Vulnerability index

Browse CVEs

42 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2025-34088EPSS 5% An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenti… Pandora Fms after 7.0_ng Fix from $1,9502025-07-03 CRITICAL 9.8 CVE-2024-11320EPSS 91% Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects P… Pandora Fms 777.5+ Fix from $2,3002024-11-21 HIGH 8.8 CVE-2024-9987 A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv functionality. This issue affects… Pandora Fms after 777.3 Fix from $1,9502024-10-22 HIGH 8.8 CVE-2024-35308 A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: … Pandora Fms 777.3+ Fix from $1,9502024-10-22 MEDIUM 6.1 CVE-2023-44089 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting … Pandora Fms after 774 Fix from $1,6002023-12-29 HIGH 8.8 CVE-2023-44088 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitr… Pandora Fms after 774 Fix from $1,9502023-12-29 MEDIUM 6.1 CVE-2023-41813 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting … Pandora Fms after 774 Fix from $1,6002023-12-29 MEDIUM 6.1 CVE-2023-41814 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting … Pandora Fms after 774 Fix from $1,6002023-12-29 MEDIUM 6.1 CVE-2023-41815 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting … Pandora Fms after 774 Fix from $1,6002023-12-29 HIGH 7.1 CVE-2023-24518 A Cross-site Request Forgery (CSRF) vulnerability in Pandora FMS allows an attacker to force authenticated users to send a request to a web applicati… Pandora Fms after 767 Fix from $1,9502023-10-03 MEDIUM 6.1 CVE-2023-0828 Cross-site Scripting (XSS) vulnerability in Syslog Section of Pandora FMS allows attacker to cause that users cookie value will be transferred to the… Pandora Fms after 767 Fix from $1,6002023-10-03 HIGH 7.2 CVE-2023-24517 Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this … Pandora Fms after 767 Fix from $1,9502023-08-22 MEDIUM 6.5 CVE-2023-24515 Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL scheme used while retrie… Pandora Fms after 767 Fix from $1,6002023-08-22 MEDIUM 6.1 CVE-2023-24514 Cross-site Scripting (XSS) vulnerability in Visual Console Module of Pandora FMS could be used to hijack admin users session cookie values, carry out… Pandora Fms after 767 Fix from $1,6002023-08-22 MEDIUM 5.4 CVE-2023-24516 Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of… Pandora Fms after 767 Fix from $1,6002023-08-22 CRITICAL 9.8 CVE-2023-2807 Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a passwor… Pandora Fms 772+ Fix from $2,3002023-06-13 MEDIUM 6.1 CVE-2022-47373 Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vulnerability arises on the forg… Pandora Fms after 766 Fix from $1,6002023-02-15 MEDIUM 5.4 CVE-2022-47372 Stored cross-site scripting vulnerability in the Create event section in Pandora FMS Console v766 and lower. An attacker typically exploits this vuln… Pandora Fms after 766 Fix from $1,6002023-02-15 CRITICAL 9.8 CVE-2022-43979 There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that the parameter that the user ha… Pandora Fms 766+ Fix from $2,3002023-01-27 MEDIUM 5.4 CVE-2022-43980 There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An attacker could modify a networ… Pandora Fms 766+ Fix from $1,6002023-01-27 MEDIUM 6.1 CVE-2021-46677 A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the event filter na… Pandora Fms 757+ Fix from $1,6002022-08-05 MEDIUM 6.1 CVE-2021-46678 A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the service name fi… Pandora Fms 757+ Fix from $1,6002022-08-05 MEDIUM 6.1 CVE-2021-46679 A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via service elements. Pandora Fms 757+ Fix from $1,6002022-08-05 MEDIUM 6.1 CVE-2021-46680 A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the module form nam… Pandora Fms after 756 Fix from $1,6002022-08-05 MEDIUM 6.1 CVE-2021-46676 A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the transactional m… Pandora Fms 757+ Fix from $1,6002022-08-05 HIGH 8.8 CVE-2022-26309 Pandora FMS v7.0NG.759 allows Cross-Site Request Forgery in Bulk operation (User operation) resulting in elevation of privilege to Administrator grou… Pandora Fms after 7.0_ng_759 Fix from $1,9502022-08-01 HIGH 8.8 CVE-2022-26310 Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management … Pandora Fms after 7.0_ng_760 Fix from $1,9502022-08-01 MEDIUM 5.4 CVE-2022-26308 Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write)… Pandora Fms after 7.0_ng_760 Fix from $1,6002022-08-01 HIGH 7.2 CVE-2022-1648 Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intend… Pandora Fms after 7.0_ng_760 Fix from $1,9502022-07-26 HIGH 8.8 CVE-2022-0507 Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This … Pandora Fms 760+ Fix from $1,9502022-03-10