Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

140 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.6)0.76%—Artica Pandora FMS13/4/202617/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability allows Remote Code Execution via file upload. This issue affects Pandora FMS: from 777 through 800
AplazadaAlta (8.1)0.43%—Pandoranext TokenstoolAI21/8/202517/6/2026
An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnerability to access API without any token.
AplazadaCrítica (10)2.1%—Pandorafms Pandora FMSAI31/7/202517/6/2026
An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web interface, which listens on TCP port 8023. The anyterm-module endpoint accepts unsanitized user input via the p parameter and directly injects it into a shell command, allowing…
AplazadaCrítica (10)2.4%—Pandorafms Pandora FMSAI25/7/202517/6/2026
An unauthenticated SQL injection vulnerability exists in Pandora FMS version 5.0 SP2 and earlier. The mobile/index.php endpoint fails to properly sanitize user input in the loginhash_data parameter, allowing attackers to extract administrator credentials or active session tokens via crafted requests. This occurs…
AnalizadaAlta (8.6)7.2%—Pandorafms Pandora FMS3/7/202514/7/2026
An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenticated users to execute arbitrary OS commands via the select_ips parameter when performing network tools operations, such as pinging. This occurs because user input is not…
AnalizadaAlta (7)36%—Artica Pandora FMS27/6/202517/6/2026
Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778
AplazadaAlta (7)1.5%—Pandora ItsmAI10/6/202517/6/2026
Improper Neutralization of Special Elements in the chromium_path variable may allow OS command injection. This issue affects Pandora ITSM 5.0.105.
AplazadaAlta (7)3.3%—Pandora ItsmAI10/6/202517/6/2026
Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects Pandora ITSM 5.0.105.
AnalizadaAlta (8.6)1.2%—Artica Pandora FMS17/3/202517/6/2026
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection via RCE. This issue affects Pandora FMS from 700 to 777.6 .
AnalizadaAlta (8.6)61%—Artica Pandora FMS17/3/202517/6/2026
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6
AnalizadaMedia (6.9)91%—Pandorafms Pandora FMS21/11/202417/6/2026
Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4
AnalizadaAlta (8.6)0.42%—Pandorafms Pandora FMS22/10/202417/6/2026
A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv functionality. This issue affects Pandora FMS: from 700 through <777.3.
AnalizadaAlta (8.3)0.61%—Pandorafms Pandora FMS22/10/202417/6/2026
A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: from 700 through <777.3.
AnalizadaMedia (5.5)0.16%—Pandora Kmplayer5/8/202417/6/2026
A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.
AnalizadaCrítica (9.4)0.91%—Artica Pandora FMS10/6/202417/6/2026
Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777.
AnalizadaAlta (8.7)0.93%—Artica Pandora FMS10/6/202417/6/2026
OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This issue affects Pandora FMS: from 700 through <777.
AnalizadaAlta (8.9)0.37%—Artica Pandora FMS10/6/202417/6/2026
Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.
AnalizadaCrítica (9.3)1.1%—Artica Pandora FMS10/6/202417/6/2026
System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. This issue affects Pandora FMS: from 700 through <777.
AnalizadaCrítica (9.1)0.85%—Artica Pandora FMS19/3/202417/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Pandora FMS on all allows OS Command Injection. This vulnerability allowed to create a reverse shell and execute commands in the OS. This issue affects Pandora FMS: from 700 through <776.
AnalizadaCrítica (9.8)0.45%—Artica Pandora FMS19/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. This ulnerability allowed SQL injections to be made even if authentication failed.This issue affects Pandora FMS: from 700 through <776.
AnalizadaMedia (6.4)0.34%—Artica Pandora FMS19/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows CVE-2008-5817. This vulnerability allowed SQL changes to be made to several files in the Grafana module. This issue affects Pandora FMS: from 700 through <776.
AnalizadaMedia (6.5)0.39%—Artica Pandora FMS19/3/202417/6/2026
: Path Traversal vulnerability in Pandora FMS on all allows Path Traversal. This vulnerability allowed changing directories and creating files and downloading them outside the allowed directories. This issue affects Pandora FMS: from 700 through <776.
ModificadaMedia (6.1)0.25%—Pandorafms Pandora FMS29/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). It was possible to execute malicious JS code on Visual Consoles. This issue affects Pandora FMS: from 700 through 774.
ModificadaAlta (8.8)0.73%—Pandorafms Pandora FMS29/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS: from 700 through 774.
ModificadaMedia (6.1)0.28%—Pandorafms Pandora FMS29/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Malicious code could be executed in the File Manager section. This issue affects Pandora FMS: from 700 through 774.