Vulnerability index

Browse CVEs

74 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Integria Ims MEDIUM 6.5
CVE-2018-19829

Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary user when the ID number is kn…

No fix yet
Fix from $1,600 2018-12-18
Integria Ims MEDIUM 6.1
CVE-2018-19828

Artica Integria IMS 5.0.83 has XSS via the search_string parameter.

No fix yet
Fix from $1,600 2018-12-17
Pandora Fms CRITICAL 9.8
CVE-2018-11221EPSS 6%

Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/up…

Fix: after 7.23
Fix from $2,300 2018-06-16
Pandora Fms HIGH 7.5
CVE-2018-11222EPSS 7%

Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php ajax …

Fix: after 7.23
Fix from $1,950 2018-06-16
Pandora Fms MEDIUM 6.5
CVE-2017-15937

Artica Pandora FMS version 7.0 leaks a full installation pathname via GET data when intercepting the main page's graph requisition. This also implies…

Mitigation only
Fix from $1,600 2017-10-27
Pandora Fms HIGH 7.2
CVE-2017-15935

Artica Pandora FMS version 7.0 is vulnerable to remote PHP code execution through the manager files function. This is only exploitable by administrat…

Mitigation only
Fix from $1,950 2017-10-27
Pandora Fms MEDIUM 5.4
CVE-2017-15934

Artica Pandora FMS version 7.0 is vulnerable to stored Cross-Site Scripting in the map name parameter.

Mitigation only
Fix from $1,600 2017-10-27
Pandora Fms MEDIUM 5.4
CVE-2017-15936

In Artica Pandora FMS version 7.0, an Attacker with write Permission can create an agent with an XSS Payload; when a user enters the agent definition…

Mitigation only
Fix from $1,600 2017-10-27
Pandora Fms HIGH 10.0
CVE-2010-4279EPSS 66%

The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypa…

Fix: after 3.1
Fix from $1,950 2010-12-02
Pandora Fms HIGH 7.5
CVE-2010-4280EPSS 5%

Multiple SQL injection vulnerabilities in Pandora FMS before 3.1.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the id_…

Fix: after 3.1
Fix from $1,950 2010-12-02
Pandora Fms HIGH 7.5
CVE-2010-4281EPSS 10%

Incomplete blacklist vulnerability in the safe_url_extraclean function in ajax.php in Pandora FMS before 3.1.1 allows remote attackers to execute arb…

Fix: after 3.1
Fix from $1,950 2010-12-02
Pandora Fms HIGH 7.5
CVE-2010-4282EPSS 20%

Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) …

Fix: after 3.1
Fix from $1,950 2010-12-02
Pandora Fms HIGH 7.5
CVE-2010-4283EPSS 9%

PHP remote file inclusion vulnerability in extras/pandora_diag.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code …

Fix: after 3.1
Fix from $1,950 2010-12-02
Pandora Fms HIGH 9.0
CVE-2010-4278EPSS 11%

operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters…

Fix: after 3.1
Fix from $1,950 2010-12-02