VYPR

Pandorafms

by Artica

CVEs (78)

  • CVE-2025-5306CriJun 27, 2025
    risk 0.68cvss 9.8epss 0.31

    Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778

  • CVE-2020-13851HigJun 11, 2020
    risk 0.67cvss 8.8epss 0.91

    Artica Pandora FMS 7.44 allows remote command execution via the events feature.

  • CVE-2024-12971HigMar 17, 2025
    risk 0.65cvss 8.8epss 0.58

    Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6

  • CVE-2021-32099CriMay 7, 2021
    risk 0.65cvss 9.8epss 0.11

    A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.

  • CVE-2026-34187CriMay 12, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affects Pandora FMS: from 777 through 800

  • CVE-2024-12992CriMar 17, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection via RCE. This issue affects Pandora FMS from 700 to 777.6 .

  • CVE-2024-35307CriJun 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777.

  • CVE-2024-35306CriJun 10, 2024
    risk 0.64cvss 9.8epss 0.01

    OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This issue affects Pandora FMS: from 700 through <777.

  • CVE-2024-35305CriJun 10, 2024
    risk 0.64cvss 9.8epss 0.00

    Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.

  • CVE-2024-35304CriJun 10, 2024
    risk 0.64cvss 9.8epss 0.01

    System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. This issue affects Pandora FMS: from 700 through <777.

  • CVE-2021-32098CriMay 7, 2021
    risk 0.64cvss 9.8epss 0.02

    Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.

  • CVE-2020-26518CriOct 2, 2020
    risk 0.64cvss 9.8epss 0.02

    Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php session_id parameter.

  • CVE-2020-13854CriJun 11, 2020
    risk 0.64cvss 9.8epss 0.03

    Artica Pandora FMS 7.44 allows privilege escalation.

  • CVE-2018-11221CriJun 16, 2018
    risk 0.64cvss 9.8epss 0.06

    Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/update_manager.ajax in the update system.

  • CVE-2025-34088HigJul 3, 2025
    risk 0.61cvss 8.8epss 0.05

    An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenticated users to execute arbitrary OS commands via the select_ips parameter when performing network tools operations, such as…

  • CVE-2019-20224HigJan 9, 2020
    risk 0.61cvss 8.8epss 0.50

    netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS…

  • CVE-2026-30805CriMay 12, 2026
    risk 0.59cvss 9.1epss 0.00

    Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800

  • CVE-2023-41807CriNov 23, 2023
    risk 0.59cvss 9.1epss 0.01

    Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability allows a user to escalate permissions on the system shell. This issue affects Pandora FMS: from 700 through 773.

  • CVE-2019-19681HigDec 26, 2019
    risk 0.58cvss 8.8epss 0.05

    Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to define and execute commands as root/Administrator. NOTE: The product vendor states that the vulnerability as it is described is not in…

  • CVE-2026-30810HigMay 12, 2026
    risk 0.57cvss 8.8epss 0.00

    Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800

Page 1 of 4