Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
124 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.20% | — | Pandorafms Pandora FMSAI | 1/10/2026 | 1/10/2026 | Unsanitized concatenation of the module parameter in the Grafana datasource endpoint allows authenticated blind SQL injection. Affects Pandora FMS from 777 onwards. | |
| Aplazada | Alta (8.4) | 0.25% | — | Pandorafms Pandora FMSAI | 1/10/2026 | 1/10/2026 | Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora FMS from 777 onwards. | |
| Aplazada | Alta (8.6) | 0.30% | — | Pandorafms Pandora FMSAI | 1/10/2026 | 1/10/2026 | Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards. | |
| Aplazada | Alta (7.1) | 0.21% | — | Pandorafms Pandora FMSAI | 1/10/2026 | 1/10/2026 | Missing authorization in module data retrieval allows unauthorized cross-group access to module history. Affects Pandora FMS from 777 onwards. | |
| Aplazada | Alta (7.5) | 0.25% | — | Pandorafms Pandora FMSAI | 1/10/2026 | 1/10/2026 | A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting in Remote Code Execution. This issue affects Pandora FMS: from 777 onwards. | |
| Aplazada | Alta (7.4) | 0.16% | — | Pandorafms Pandora FMSAI | 1/10/2026 | 1/10/2026 | A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards. | |
| Aplazada | Media (5.9) | 0.15% | — | Pandorafms Pandora FMSAI | 1/10/2026 | 1/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands via sequential, unvalidated GET requests when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards. | |
| Aplazada | Media (5.9) | 0.21% | — | Pandorafms Pandora FMSAI | 1/10/2026 | 1/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards. | |
| Analizada | Alta (7.6) | 0.38% | — | Artica Pandora FMS | 12/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affects Pandora FMS: from 777 through 800 | |
| Analizada | Alta (7.1) | 0.42% | — | Artica Pandora FMS | 12/5/2026 | 17/6/2026 | Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800 | |
| Analizada | Alta (7.6) | 0.36% | — | Artica Pandora FMS | 12/5/2026 | 17/6/2026 | Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777 through 800 | |
| Analizada | Alta (7.1) | 0.18% | — | Artica Pandora FMS | 12/5/2026 | 17/6/2026 | Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 through 800 | |
| Analizada | Crítica (9.1) | 0.48% | — | Artica Pandora FMS | 12/5/2026 | 17/6/2026 | Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800 | |
| Analizada | Alta (7.5) | 1.7% | — | Artica Pandora FMS | 13/4/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Event Response execution. This issue affects Pandora FMS: from 777 through 800 | |
| Analizada | Alta (8.7) | 0.44% | — | Artica Pandora FMS | 13/4/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via custom fields. This issue affects Pandora FMS: from 777 through 800 | |
| Analizada | Alta (8.7) | 0.44% | — | Artica Pandora FMS | 13/4/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via module search. This issue affects Pandora FMS: from 777 through 800 | |
| Analizada | Baja (2.1) | 0.23% | — | Artica Pandora FMS | 13/4/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event comments. This issue affects Pandora FMS: from 777 through 800 | |
| Analizada | Alta (8.4) | 0.34% | — | Artica Pandora FMS | 13/4/2026 | 17/6/2026 | Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affects Pandora FMS: from 777 through 800 | |
| Analizada | Alta (8.7) | 1.6% | — | Artica Pandora FMS | 13/4/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via WebServerModuleDebug. This issue affects Pandora FMS: from 777 through 800 | |
| Analizada | Alta (8.7) | 1.6% | — | Artica Pandora FMS | 13/4/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Network Report. This issue affects Pandora FMS: from 777 through 800 | |
| Analizada | Alta (8.6) | 0.76% | — | Artica Pandora FMS | 13/4/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability allows Remote Code Execution via file upload. This issue affects Pandora FMS: from 777 through 800 | |
| Aplazada | Crítica (10) | 2.1% | — | Pandorafms Pandora FMSAI | 31/7/2025 | 17/6/2026 | An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web interface, which listens on TCP port 8023. The anyterm-module endpoint accepts unsanitized user input via the p parameter and directly injects it into a shell command, allowing… | |
| Aplazada | Crítica (10) | 2.4% | — | Pandorafms Pandora FMSAI | 25/7/2025 | 17/6/2026 | An unauthenticated SQL injection vulnerability exists in Pandora FMS version 5.0 SP2 and earlier. The mobile/index.php endpoint fails to properly sanitize user input in the loginhash_data parameter, allowing attackers to extract administrator credentials or active session tokens via crafted requests. This occurs… | |
| Analizada | Alta (8.6) | 7.2% | — | Pandorafms Pandora FMS | 3/7/2025 | 14/7/2026 | An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenticated users to execute arbitrary OS commands via the select_ips parameter when performing network tools operations, such as pinging. This occurs because user input is not… | |
| Analizada | Alta (7) | 36% | — | Artica Pandora FMS | 27/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778 |