Known Vulnerabilities for products from Untangle
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Untangle".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-46141 json | Not Provided | 2026-05-28 | 2026-06-14 | |
| CVE-2020-17494 json | Untangle Firewall NG before 16.0 uses MD5 for passwords. | 5.3 - MEDIUM | 2020-11-12 | 2021-07-21 |
| CVE-2019-18649 json | When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to st... | 4.8 - MEDIUM | 2019-11-14 | 2019-11-14 |
| CVE-2019-18648 json | When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specif... | 4.8 - MEDIUM | 2019-11-14 | 2019-11-14 |
| CVE-2019-18647 json | The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user. | 7.2 - HIGH | 2019-11-14 | 2020-08-24 |
| CVE-2019-18646 json | The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn pa... | 7.2 - HIGH | 2019-11-14 | 2019-11-14 |
Known software with vulnerabilities from Untangle
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Untangle | Ng Firewall | 14.2.0 |
| Application | Untangle | Untangle Firewall Ng | - |