenticated user to make internal requests to the server via the `gravity_Downl...
CVE-2024-28247
- EPSS 5.58%
- Veröffentlicht 27.03.2024 19:15:48
- Zuletzt bearbeitet 10.10.2025 17:34:48
The Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-side software. A vulnerability has been discovered in Pihole that allows an authenticated user on the platform to read internal server files ...
CVE-2021-32793
- EPSS 0.22%
- Veröffentlicht 04.08.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:07:45
Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the function to add domains to blocklists or allowlists is vulnerable to a stored cross-...
CVE-2021-32706
- EPSS 61.05%
- Veröffentlicht 04.08.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:07:34
Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the `validDomainWildcard` preg_match filter allows a malicious character through that ca...
CVE-2021-29448
- EPSS 0.3%
- Veröffentlicht 15.04.2021 16:15:14
- Zuletzt bearbeitet 21.11.2024 06:01:07
Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHu...
CVE-2021-29449
- EPSS 11.36%
- Veröffentlicht 14.04.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 06:01:07
Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole core. See the referenced GitHub security advisory for details.
CVE-2020-35592
- EPSS 0.17%
- Veröffentlicht 18.02.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:27:39
Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack agai...
CVE-2020-35591
- EPSS 0.18%
- Veröffentlicht 18.02.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:27:39
Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value and inject it to a victim. After the victim logs in...