Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2025-34088EPSS 5%
An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenti…
Pandora Fms
after 7.0_ng
CRITICAL 9.8
CVE-2024-11320EPSS 91%
Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects P…
Pandora Fms
777.5+
HIGH 8.8
CVE-2024-9987
A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv functionality. This issue affects…
Pandora Fms
after 777.3
HIGH 8.8
CVE-2024-35308
A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: …
Pandora Fms
777.3+
MEDIUM 6.1
CVE-2023-44089
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting …
Pandora Fms
after 774
HIGH 8.8
CVE-2023-44088
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitr…
Pandora Fms
after 774
MEDIUM 6.1
CVE-2023-41813
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting …
Pandora Fms
after 774
MEDIUM 6.1
CVE-2023-41814
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting …
Pandora Fms
after 774
MEDIUM 6.1
CVE-2023-41815
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting …
Pandora Fms
after 774
HIGH 7.1
CVE-2023-24518
A Cross-site Request Forgery (CSRF) vulnerability in Pandora FMS allows an attacker to force authenticated users to send a request to a web applicati…
Pandora Fms
after 767
MEDIUM 6.1
CVE-2023-0828
Cross-site Scripting (XSS) vulnerability in Syslog Section of Pandora FMS allows attacker to cause that users cookie value will be transferred to the…
Pandora Fms
after 767
HIGH 7.2
CVE-2023-24517
Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this …
Pandora Fms
after 767
MEDIUM 6.5
CVE-2023-24515
Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL scheme used while retrie…
Pandora Fms
after 767
MEDIUM 6.1
CVE-2023-24514
Cross-site Scripting (XSS) vulnerability in Visual Console Module of Pandora FMS could be used to hijack admin users session cookie values, carry out…
Pandora Fms
after 767
MEDIUM 5.4
CVE-2023-24516
Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of…
Pandora Fms
after 767
CRITICAL 9.8
CVE-2023-2807
Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a passwor…
Pandora Fms
772+
MEDIUM 6.1
CVE-2022-47373
Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vulnerability arises on the forg…
Pandora Fms
after 766
MEDIUM 5.4
CVE-2022-47372
Stored cross-site scripting vulnerability in the Create event section in Pandora FMS Console v766 and lower. An attacker typically exploits this vuln…
Pandora Fms
after 766
CRITICAL 9.8
CVE-2022-43979
There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that the parameter that the user ha…
Pandora Fms
766+
MEDIUM 5.4
CVE-2022-43980
There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An attacker could modify a networ…
Pandora Fms
766+
MEDIUM 6.1
CVE-2021-46677
A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the event filter na…
Pandora Fms
757+
MEDIUM 6.1
CVE-2021-46678
A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the service name fi…
Pandora Fms
757+
MEDIUM 6.1
CVE-2021-46679
A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via service elements.
Pandora Fms
757+
MEDIUM 6.1
CVE-2021-46680
A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the module form nam…
Pandora Fms
after 756
MEDIUM 6.1
CVE-2021-46676
A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the transactional m…
Pandora Fms
757+
HIGH 8.8
CVE-2022-26309
Pandora FMS v7.0NG.759 allows Cross-Site Request Forgery in Bulk operation (User operation) resulting in elevation of privilege to Administrator grou…
Pandora Fms
after 7.0_ng_759
HIGH 8.8
CVE-2022-26310
Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management …
Pandora Fms
after 7.0_ng_760
MEDIUM 5.4
CVE-2022-26308
Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write)…
Pandora Fms
after 7.0_ng_760
HIGH 7.2
CVE-2022-1648
Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intend…
Pandora Fms
after 7.0_ng_760
HIGH 8.8
CVE-2022-0507
Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This …
Pandora Fms
760+