Vulnerabilities (CVE)

Filtered by vendor Artica Subscribe
Total 74 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-36698 1 Artica 1 Pandora Fms 2026-07-09 3.5 LOW 5.4 MEDIUM
Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.
CVE-2021-36697 1 Artica 1 Pandora Fms 2026-07-09 4.6 MEDIUM 6.7 MEDIUM
With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file type" and the code can be executed with an HTTP request.
CVE-2026-34188 1 Artica 1 Pandora Fms 2026-06-17 N/A 7.2 HIGH
Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Event Response execution. This issue affects Pandora FMS: from 777 through 800
CVE-2026-34187 1 Artica 1 Pandora Fms 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affects Pandora FMS: from 777 through 800
CVE-2026-34186 1 Artica 1 Pandora Fms 2026-06-17 N/A 8.8 HIGH
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via custom fields. This issue affects Pandora FMS: from 777 through 800
CVE-2026-30813 1 Artica 1 Pandora Fms 2026-06-17 N/A 8.8 HIGH
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via module search. This issue affects Pandora FMS: from 777 through 800
CVE-2026-30812 1 Artica 1 Pandora Fms 2026-06-17 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event comments. This issue affects Pandora FMS: from 777 through 800
CVE-2026-30811 1 Artica 1 Pandora Fms 2026-06-17 N/A 6.5 MEDIUM
Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affects Pandora FMS: from 777 through 800
CVE-2026-30810 1 Artica 1 Pandora Fms 2026-06-17 N/A 8.8 HIGH
Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800
CVE-2026-30809 1 Artica 1 Pandora Fms 2026-06-17 N/A 8.8 HIGH
Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via WebServerModuleDebug. This issue affects Pandora FMS: from 777 through 800
CVE-2026-30808 1 Artica 1 Pandora Fms 2026-06-17 N/A 8.1 HIGH
Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777 through 800
CVE-2026-30807 1 Artica 1 Pandora Fms 2026-06-17 N/A 8.8 HIGH
Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 through 800
CVE-2026-30806 1 Artica 1 Pandora Fms 2026-06-17 N/A 8.8 HIGH
Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Network Report. This issue affects Pandora FMS: from 777 through 800
CVE-2026-30805 1 Artica 1 Pandora Fms 2026-06-17 N/A 9.1 CRITICAL
Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800
CVE-2026-30804 1 Artica 1 Pandora Fms 2026-06-17 N/A 7.2 HIGH
Unrestricted Upload of File with Dangerous Type vulnerability allows Remote Code Execution via file upload. This issue affects Pandora FMS: from 777 through 800
CVE-2025-5306 1 Artica 1 Pandora Fms 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778
CVE-2024-35307 1 Artica 1 Pandora Fms 2026-06-17 N/A 9.8 CRITICAL
Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777.
CVE-2024-35306 1 Artica 1 Pandora Fms 2026-06-17 N/A 9.8 CRITICAL
OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This issue affects Pandora FMS: from 700 through <777.
CVE-2024-35305 1 Artica 1 Pandora Fms 2026-06-17 N/A 9.8 CRITICAL
Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.
CVE-2024-35304 1 Artica 1 Pandora Fms 2026-06-17 N/A 9.8 CRITICAL
System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. This issue affects Pandora FMS: from 700 through <777.