Vulnerabilities in NETGATE

21 results
Vexday analysis

A Netgate possui apenas 1 vulnerabilidade registrada na base, sem exploração ativa conhecida ou classificação crítica, reduzindo significativamente o risco imediato. A fraqueza identificada (CWE-428) não está sob ataque e não foi publicada recentemente, indicando um cenário de risco baixo no contexto atual.

CVE-2018-4021HIGHAn exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POSEPSS 72.2%CVE-2018-4020HIGHAn exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POSEPSS 48.7%CVE-2018-4019HIGHAn exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POSEPSS 48.7%CVE-2025-12490HIGHNetgate pfSense CE Suricata Path Traversal Remote Code Execution VulnerabilityEPSS 20.1%CVE-2025-34176MEDIUMNetgate pfSense CE Suricata Package v7.0.8_2 Directory Traversal Information DisclosureEPSS 15.0%CVE-2025-34175MEDIUMNetgate pfSense CE Suricata package v7.0.8_2 Reflected Cross-Site ScriptingEPSS 14.8%CVE-2025-34174MEDIUMNetgate pfSense CE Status_Traffic_Totals Package v2.3.2_7 Stored Cross-Site ScriptingEPSS 9.8%CVE-2025-34178MEDIUMNetgate pfSense CE Suricata package v7.0.8_2 Stored Cross-Site ScriptingEPSS 3.7%CVE-2025-53392MEDIUMIn Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directEPSS 1.8%CVE-2026-67189MEDIUMpfSense Plus/CE Stored XSS via Traffic Graphs PTR RecordEPSS 1.2%CVE-2026-56127MEDIUMpfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_rules_edit.phpEPSS 1.1%CVE-2026-56126MEDIUMpfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via status_monitoring.phpEPSS 1.1%CVE-2026-56128MEDIUMpfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_schedule_edit.phpEPSS 1.1%CVE-2025-34172MEDIUMNetgate pfSense CE HAProxy Package 0.63_10 Reflected Cross-Site ScriptingEPSS 1.0%CVE-2026-97730HIGHIn Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) wiEPSS 1.0%CVE-2025-34173MEDIUMNetgate pfSense CE Snort package v4.1.6_25 Directory Traversal Information DisclosureEPSS 0.9%CVE-2025-34177MEDIUMNetgate pfSense CE Suricata package v7.0.8_2 Stored Cross-Site ScriptingEPSS 0.9%CVE-2016-20058HIGHNetgate AMITI Antivirus build 23.0.305 Unquoted Service Path Privilege EscalationEPSS 0.7%CVE-2016-20057HIGHNETGATE Registry Cleaner build 16.0.205 Unquoted Service Path Privilege EscalationEPSS 0.6%CVE-2019-25271HIGHNETGATE Data Backup 3.0.620 - 'NGDatBckpSrv' Unquoted Service PathEPSS 0.3%