Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

140 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.20%—Pandorafms Pandora FMSAI1/10/20261/10/2026
Unsanitized concatenation of the module parameter in the Grafana datasource endpoint allows authenticated blind SQL injection. Affects Pandora FMS from 777 onwards.
AplazadaAlta (8.4)0.25%—Pandorafms Pandora FMSAI1/10/20261/10/2026
Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora FMS from 777 onwards.
AplazadaAlta (8.6)0.30%—Pandorafms Pandora FMSAI1/10/20261/10/2026
Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards.
AplazadaAlta (7.1)0.21%—Pandorafms Pandora FMSAI1/10/20261/10/2026
Missing authorization in module data retrieval allows unauthorized cross-group access to module history. Affects Pandora FMS from 777 onwards.
AplazadaAlta (7.5)0.25%—Pandorafms Pandora FMSAI1/10/20261/10/2026
A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting in Remote Code Execution. This issue affects Pandora FMS: from 777 onwards.
AplazadaAlta (7.4)0.16%—Pandorafms Pandora FMSAI1/10/20261/10/2026
A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards.
AplazadaMedia (5.9)0.15%—Pandorafms Pandora FMSAI1/10/20261/10/2026
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands via sequential, unvalidated GET requests when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
AplazadaMedia (5.9)0.21%—Pandorafms Pandora FMSAI1/10/20261/10/2026
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
Pendiente de análisisCrítica (9.3)0.50%—PandoraAI9/9/202610/9/2026
Pandora contains a path traversal vulnerability in its archive extraction worker. When processing a specially crafted archive or disk image, attacker-controlled file paths could be used without ensuring that the resulting destination remained within the intended extraction directory. An attacker able to submit a…
Pendiente de análisisAlta (7)0.44%—PandoraAI17/8/202626/8/2026
Pandora contains a stored cross-site scripting (XSS) vulnerability in the rendering of URL observables. A URL extracted from or associated with an analyzed file was inserted directly into the inline JavaScript onclick handler used by the Submit to Lookyloo action. Although the value was subject to HTML escaping by the…
Pendiente de análisisMedia (6.9)0.44%—PandoraAIPalletsprojects FlaskAI17/8/202626/8/2026
Pandora is affected by a stored cross-site scripting vulnerability in the PDF download functionality. The /task-download/<task_id>/.../pdf endpoint verifies that the submitted file is a PDF using Pandora's content-based file-type detection, but previously returned the file using send_file(task.file.path) without…
Pendiente de análisisAlta (8.7)0.43%—PandoraAI15/8/202626/8/2026
Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the internal ISO image from a DAA archive, compressed chunks were decompressed using zlib.decompress() without enforcing a limit on the resulting uncompressed data. An attacker able to submit a…
Pendiente de análisisCrítica (10)0.61%—PandoraAI15/8/202626/8/2026
Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive member names directly to Python's tarfile.TarFile.extract() without applying an extraction filter. An attacker able to submit a specially crafted TAR…
AnalizadaAlta (7.6)0.38%—Artica Pandora FMS12/5/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affects Pandora FMS: from 777 through 800
AnalizadaAlta (7.1)0.42%—Artica Pandora FMS12/5/202617/6/2026
Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800
AnalizadaAlta (7.6)0.36%—Artica Pandora FMS12/5/202617/6/2026
Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777 through 800
AnalizadaAlta (7.1)0.18%—Artica Pandora FMS12/5/202617/6/2026
Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 through 800
AnalizadaCrítica (9.1)0.48%—Artica Pandora FMS12/5/202617/6/2026
Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800
AnalizadaAlta (7.5)1.7%—Artica Pandora FMS13/4/202617/6/2026
Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Event Response execution. This issue affects Pandora FMS: from 777 through 800
AnalizadaAlta (8.7)0.44%—Artica Pandora FMS13/4/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via custom fields. This issue affects Pandora FMS: from 777 through 800
AnalizadaAlta (8.7)0.44%—Artica Pandora FMS13/4/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via module search. This issue affects Pandora FMS: from 777 through 800
AnalizadaBaja (2.1)0.23%—Artica Pandora FMS13/4/202617/6/2026
Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event comments. This issue affects Pandora FMS: from 777 through 800
AnalizadaAlta (8.4)0.34%—Artica Pandora FMS13/4/202617/6/2026
Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affects Pandora FMS: from 777 through 800
AnalizadaAlta (8.7)1.6%—Artica Pandora FMS13/4/202617/6/2026
Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via WebServerModuleDebug. This issue affects Pandora FMS: from 777 through 800
AnalizadaAlta (8.7)1.6%—Artica Pandora FMS13/4/202617/6/2026
Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Network Report. This issue affects Pandora FMS: from 777 through 800