Core
Opnsense · 7 CVEs
CVE-2026-53581
CRITICAL
ntp: write path traversal
Sep 8, 2026
CVE-2026-45158
CRITICAL
OPNsense: Command Injection via Attacker-Controlled DHCP Config
May 13, 2026
CVE-2026-44194
CRITICAL
OPNsense: RCE on user managment
May 13, 2026
CVE-2026-44195
MEDIUM
OPNsense: Authentication lockout bypass
May 13, 2026
CVE-2026-44193
CRITICAL
OPNsense: RCE via XMLRPC endpoint using `opnsense.restore_config_section` method
May 13, 2026
CVE-2026-34578
HIGH
OPNsense has an LDAP Injection via Unsanitized Username in Authentication
Apr 9, 2026
CVE-2026-30868
HIGH
Cross-Site Request Forgery (CSRF) in opnsense/core
Mar 11, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-53581 | ntp: write path traversal | CRITICAL | 0.47% | Sep 8, 2026 |
| CVE-2026-45158 | OPNsense: Command Injection via Attacker-Controlled DHCP Config | CRITICAL | 0.82% | May 13, 2026 |
| CVE-2026-44194 | OPNsense: RCE on user managment | CRITICAL | 0.82% | May 13, 2026 |
| CVE-2026-44195 | OPNsense: Authentication lockout bypass | MEDIUM | 0.38% | May 13, 2026 |
| CVE-2026-44193 | OPNsense: RCE via XMLRPC endpoint using `opnsense.restore_config_section` method | CRITICAL | 0.86% | May 13, 2026 |
| CVE-2026-34578 | OPNsense has an LDAP Injection via Unsanitized Username in Authentication | HIGH | 0.48% | Apr 9, 2026 |
| CVE-2026-30868 | Cross-Site Request Forgery (CSRF) in opnsense/core | HIGH | 0.19% | Mar 11, 2026 |
Showing 1 to 7 of 7 CVEs