Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
140 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 2.6% | — | Artica Pandora FMS | 7/5/2021 | 17/6/2026 | A remote file inclusion vulnerability exists in Artica Pandora FMS 742, exploitable by the lowest privileged user. | |
| Modificada | Crítica (9.8) | 13% | 💥 PoC | Artica Pandora FMS | 7/5/2021 | 17/6/2026 | A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass. | |
| Modificada | Crítica (9.8) | 2.5% | — | Artica Pandora FMS | 7/5/2021 | 17/6/2026 | Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization. | |
| Modificada | Crítica (9.8) | 2.1% | — | Artica Pandora FMS | 2/10/2020 | 17/6/2026 | Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php session_id parameter. | |
| Modificada | Crítica (9) | 16% | 💥 Exploit | Pandorafms Pandora FMS | 13/7/2020 | 17/6/2026 | Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (XSS), which can run arbitrary code to allow Remote Code Execution as root or apache2. | |
| Modificada | Alta (7.2) | 28% | — | Pandorafms Pandora FMS | 11/6/2020 | 17/6/2026 | Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manager feature. | |
| Modificada | Crítica (9.8) | 3.0% | — | Pandorafms Pandora FMS | 11/6/2020 | 17/6/2026 | Artica Pandora FMS 7.44 allows privilege escalation. | |
| Modificada | Media (5.4) | 1.0% | — | Pandorafms Pandora FMS | 11/6/2020 | 17/6/2026 | Artica Pandora FMS 7.44 has persistent XSS in the Messages feature. | |
| Modificada | Alta (7.2) | 28% | — | Pandorafms Pandora FMS | 11/6/2020 | 17/6/2026 | Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature. | |
| Modificada | Alta (8.8) | 91% | 💥 Exploit | Pandorafms Pandora FMS | 11/6/2020 | 17/6/2026 | Artica Pandora FMS 7.44 allows remote command execution via the events feature. | |
| Modificada | Alta (7.5) | 2.2% | — | Pandorafms Pandora FMS | 11/6/2020 | 17/6/2026 | Artica Pandora FMS 7.44 has inadequate access controls on a web folder. | |
| Modificada | Alta (7.2) | 3.1% | — | Artica Pandora FMS | 23/3/2020 | 17/6/2026 | In Artica Pandora FMS through 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the File Repository component, a different issue than CVE-2020-7935 and CVE-2020-8500. | |
| Modificada | Alta (7.2) | 3.1% | — | Artica Pandora FMS | 23/3/2020 | 17/6/2026 | Artica Pandora FMS through 7.42 is vulnerable to remote PHP code execution because of an Unrestricted Upload Of A File With A Dangerous Type issue in the File Manager. An attacker can create a (or use an existing) directory that is externally accessible to store PHP files. The filename and the exact path is known by… | |
| Modificada | Media (5.3) | 5.4% | 💥 Exploit | Artica Pandora FMS | 23/3/2020 | 17/6/2026 | In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, user IDs, private messages, and timestamps. | |
| Modificada | Alta (7.2) | 30% | 💥 Exploit | Artica Pandora FMS | 16/3/2020 | 17/6/2026 | index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020. | |
| Modificada | Alta (7.2) | 3.5% | — | Artica Pandora FMS | 2/3/2020 | 17/6/2026 | In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Extension component. NOTE: The vendor reports that this is intended functionality | |
| Modificada | Alta (7.2) | 22% | 💥 Exploit | Artica Pandora FMS | 12/2/2020 | 17/6/2026 | functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?operation/netflow/nf_live_view ip_dst, dst_port, or src_port parameter, a different vulnerability than CVE-2019-20224. | |
| Modificada | Media (5.4) | 0.80% | — | Pandorafms Pandora FMS | 4/2/2020 | 17/6/2026 | PandoraFMS 742 suffers from multiple XSS vulnerabilities, affecting the Agent Management, Report Builder, and Graph Builder components. An authenticated user can inject dangerous content into a data store that is later read and included in dynamic content. | |
| Modificada | Media (6.8) | 3.4% | — | Artica Pandora FMS | 30/1/2020 | 17/6/2026 | Pandora FMS ≤ 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated user should create a new folder with a "tricky" name in the filemanager. The exploit works when the php-fileinfo extension is disabled on the host system. The attacker must include shell metacharacters… | |
| Modificada | Alta (8.8) | 50% | 💥 Exploit | Artica Pandora FMS | 9/1/2020 | 17/6/2026 | netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742. | |
| Modificada | Alta (8.8) | 4.6% | — | Artica Pandora FMS | 26/12/2019 | 17/6/2026 | Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to define and execute commands as root/Administrator. NOTE: The product vendor states that the vulnerability as it is described is not in fact an actual vulnerability. They state… | |
| Modificada | Alta (7.8) | 0.39% | — | Pandorafms Pandora FMS | 29/6/2019 | 17/6/2026 | Artica Pandora FMS 7.0 NG before 735 suffers from local privilege escalation due to improper permissions on C:\PandoraFMS and its sub-folders, allowing standard users to create new files. Moreover, the Apache service httpd.exe will try to execute cmd.exe from C:\PandoraFMS (the current directory) as NT… | |
| Modificada | Alta (7.8) | 1.7% | — | Pandora Kmplayer | 20/12/2018 | 17/6/2026 | KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV format file. The problem is that more frame data is copied to heap memory than the size specified in the frame header. This results in a memory corruption and remote code execution. | |
| Modificada | Alta (7.5) | 1.3% | — | Pandora Project Pandora | 4/7/2018 | 17/6/2026 | The transfer and transferFrom functions of a smart contract implementation for Pandora (PDX), an Ethereum token, have an integer overflow. NOTE: this has been disputed by a third party. | |
| Modificada | Media (5.4) | 1.3% | — | Pandorafms Artica Pandora FMS | 16/6/2018 | 17/6/2026 | XSS in Artica Pandora FMS before 7.0 NG 723 allows an attacker to execute arbitrary code via a crafted "refr" parameter in a "/pandora_console/index.php?sec=estado&sec2=operation/agentes/estado_agente&refr=" call. |