VYPR
Vendor

Artica

Products
5
CVEs
96
Across products
99
Status
Private

Products

5

Recent CVEs

96
View all 96 CVEs →
  • CVE-2020-17506CriAug 12, 2020
    risk 0.74cvss 9.8epss 0.94

    Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.

  • CVE-2025-5306CriJun 27, 2025
    risk 0.68cvss 9.8epss 0.23

    Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778

  • CVE-2020-17505HigAug 12, 2020
    risk 0.67cvss 8.8epss 0.82

    Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_peform.

  • CVE-2020-13851HigJun 11, 2020
    risk 0.67cvss 8.8epss 0.91

    Artica Pandora FMS 7.44 allows remote command execution via the events feature.

  • CVE-2024-12971HigMar 17, 2025
    risk 0.65cvss 8.8epss 0.58

    Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6

  • CVE-2024-2056CriMar 5, 2024
    risk 0.65cvss 9.8epss 0.17

    Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running as the root user, is bound to the loopback interface, and is listening on TCP port 7050. Security…

  • CVE-2021-32099CriMay 7, 2021
    risk 0.65cvss 9.8epss 0.11

    A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.

  • CVE-2026-34187CriMay 12, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affects Pandora FMS: from 777 through 800

  • CVE-2024-12992CriMar 17, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection via RCE. This issue affects Pandora FMS from 700 to 777.6 .

  • CVE-2024-35307CriJun 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777.

  • CVE-2024-35306CriJun 10, 2024
    risk 0.64cvss 9.8epss 0.01

    OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This issue affects Pandora FMS: from 700 through <777.

  • CVE-2024-35305CriJun 10, 2024
    risk 0.64cvss 9.8epss 0.00

    Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.

  • CVE-2024-35304CriJun 10, 2024
    risk 0.64cvss 9.8epss 0.01

    System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. This issue affects Pandora FMS: from 700 through <777.

  • CVE-2024-2055CriMar 5, 2024
    risk 0.64cvss 9.8epss 0.01

    The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user.

  • CVE-2021-3833CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.01

    Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash stored in the database. An attacker with a specific formatted password could exploit this vulnerability in order to login in the system with…

  • CVE-2021-3832CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.02

    Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenticated attacker could abuse the AsyncUpload() function in order to exploit the vulnerability.

  • CVE-2021-32098CriMay 7, 2021
    risk 0.64cvss 9.8epss 0.02

    Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.

  • CVE-2020-26518CriOct 2, 2020
    risk 0.64cvss 9.8epss 0.02

    Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php session_id parameter.

  • CVE-2020-13854CriJun 11, 2020
    risk 0.64cvss 9.8epss 0.03

    Artica Pandora FMS 7.44 allows privilege escalation.

  • CVE-2019-15091CriAug 16, 2019
    risk 0.64cvss 9.8epss 0.02

    filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary file upload.