Vulnerabilities (CVE)

Filtered by vendor Pfsense Subscribe
Filtered by product Pfsense
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-26693 1 Pfsense 1 Pfsense 2024-11-21 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which allows an authenticated attacker to execute arbitrary web scripts via exploitation of the load_balancer_monitor.php function.
CVE-2016-10709 1 Pfsense 1 Pfsense 2024-11-21 9.0 HIGH 8.8 HIGH
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php graph parameter, related to _rrd_graph_img.php.