Vulnerability index

Browse CVEs

74 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pandora Fms MEDIUM 6.1
CVE-2023-41792

Cross-Site Request Forgery (CSRF) vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code t…

Fix: after 773
Fix from $1,600 2023-11-23
Pandora Fms MEDIUM 6.1
CVE-2023-41810

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting …

Fix: after 773
Fix from $1,600 2023-11-23
Pandora Fms CRITICAL 9.8
CVE-2023-41790

Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths. This vulnerabili…

Fix: after 773
Fix from $2,300 2023-11-23
Pandora Fms HIGH 8.8
CVE-2023-41788

Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not Properly Constrained by ACLs. …

Fix: 774+
Fix from $1,950 2023-11-23
Pandora Fms HIGH 7.5
CVE-2023-41787

Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths. This vulnerabili…

Fix: 773+
Fix from $1,950 2023-11-23
Pandora Fms MEDIUM 6.5
CVE-2023-41786

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pandora FMS on all allows File Discovery. This vulnerability allows users…

Fix: 773+
Fix from $1,600 2023-11-23
Pandora Fms MEDIUM 6.1
CVE-2023-41789

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting …

Fix: after 773
Fix from $1,600 2023-11-23
Pandora Fms MEDIUM 5.4
CVE-2023-41791

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting …

Fix: after 773
Fix from $1,600 2023-11-23
Pandora Fms MEDIUM 6.1
CVE-2021-46681

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via module massive oper…

Fix: 757+
Fix from $1,600 2022-08-05
Pandora Fms MEDIUM 6.7
CVE-2021-36697

With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file cont…

Fix: after 755
Fix from $1,600 2021-11-03
Pandora Fms MEDIUM 5.4
CVE-2021-36698

Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.

Fix: after 755
Fix from $1,600 2021-11-03
Integria Ims MEDIUM 6.1
CVE-2021-3834

Integria IMS in its 5.0.92 version does not filter correctly some fields related to the login.php file. An attacker could exploit this vulnerability …

Mitigation only
Fix from $1,600 2021-10-07
Integria Ims CRITICAL 9.8
CVE-2021-3833

Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash stored in the d…

Mitigation only
Fix from $2,300 2021-10-07
Integria Ims CRITICAL 9.8
CVE-2021-3832

Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenticated attacker could abuse th…

Mitigation only
Fix from $2,300 2021-10-07
Pandora Fms MEDIUM 5.9
CVE-2021-34075

In Artica Pandora FMS <=754 in the File Manager component, there is sensitive information exposed on the client side which attackers can access.

Fix: after 754
Fix from $1,600 2021-06-30
Pandora Fms CRITICAL 9.8
CVE-2021-32098

Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.

No fix yet
Fix from $2,300 2021-05-07
Pandora Fms CRITICAL 9.8
CVE-2021-32099EPSS 11%

A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileg…

No fix yet
Fix from $2,300 2021-05-07
Pandora Fms MEDIUM 6.5
CVE-2021-32100

A remote file inclusion vulnerability exists in Artica Pandora FMS 742, exploitable by the lowest privileged user.

No fix yet
Fix from $1,600 2021-05-07
Pandora Fms CRITICAL 9.8
CVE-2020-26518

Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php s…

Fix: 743+
Fix from $2,300 2020-10-02
Pandora Fms HIGH 7.2
CVE-2020-7935

Artica Pandora FMS through 7.42 is vulnerable to remote PHP code execution because of an Unrestricted Upload Of A File With A Dangerous Type issue in…

Fix: after 7.42
Fix from $1,950 2020-03-23
Pandora Fms HIGH 7.2
CVE-2020-8511

In Artica Pandora FMS through 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the File Repository component, a differen…

Fix: after 7.42
Fix from $1,950 2020-03-23
Pandora Fms MEDIUM 5.3
CVE-2020-8497EPSS 5%

In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, use…

Fix: after 7.42
Fix from $1,600 2020-03-23
Pandora Fms HIGH 7.2
CVE-2020-5844EPSS 30%

index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP script…

No fix yet
Fix from $1,950 2020-03-16
Pandora Fms HIGH 7.2
CVE-2020-8500

In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Extension component. NOTE: The ven…

No fix yet
Fix from $1,950 2020-03-02
Pandora Fms HIGH 7.2
CVE-2020-8947EPSS 22%

functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?op…

No fix yet
Fix from $1,950 2020-02-12
Pandora Fms MEDIUM 6.8
CVE-2019-20050

Pandora FMS ≤ 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated user should create a new folder…

No fix yet
Fix from $1,600 2020-01-30
Pandora Fms HIGH 8.8
CVE-2019-20224EPSS 50%

netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metachar…

No fix yet
Fix from $1,950 2020-01-09
Pandora Fms HIGH 8.8
CVE-2019-19681

Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to defin…

Mitigation only
Fix from $1,950 2019-12-26
Integria Ims CRITICAL 9.8
CVE-2019-15091

filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary file upload.

Mitigation only
Fix from $2,300 2019-08-16
Integria Ims HIGH 8.1
CVE-2018-1000812

Artica Integria IMS version 5.0 MR56 Package 58, likely earlier versions contains a CWE-640: Weak Password Recovery Mechanism for Forgotten Password …

Fix: after 5.0
Fix from $1,950 2018-12-20