VendorsArticapandora_fmsall versions
Vulnerabilities

Artica Pandora FMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

67CVEs
CVE-2010-4279
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash of "admin" in the loginhash_data parameter.
Published 2010-12-02 · Modified
10.02 PoCEPSS 0.656
CVE-2025-5306
Command Injection in Netflow path
Published 2025-06-27 · Analyzed
9.8EPSS 0.317
CVE-2021-32099
A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.
Published 2021-05-07 · Modified
9.8EPSS 0.127
CVE-2018-11221
Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/update_manager.ajax in the update system.
Published 2018-06-15 · Modified
9.8EPSS 0.056
CVE-2021-32098
Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.
Published 2021-05-07 · Modified
9.8EPSS 0.025
CVE-2020-26518
Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php session_id parameter.
Published 2020-10-02 · Modified
9.8EPSS 0.021
CVE-2024-12992
Remote Code Execution leads to Command Injection
Published 2025-03-17 · Analyzed
9.8EPSS 0.012
CVE-2024-35304
System command injection through Netflow function
Published 2024-06-10 · Analyzed
9.8EPSS 0.011
CVE-2024-35306
OS Command injection in Ajax PHP files through HTTP Request
Published 2024-06-10 · Analyzed
9.8EPSS 0.009
CVE-2024-35307
Argument Injection Leading to Remote Code Execution in Realtime Graph Extension
Published 2024-06-10 · Analyzed
9.8EPSS 0.009
CVE-2023-41790
Traversal Path on PHP file
Published 2023-11-23 · Modified
9.8EPSS 0.006
CVE-2023-4677
Unauthenticated Admin Account Takeover Via Cron Log File Backups
Published 2023-11-23 · Modified
9.8EPSS 0.005
CVE-2023-44091
Unauth Time-Based SQL Injection
Published 2024-03-19 · Analyzed
9.8EPSS 0.005
CVE-2026-34187
SQL Injection in Graph Container Parameter
Published 2026-05-12 · Analyzed
9.8EPSS 0.004
CVE-2024-35305
Unauth Time-Based SQL Injection via API
Published 2024-06-10 · Analyzed
9.8EPSS 0.004
CVE-2023-44092
OS Command Injection
Published 2024-03-19 · Analyzed
9.1EPSS 0.008
CVE-2023-41807
Linux Local Privilege Escalation Via GoTTY Page
Published 2023-11-23 · Modified
9.1EPSS 0.007
CVE-2026-30805
Insecure Default Initialization in API Authentication leads to Authentication Bypass
Published 2026-05-12 · Analyzed
9.1EPSS 0.005
CVE-2019-20224
netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742.
Published 2020-01-09 · Modified
9.0EPSS 0.497
CVE-2020-8947
functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?operation/netflow/nf_live_view ip_dst, dst_port, or src_port parameter, a different vulnerability than CVE-2019-20224.
Published 2020-02-12 · Modified
9.01 PoCEPSS 0.225
CVE-2010-4278
operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the layout parameter in an operation/agentes/networkmap action to index.php.
Published 2010-12-02 · Modified
9.01 PoCEPSS 0.113
CVE-2019-19681
Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to define and execute commands as root/Administrator. NOTE: The product vendor states that the vulnerability as it is described is not in fact an actual vulnerability. They state that to be able to create alert commands, you need to have admin rights. They also state that the extended ACL system can disable access to specific sections of the configuration, such as defining new alert commands
Published 2019-12-26 · Modified
9.0EPSS 0.046
CVE-2017-15935
Artica Pandora FMS version 7.0 is vulnerable to remote PHP code execution through the manager files function. This is only exploitable by administrators who upload a PHP file.
Published 2017-10-27 · Modified
9.0EPSS 0.025
CVE-2024-12971
QuickShell Authenticated Command Injection
Published 2025-03-17 · Analyzed
8.8EPSS 0.615
CVE-2026-30809
OS Command Injection in WebServerModuleDebug via Blacklist Bypass leads to Remote Code Execution
Published 2026-04-13 · Analyzed
8.8EPSS 0.016
CVE-2026-30806
OS Command Injection in Network Report leads to Remote Code Execution
Published 2026-04-13 · Analyzed
8.8EPSS 0.016
CVE-2023-41788
Remote Code Execution via File Uploader
Published 2023-11-23 · Modified
8.8EPSS 0.007
CVE-2023-41812
Uploading executables via the file manager
Published 2023-11-23 · Modified
8.8EPSS 0.006
CVE-2026-34186
SQL Injection in Custom Fields leads to Database Compromise
Published 2026-04-13 · Analyzed
8.8EPSS 0.004
CVE-2026-30813
SQL Injection in Module Search leads to Database Compromise
Published 2026-04-13 · Analyzed
8.8EPSS 0.004
CVE-2026-30810
Server-Side Request Forgery in API Checker leads to Privilege Escalation
Published 2026-05-12 · Analyzed
8.8EPSS 0.004
CVE-2026-30807
Cross-Site Request Forgery on Extension Pages
Published 2026-05-12 · Analyzed
8.8EPSS 0.002
CVE-2026-30804
Unrestricted File Upload in Extension Uploader leads to Remote Code Execution
Published 2026-04-13 · Analyzed
8.6EPSS 0.008
CVE-2023-41808
Arbitrary File Read As Root Via GoTTY Page
Published 2023-11-23 · Modified
8.5EPSS 0.005
CVE-2023-41791
Lack of Authorization and Stored XSS Via Translation Abuse
Published 2023-11-23 · Modified
8.4EPSS 0.005
CVE-2026-30811
Missing Authorization in Configuration Ajax Endpoint leads to Information Disclosure
Published 2026-04-13 · Analyzed
8.4EPSS 0.003
CVE-2023-41806
Misassignment of privileges can cause DOS attack
Published 2023-11-23 · Modified
8.2EPSS 0.005
CVE-2026-30808
Session Fixation in Authentication leads to Session Hijacking
Published 2026-05-12 · Analyzed
8.1EPSS 0.004
CVE-2023-41789
Unauthenticated Admin Account Takeover Via XSS
Published 2023-11-23 · Modified
7.6EPSS 0.005
CVE-2010-4282
Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote attackers to include and execute, create, modify, or delete arbitrary local files via (3) the layout parameter to operation/agentes/networkmap.php.
Published 2010-12-02 · Modified
7.51 PoCEPSS 0.196
1 / 2Next →