Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pfsense

First CVE: Jan 3, 2012Active for: 15 yearsTotal CVEs: 31
43.9
VTI Score
High

Pfense is a widely embedded open-source firewall and routing platform deployed across small-business networks, enterprise security architectures, and service-provider infrastructure, where its compact product footprint belies substantial reach across distributed defensive perimeters. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a consistent tendency to acquire public exploit code; the exposure spans the core firewall application and its ecosystem of security packages including Suricata, Snort integration, and DNS filtering modules. The recurring weakness classes—cross-site scripting, path traversal, OS command injection, and dynamic object-attribute manipulation—reflect the complexity of web-based administrative interfaces, shell-command delegation in packet-filtering rules, and plugin architecture, creating a durable attack surface characteristic of appliance-oriented software. Defenders should prioritize patch deployment for this vendor's releases and restrict administrative access to the web interface; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 97% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pfsense over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 3, 2012
14 years ago
Most Recent CVE
May 8, 2026
77 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-41282HIGH
diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the firewall. The data is retrieved by
Mar 1, 20228.888NOYES
CVE-2016-10709HIGH
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php graph parameter, related to _rrd_graph_img
Jan 22, 20188.858NOYES
CVE-2022-40624CRITICAL
pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.
Dec 20, 20229.850NOYES
CVE-2023-27100CRITICAL
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to byp
Mar 22, 20239.845NOYES
CVE-2025-69691CRITICAL
Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they ar
May 8, 20269.936NONO
CVE-2025-69690CRITICAL
Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the
May 8, 20269.134NONO
CVE-2021-27933MEDIUM
pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.
Apr 28, 20216.133NONO
CVE-2025-34175MEDIUM
In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings. This
Sep 9, 20256.129NONO
CVE-2020-19678HIGH
Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensitive information via the file parameter
Apr 6, 20237.526NONO
CVE-2025-34176MEDIUM
In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly use
Sep 9, 20254.325NONO
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
68%
16%
16%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network25 (80.6%)
Unknown6 (19.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (80.6%)
High0 (0.0%)
Unknown6 (19.4%)
User Interaction
None14 (45.2%)
Unknown6 (19.4%)
Required11 (35.5%)
Privileges Required
Low11 (35.5%)
High3 (9.7%)
None11 (35.5%)
Unknown6 (19.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
6.5% of CVEs· 98th percentile
Nuclei
2 CVEs
6.5% of CVEs· 96th percentile
ExploitDB
1 CVE
3.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pfsense.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pfsense — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pfsense's Products

View all 3 CNAs →

Top CWEs