Vulnerability index

Browse CVEs

42 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pandora Fms HIGH 8.8
CVE-2025-34088EPSS 5%

An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenti…

Fix: after 7.0_ng
Fix from $1,950 2025-07-03
Pandora Fms CRITICAL 9.8
CVE-2024-11320EPSS 91%

Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects P…

Fix: 777.5+
Fix from $2,300 2024-11-21
Pandora Fms HIGH 8.8
CVE-2024-9987

A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv functionality. This issue affects…

Fix: after 777.3
Fix from $1,950 2024-10-22
Pandora Fms HIGH 8.8
CVE-2024-35308

A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: …

Fix: 777.3+
Fix from $1,950 2024-10-22
Pandora Fms MEDIUM 6.1
CVE-2023-44089

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting …

Fix: after 774
Fix from $1,600 2023-12-29
Pandora Fms HIGH 8.8
CVE-2023-44088

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitr…

Fix: after 774
Fix from $1,950 2023-12-29
Pandora Fms MEDIUM 6.1
CVE-2023-41813

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting …

Fix: after 774
Fix from $1,600 2023-12-29
Pandora Fms MEDIUM 6.1
CVE-2023-41814

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting …

Fix: after 774
Fix from $1,600 2023-12-29
Pandora Fms MEDIUM 6.1
CVE-2023-41815

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting …

Fix: after 774
Fix from $1,600 2023-12-29
Pandora Fms HIGH 7.1
CVE-2023-24518

A Cross-site Request Forgery (CSRF) vulnerability in Pandora FMS allows an attacker to force authenticated users to send a request to a web applicati…

Fix: after 767
Fix from $1,950 2023-10-03
Pandora Fms MEDIUM 6.1
CVE-2023-0828

Cross-site Scripting (XSS) vulnerability in Syslog Section of Pandora FMS allows attacker to cause that users cookie value will be transferred to the…

Fix: after 767
Fix from $1,600 2023-10-03
Pandora Fms HIGH 7.2
CVE-2023-24517

Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this …

Fix: after 767
Fix from $1,950 2023-08-22
Pandora Fms MEDIUM 6.5
CVE-2023-24515

Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL scheme used while retrie…

Fix: after 767
Fix from $1,600 2023-08-22
Pandora Fms MEDIUM 6.1
CVE-2023-24514

Cross-site Scripting (XSS) vulnerability in Visual Console Module of Pandora FMS could be used to hijack admin users session cookie values, carry out…

Fix: after 767
Fix from $1,600 2023-08-22
Pandora Fms MEDIUM 5.4
CVE-2023-24516

Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of…

Fix: after 767
Fix from $1,600 2023-08-22
Pandora Fms CRITICAL 9.8
CVE-2023-2807

Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a passwor…

Fix: 772+
Fix from $2,300 2023-06-13
Pandora Fms MEDIUM 6.1
CVE-2022-47373

Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vulnerability arises on the forg…

Fix: after 766
Fix from $1,600 2023-02-15
Pandora Fms MEDIUM 5.4
CVE-2022-47372

Stored cross-site scripting vulnerability in the Create event section in Pandora FMS Console v766 and lower. An attacker typically exploits this vuln…

Fix: after 766
Fix from $1,600 2023-02-15
Pandora Fms CRITICAL 9.8
CVE-2022-43979

There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that the parameter that the user ha…

Fix: 766+
Fix from $2,300 2023-01-27
Pandora Fms MEDIUM 5.4
CVE-2022-43980

There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An attacker could modify a networ…

Fix: 766+
Fix from $1,600 2023-01-27
Pandora Fms MEDIUM 6.1
CVE-2021-46677

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the event filter na…

Fix: 757+
Fix from $1,600 2022-08-05
Pandora Fms MEDIUM 6.1
CVE-2021-46678

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the service name fi…

Fix: 757+
Fix from $1,600 2022-08-05
Pandora Fms MEDIUM 6.1
CVE-2021-46679

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via service elements.

Fix: 757+
Fix from $1,600 2022-08-05
Pandora Fms MEDIUM 6.1
CVE-2021-46680

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the module form nam…

Fix: after 756
Fix from $1,600 2022-08-05
Pandora Fms MEDIUM 6.1
CVE-2021-46676

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the transactional m…

Fix: 757+
Fix from $1,600 2022-08-05
Pandora Fms HIGH 8.8
CVE-2022-26309

Pandora FMS v7.0NG.759 allows Cross-Site Request Forgery in Bulk operation (User operation) resulting in elevation of privilege to Administrator grou…

Fix: after 7.0_ng_759
Fix from $1,950 2022-08-01
Pandora Fms HIGH 8.8
CVE-2022-26310

Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management …

Fix: after 7.0_ng_760
Fix from $1,950 2022-08-01
Pandora Fms MEDIUM 5.4
CVE-2022-26308

Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write)…

Fix: after 7.0_ng_760
Fix from $1,600 2022-08-01
Pandora Fms HIGH 7.2
CVE-2022-1648

Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intend…

Fix: after 7.0_ng_760
Fix from $1,950 2022-07-26
Pandora Fms HIGH 8.8
CVE-2022-0507

Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This …

Fix: 760+
Fix from $1,950 2022-03-10