VYPR

Vendor CVEs

Pandora

All CVEs

91 total · sorted by risk
  • CVE-2026-30811MedApr 13, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affects Pandora FMS: from 777 through 800

  • CVE-2023-24517MedAug 22, 2023
    risk 0.42cvss 6.4epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this issue ( unrestricted file upload ) to execute arbitrary system commands. This issue affects Pandora FMS v767 version and prior…

  • CVE-2023-2807MedJun 13, 2023
    risk 0.42cvss 6.4epss 0.01

    Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all…

  • CVE-2022-47373MedFeb 15, 2023
    risk 0.42cvss 6.4epss 0.00

    Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vulnerability arises on the forget password functionality in which parameter username does not proper input validation/sanitization thus results in executing…

  • CVE-2022-45437MedFeb 15, 2023
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artica PFMS Pandora FMS v765 on all allows Cross-Site Scripting (XSS). A user with edition privileges can create a Payload in the reporting dashboard module. An admin user can…

  • CVE-2023-24514MedAug 22, 2023
    risk 0.41cvss 6.3epss 0.00

    Cross-site Scripting (XSS) vulnerability in Visual Console Module of Pandora FMS could be used to hijack admin users session cookie values, carry out phishing attacks, etc. This issue affects Pandora FMS v767 version and prior versions on all platforms.

  • CVE-2023-44089MedDec 29, 2023
    risk 0.40cvss 6.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). It was possible to execute malicious JS code on Visual Consoles. This issue affects Pandora FMS: from 700 through 774.

  • CVE-2023-41787MedNov 23, 2023
    risk 0.39cvss 6.0epss 0.01

    Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths. This vulnerability allows access to files with sensitive information. This issue affects Pandora FMS: from 700 through 772.

  • CVE-2023-41792MedNov 23, 2023
    risk 0.38cvss 5.9epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in the SNMP Trap Editor. This issue affects Pandora FMS: from 700 through 773.

  • CVE-2023-24516MedAug 22, 2023
    risk 0.38cvss 5.9epss 0.00

    Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of admin users easily with little user interaction. This issue affects Pandora FMS v767 version and prior versions on all platforms.

  • CVE-2022-43979MedJan 27, 2023
    risk 0.38cvss 5.9epss 0.01

    There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that the parameter that the user has inserted does not contain malicious characteres, but this check is insufficient. An attacker could insert an absolute path to…

  • CVE-2022-0507MedMar 10, 2022
    risk 0.38cvss 5.8epss 0.01

    Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This vulnerability could allow an attacker with authenticated IP to inject SQL.

  • CVE-2023-41812MedNov 23, 2023
    risk 0.37cvss 5.7epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not Properly Constrained by ACLs. This vulnerability allowed PHP executable files to be uploaded through the file manager. This issue affects Pandora FMS: from 700…

  • CVE-2022-1648MedJul 26, 2022
    risk 0.37cvss 5.7epss 0.01

    Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to a Remote Code Execution with running…

  • CVE-2024-41200MedAug 5, 2024
    risk 0.36cvss 5.5epss 0.00

    A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.

  • CVE-2022-43978MedJan 27, 2023
    risk 0.36cvss 5.6epss 0.00

    There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid session when he is not trying to do a login. Since the secret is static in generatePublicHash function, an attacker with knowledge of a valid session can…

  • CVE-2026-30812MedApr 13, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event comments. This issue affects Pandora FMS: from 777 through 800

  • CVE-2021-36698MedNov 3, 2021
    risk 0.35cvss 5.4epss 0.01

    Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.

  • CVE-2023-44088MedDec 29, 2023
    risk 0.34cvss 5.9epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS: from 700…

  • CVE-2023-41811MedNov 23, 2023
    risk 0.34cvss 5.3epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in the news section of the web console. This issue affects…

  • CVE-2023-24515MedAug 22, 2023
    risk 0.34cvss 5.2epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL scheme used while retrieving API URL. Rather than validating the http/https scheme, the application allows other scheme such as file, which could allow a…

  • CVE-2023-1745MedMar 30, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in KMPlayer 4.2.2.73. This issue affects some unknown processing in the library SHFOLDER.dll. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been…

  • CVE-2022-43980MedJan 27, 2023
    risk 0.34cvss 5.2epss 0.00

    There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An attacker could modify a network map, including on purpose the name of an XSS payload. Once created, if a user with admin privileges clicks on the edited network…

  • CVE-2023-41810MedNov 23, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in some Widgets' text box. This issue affects Pandora FMS: from…

  • CVE-2021-46681MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via module massive operation name field.

  • CVE-2021-46680MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the module form name field.

  • CVE-2021-46679MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via service elements.

  • CVE-2021-46678MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the service name field.

  • CVE-2021-46677MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the event filter name field.

  • CVE-2021-46676MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the transactional maps name field.

  • CVE-2023-41814LowDec 29, 2023
    risk 0.24cvss 3.7epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Through an HTML payload (iframe tag) it is possible to carry out XSS attacks when the user receiving the messages opens…

  • CVE-2022-26309LowAug 1, 2022
    risk 0.24cvss 3.7epss 0.00

    Pandora FMS v7.0NG.759 allows Cross-Site Request Forgery in Bulk operation (User operation) resulting in elevation of privilege to Administrator group.

  • CVE-2022-26308LowAug 1, 2022
    risk 0.24cvss 3.7epss 0.00

    Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intended role.

  • CVE-2022-2059LowJul 25, 2022
    risk 0.23cvss 3.5epss 0.00

    In Pandora FMS v7.0NG.761 and below, in the agent creation section, the alias parameter is vulnerable to a Stored Cross Site-Scripting. This vulnerability can be exploited by an attacker with administrator privileges logged in the system.

  • CVE-2022-2032LowJul 25, 2022
    risk 0.23cvss 3.5epss 0.00

    In Pandora FMS v7.0NG.761 and below, in the file manager section, the dirname parameter is vulnerable to a Stored Cross Site-Scripting. This vulnerability can be exploited by an attacker with administrator privileges logged in the system.

  • CVE-2023-41813LowDec 29, 2023
    risk 0.20cvss 3.0epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Allows you to edit the Web Console user notification options. This issue affects Pandora FMS: from 700 through 774.

  • CVE-2010-4282Dec 2, 2010
    risk 0.05cvss epss 0.20

    Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote attackers to include and…

  • CVE-2010-4283Dec 2, 2010
    risk 0.04cvss epss 0.09

    PHP remote file inclusion vulnerability in extras/pandora_diag.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the argv[1] parameter.

  • CVE-2010-4281Dec 2, 2010
    risk 0.04cvss epss 0.10

    Incomplete blacklist vulnerability in the safe_url_extraclean function in ajax.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code by using a page parameter containing a UNC share pathname, which bypasses the check for the : (colon) character.

  • CVE-2010-4278Dec 2, 2010
    risk 0.04cvss epss 0.11

    operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the layout parameter in an operation/agentes/networkmap action to index.php.

  • CVE-2014-8629Nov 19, 2014
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the Page visualization agents in Pandora FMS 5.1 SP1 and earlier allows remote attackers to inject arbitrary web script or HTML via the refr parameter to index.php.

Page 2 of 2