Show filters
69 Total Results
Displaying 11-20 of 69
Sort by:
Attacker Value
Unknown
CVE-2020-19678
Disclosure Date: April 06, 2023 (last updated October 08, 2023)
Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensitive information via the file parameter to suricata/suricata_logs_browser.php.
0
Attacker Value
Unknown
CVE-2020-21487
Disclosure Date: April 04, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.
0
Attacker Value
Unknown
CVE-2023-27100
Disclosure Date: March 22, 2023 (last updated October 08, 2023)
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.
0
Attacker Value
Unknown
CVE-2022-29273
Disclosure Date: February 22, 2023 (last updated October 08, 2023)
pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
0
Attacker Value
Unknown
CVE-2020-21219
Disclosure Date: December 15, 2022 (last updated October 08, 2023)
Cross Site Scripting (XSS) vulnerability in Netgate pf Sense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 allows remote attackers to to run arbitrary code via the RootFolder field to acme_certificate_edit.php page of the ACME package.
0
Attacker Value
Unknown
CVE-2022-42247
Disclosure Date: October 03, 2022 (last updated October 08, 2023)
pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a file name.
0
Attacker Value
Unknown
CVE-2022-26019
Disclosure Date: March 31, 2022 (last updated October 07, 2023)
Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change NTP GPS settings to rewrite existing files on the file system, which may result in arbitrary command execution.
0
Attacker Value
Unknown
CVE-2022-24299
Disclosure Date: March 31, 2022 (last updated October 07, 2023)
Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.
0
Attacker Value
Unknown
CVE-2021-20729
Disclosure Date: March 31, 2022 (last updated October 07, 2023)
Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier) allows a remote attacker to inject an arbitrary script via a malicious URL.
0
Attacker Value
Unknown
CVE-2022-21132
Disclosure Date: March 10, 2022 (last updated October 07, 2023)
Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0.1.6 versions prior to 0.1.6_1 allows a remote authenticated attacker to lead a pfSense user to view a file outside the public folder.
0