VYPR
Vendor

Pfsense

Products
14
CVEs
67
Across products
78
Status
Private

Products

14

Recent CVEs

67
View all 67 CVEs →
  • CVE-2023-27100CriMar 22, 2023
    risk 0.67cvss 9.8epss 0.10

    Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.

  • CVE-2021-41282HigMar 1, 2022
    risk 0.67cvss 8.8epss 0.87

    diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the firewall. The data is retrieved by executing the netstat utility, and then its output is parsed via the sed utility. Although the…

  • CVE-2022-40624CriDec 20, 2022
    risk 0.65cvss 9.8epss 0.17

    pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.

  • CVE-2019-16667HigSep 26, 2019
    risk 0.65cvss 8.8epss 0.55

    diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a CSRF token is missing.

  • CVE-2025-69691CriMay 8, 2026
    risk 0.64cvss 9.9epss 0.01

    Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code.

  • CVE-2023-29974CriNov 8, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.

  • CVE-2016-10709HigJan 22, 2018
    risk 0.63cvss 8.8epss 0.34

    pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php graph parameter, related to _rrd_graph_img.php.

  • CVE-2025-69690CriMay 8, 2026
    risk 0.59cvss 9.1epss 0.01

    Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only available to admins and they are…

  • CVE-2018-16055HigSep 26, 2018
    risk 0.58cvss 8.8epss 0.11

    An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to its passing user input from the $_POST parameters "ifdescr" and "ipv" to a shell without escaping the contents of the variables. This…

  • CVE-2019-16915CriSep 26, 2019
    risk 0.57cvss 9.8epss 0.04

    An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_contents or file_put_contents.

  • CVE-2019-16701HigSep 25, 2019
    risk 0.55cvss 8.8epss 0.20

    pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value.

  • CVE-2025-12490HigNov 6, 2025
    risk 0.52cvss 8.8epss 0.20

    Netgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Netgate pfSense. Authentication is required to exploit this vulnerability. The specific flaw exists…

  • CVE-2018-20799HigMar 1, 2019
    risk 0.49cvss 7.5epss 0.02

    In pfSense 2.4.4_1, blocking of source IP addresses on the basis of failed HTTPS authentication is inconsistent with blocking of source IP addresses on the basis of failed SSH authentication (the behavior does not match the sshguard documentation), which might make it easier for…

  • CVE-2018-20798HigMar 1, 2019
    risk 0.49cvss 7.5epss 0.01

    The expiretable configuration in pfSense 2.4.4_1 establishes block durations that are incompatible with the block durations implemented by sshguard, which might make it easier for attackers to bypass intended access restrictions.

  • CVE-2023-29975HigNov 9, 2023
    risk 0.47cvss 7.2epss 0.02

    An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.

  • CVE-2019-11816HigMay 20, 2019
    risk 0.47cvss 7.2epss 0.03

    Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authenticated users to escalate privileges to administrator via a specially crafted request.

  • CVE-2022-29273MedFeb 22, 2023
    risk 0.44cvss 6.1epss 0.60

    pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.

  • CVE-2022-21132MedMar 10, 2022
    risk 0.42cvss 6.5epss 0.02

    Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0.1.6 versions prior to 0.1.6_1 allows a remote authenticated attacker to lead a pfSense user to view a file outside the public folder.

  • CVE-2021-27933MedApr 28, 2021
    risk 0.42cvss 6.1epss 0.27

    pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.

  • CVE-2025-34175MedSep 9, 2025
    risk 0.41cvss 6.1epss 0.16

    In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings. This can result in reflected cross-site scripting if the victim is authenticated.