Filtered by vendor Artica
Subscribe
Total
74 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-36698 | 1 Artica | 1 Pandora Fms | 2026-07-09 | 3.5 LOW | 5.4 MEDIUM |
| Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name. | |||||
| CVE-2021-36697 | 1 Artica | 1 Pandora Fms | 2026-07-09 | 4.6 MEDIUM | 6.7 MEDIUM |
| With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file type" and the code can be executed with an HTTP request. | |||||
| CVE-2026-34188 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 7.2 HIGH |
| Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Event Response execution. This issue affects Pandora FMS: from 777 through 800 | |||||
| CVE-2026-34187 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 9.8 CRITICAL |
| Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affects Pandora FMS: from 777 through 800 | |||||
| CVE-2026-34186 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 8.8 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via custom fields. This issue affects Pandora FMS: from 777 through 800 | |||||
| CVE-2026-30813 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 8.8 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via module search. This issue affects Pandora FMS: from 777 through 800 | |||||
| CVE-2026-30812 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event comments. This issue affects Pandora FMS: from 777 through 800 | |||||
| CVE-2026-30811 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 6.5 MEDIUM |
| Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affects Pandora FMS: from 777 through 800 | |||||
| CVE-2026-30810 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 8.8 HIGH |
| Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800 | |||||
| CVE-2026-30809 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 8.8 HIGH |
| Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via WebServerModuleDebug. This issue affects Pandora FMS: from 777 through 800 | |||||
| CVE-2026-30808 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 8.1 HIGH |
| Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777 through 800 | |||||
| CVE-2026-30807 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 8.8 HIGH |
| Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 through 800 | |||||
| CVE-2026-30806 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 8.8 HIGH |
| Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Network Report. This issue affects Pandora FMS: from 777 through 800 | |||||
| CVE-2026-30805 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 9.1 CRITICAL |
| Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800 | |||||
| CVE-2026-30804 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 7.2 HIGH |
| Unrestricted Upload of File with Dangerous Type vulnerability allows Remote Code Execution via file upload. This issue affects Pandora FMS: from 777 through 800 | |||||
| CVE-2025-5306 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 9.8 CRITICAL |
| Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778 | |||||
| CVE-2024-35307 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 9.8 CRITICAL |
| Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777. | |||||
| CVE-2024-35306 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 9.8 CRITICAL |
| OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This issue affects Pandora FMS: from 700 through <777. | |||||
| CVE-2024-35305 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 9.8 CRITICAL |
| Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777. | |||||
| CVE-2024-35304 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 9.8 CRITICAL |
| System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. This issue affects Pandora FMS: from 700 through <777. | |||||
