Vulnerabilities > Netgate > Pfsense > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-06-03 | CVE-2019-12584 | Cross-site Scripting vulnerability in multiple products Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php. | 4.3 |
2019-05-29 | CVE-2019-12347 | Cross-site Scripting vulnerability in Netgate Pfsense 2.4.4 In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. | 4.3 |
2019-05-20 | CVE-2019-11816 | Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authenticated users to escalate privileges to administrator via a specially crafted request. | 6.5 |
2019-03-01 | CVE-2018-20799 | Unspecified vulnerability in Netgate Pfsense 2.4.4 In pfSense 2.4.4_1, blocking of source IP addresses on the basis of failed HTTPS authentication is inconsistent with blocking of source IP addresses on the basis of failed SSH authentication (the behavior does not match the sshguard documentation), which might make it easier for attackers to bypass intended access restrictions. | 5.0 |
2019-03-01 | CVE-2018-20798 | Incorrect Permission Assignment for Critical Resource vulnerability in Netgate Pfsense 2.4.4 The expiretable configuration in pfSense 2.4.4_1 establishes block durations that are incompatible with the block durations implemented by sshguard, which might make it easier for attackers to bypass intended access restrictions. | 5.0 |
2018-12-03 | CVE-2018-4021 | OS Command Injection vulnerability in Netgate Pfsense 2.4.4 An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. | 6.5 |
2018-12-03 | CVE-2018-4020 | OS Command Injection vulnerability in Netgate Pfsense 2.4.4 An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. | 6.5 |
2018-12-03 | CVE-2018-4019 | OS Command Injection vulnerability in Netgate Pfsense 2.4.4 An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. | 6.5 |
2018-01-03 | CVE-2017-1000479 | Cross-Site Request Forgery (CSRF) vulnerability in multiple products pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occurs before an X-Frame-Options header is set. | 6.8 |
2015-08-18 | CVE-2015-6511 | Cross-site Scripting vulnerability in Netgate Pfsense Cross-site scripting (XSS) vulnerability in pfSense before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the server[] parameter to services_ntpd.php. | 4.3 |