Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

140 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)2.6%—Artica Pandora FMS7/5/202117/6/2026
A remote file inclusion vulnerability exists in Artica Pandora FMS 742, exploitable by the lowest privileged user.
ModificadaCrítica (9.8)13%💥 PoCArtica Pandora FMS7/5/202117/6/2026
A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.
ModificadaCrítica (9.8)2.5%—Artica Pandora FMS7/5/202117/6/2026
Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.
ModificadaCrítica (9.8)2.1%—Artica Pandora FMS2/10/202017/6/2026
Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php session_id parameter.
ModificadaCrítica (9)16%💥 ExploitPandorafms Pandora FMS13/7/202017/6/2026
Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (XSS), which can run arbitrary code to allow Remote Code Execution as root or apache2.
ModificadaAlta (7.2)28%—Pandorafms Pandora FMS11/6/202017/6/2026
Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manager feature.
ModificadaCrítica (9.8)3.0%—Pandorafms Pandora FMS11/6/202017/6/2026
Artica Pandora FMS 7.44 allows privilege escalation.
ModificadaMedia (5.4)1.0%—Pandorafms Pandora FMS11/6/202017/6/2026
Artica Pandora FMS 7.44 has persistent XSS in the Messages feature.
ModificadaAlta (7.2)28%—Pandorafms Pandora FMS11/6/202017/6/2026
Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature.
ModificadaAlta (8.8)91%💥 ExploitPandorafms Pandora FMS11/6/202017/6/2026
Artica Pandora FMS 7.44 allows remote command execution via the events feature.
ModificadaAlta (7.5)2.2%—Pandorafms Pandora FMS11/6/202017/6/2026
Artica Pandora FMS 7.44 has inadequate access controls on a web folder.
ModificadaAlta (7.2)3.1%—Artica Pandora FMS23/3/202017/6/2026
In Artica Pandora FMS through 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the File Repository component, a different issue than CVE-2020-7935 and CVE-2020-8500.
ModificadaAlta (7.2)3.1%—Artica Pandora FMS23/3/202017/6/2026
Artica Pandora FMS through 7.42 is vulnerable to remote PHP code execution because of an Unrestricted Upload Of A File With A Dangerous Type issue in the File Manager. An attacker can create a (or use an existing) directory that is externally accessible to store PHP files. The filename and the exact path is known by…
ModificadaMedia (5.3)5.4%💥 ExploitArtica Pandora FMS23/3/202017/6/2026
In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, user IDs, private messages, and timestamps.
ModificadaAlta (7.2)30%💥 ExploitArtica Pandora FMS16/3/202017/6/2026
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.
ModificadaAlta (7.2)3.5%—Artica Pandora FMS2/3/202017/6/2026
In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Extension component. NOTE: The vendor reports that this is intended functionality
ModificadaAlta (7.2)22%💥 ExploitArtica Pandora FMS12/2/202017/6/2026
functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?operation/netflow/nf_live_view ip_dst, dst_port, or src_port parameter, a different vulnerability than CVE-2019-20224.
ModificadaMedia (5.4)0.80%—Pandorafms Pandora FMS4/2/202017/6/2026
PandoraFMS 742 suffers from multiple XSS vulnerabilities, affecting the Agent Management, Report Builder, and Graph Builder components. An authenticated user can inject dangerous content into a data store that is later read and included in dynamic content.
ModificadaMedia (6.8)3.4%—Artica Pandora FMS30/1/202017/6/2026
Pandora FMS ≤ 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated user should create a new folder with a "tricky" name in the filemanager. The exploit works when the php-fileinfo extension is disabled on the host system. The attacker must include shell metacharacters…
ModificadaAlta (8.8)50%💥 ExploitArtica Pandora FMS9/1/202017/6/2026
netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742.
ModificadaAlta (8.8)4.6%—Artica Pandora FMS26/12/201917/6/2026
Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to define and execute commands as root/Administrator. NOTE: The product vendor states that the vulnerability as it is described is not in fact an actual vulnerability. They state…
ModificadaAlta (7.8)0.39%—Pandorafms Pandora FMS29/6/201917/6/2026
Artica Pandora FMS 7.0 NG before 735 suffers from local privilege escalation due to improper permissions on C:\PandoraFMS and its sub-folders, allowing standard users to create new files. Moreover, the Apache service httpd.exe will try to execute cmd.exe from C:\PandoraFMS (the current directory) as NT…
ModificadaAlta (7.8)1.7%—Pandora Kmplayer20/12/201817/6/2026
KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV format file. The problem is that more frame data is copied to heap memory than the size specified in the frame header. This results in a memory corruption and remote code execution.
ModificadaAlta (7.5)1.3%—Pandora Project Pandora4/7/201817/6/2026
The transfer and transferFrom functions of a smart contract implementation for Pandora (PDX), an Ethereum token, have an integer overflow. NOTE: this has been disputed by a third party.
ModificadaMedia (5.4)1.3%—Pandorafms Artica Pandora FMS16/6/201817/6/2026
XSS in Artica Pandora FMS before 7.0 NG 723 allows an attacker to execute arbitrary code via a crafted "refr" parameter in a "/pandora_console/index.php?sec=estado&sec2=operation/agentes/estado_agente&refr=" call.
Orbitaley — Vulnerabilidades