Products: 7
    Vulnerabilities: 32
    Known Exploited: 0
    6
    Critical Level Threats
    5
    High Level Threats
    21
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-69690

    Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only available to admins and they are intentionally allowed to execute PHP code.

    Last Modified: May 12, 2026
    Published: May 08, 2026

    CVE-2025-69691

    XMLRPC API Code Execution in Netgate pfSense CE 2.8.0

    Last Modified: May 12, 2026
    Published: May 08, 2026

    CVE-2025-34178

    Netgate pfSense CE Suricata package v7.0.8_2 Stored Cross-Site Scripting

    Last Modified: Nov 20, 2025
    Published: Sep 09, 2025

    CVE-2025-34177

    Netgate pfSense CE Suricata package v7.0.8_2 Stored Cross-Site Scripting

    Last Modified: Nov 20, 2025
    Published: Sep 09, 2025

    CVE-2025-34176

    Netgate pfSense CE Suricata Package v7.0.8_2 Directory Traversal Information Disclosure

    Last Modified: Nov 20, 2025
    Published: Sep 09, 2025
    Items Per Page
    Pfsense Vulnerabilities & Security CVEs | CVE-DB