VYPR

Adguardhome

by AdGuard

Source repositories

CVEs (4)

  • CVE-2026-32136CriMar 11, 2026
    risk 0.64cvss 9.8epss 0.01

    AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentication in AdGuardHome by sending an HTTP/1.1 request that requests an upgrade to HTTP/2 cleartext (h2c). Once the upgrade is…

  • CVE-2021-27935HigMar 3, 2021
    risk 0.49cvss 7.5epss 0.05

    An issue was discovered in AdGuard before 0.105.2. An attacker able to get the user's cookie is able to bruteforce their password offline, because the hash of the password is stored in the cookie.

  • CVE-2022-32175MedOct 11, 2022
    risk 0.28cvss 5.4epss 0.00

    In AdGuardHome, versions v0.95 through v0.108.0-b.13 are vulnerable to Cross-Site Request Forgery (CSRF), in the custom filtering rules functionality. An attacker can persuade an authorized user to follow a malicious link, resulting in deleting/modifying the custom filtering…

  • CVE-2026-47703MedJul 15, 2026
    risk 0.27cvss 5.3epss 0.00

    AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.75, AdGuard Home's client-triggered DoQ forwarding path to a udp:// upstream reduced backend UDP DNS state by producing dns_id=0 or txid=0 and exposed a quoted-port ICMP source-port oracle,…