Vulnerabilities > Netgate

DATE CVE VULNERABILITY TITLE RISK
2024-10-22 CVE-2024-46538 Cross-site Scripting vulnerability in Netgate Pfsense 2.5.2
A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php.
network
low complexity
netgate CWE-79
4.8
2023-12-18 CVE-2023-48795 Improper Validation of Integrity Check Value vulnerability in multiple products
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack.
5.9
2023-12-06 CVE-2023-48123 Unspecified vulnerability in Netgate Pfsense and Pfsense Plus
An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.
network
low complexity
netgate
8.8
2023-11-14 CVE-2023-42326 Command Injection vulnerability in Netgate Pfsense and Pfsense Plus
An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.
network
low complexity
netgate CWE-77
8.8
2023-11-14 CVE-2023-42325 Cross-site Scripting vulnerability in Netgate Pfsense 2.7.0
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page.
network
low complexity
netgate CWE-79
5.4
2023-11-14 CVE-2023-42327 Cross-site Scripting vulnerability in Netgate Pfsense 2.7.0
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.
network
low complexity
netgate CWE-79
5.4
2023-04-04 CVE-2020-21487 Cross-site Scripting vulnerability in Netgate Pfsense and Pfsense Acme Package
Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.
network
low complexity
netgate CWE-79
critical
9.6
2023-03-22 CVE-2023-27100 Improper Restriction of Excessive Authentication Attempts vulnerability in multiple products
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.
network
low complexity
netgate pfsense CWE-307
critical
9.8
2023-03-17 CVE-2023-27253 XML Injection (aka Blind XPath Injection) vulnerability in Netgate Pfsense 2.7.0
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.
network
low complexity
netgate CWE-91
8.8
2023-02-22 CVE-2022-29273 Cross-site Scripting vulnerability in Netgate Pfsense
pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
network
low complexity
netgate CWE-79
6.1