Known Vulnerabilities for products from Pandorafms
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Pandorafms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-34088 json | An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php funct... | Not Provided | 2025-07-03 | 2026-07-14 |
| CVE-2023-44089 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2023-12-29 | 2024-01-05 |
| CVE-2023-44088 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2023-12-29 | 2024-01-05 |
| CVE-2023-41815 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2023-12-29 | 2024-01-05 |
| CVE-2023-41814 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2023-12-29 | 2024-01-05 |
| CVE-2023-41813 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2023-12-29 | 2024-01-05 |
| CVE-2023-24518 json | A Cross-site Request Forgery (CSRF) vulnerability in Pandora FMS allows an attacker to force authenticated users to send a re... | 7.1 - HIGH | 2023-10-03 | 2023-10-04 |
| CVE-2023-24517 json | Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker t... | 7.2 - HIGH | 2023-08-22 | 2023-11-02 |
| CVE-2023-24516 json | Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the... | 5.4 - MEDIUM | 2023-08-22 | 2023-11-02 |
| CVE-2023-24515 json | Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL ... | 6.5 - MEDIUM | 2023-08-22 | 2023-10-18 |
| CVE-2023-24514 json | Cross-site Scripting (XSS) vulnerability in Visual Console Module of Pandora FMS could be used to hijack admin users session ... | 6.1 - MEDIUM | 2023-08-22 | 2023-08-26 |
| CVE-2023-2807 json | Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attack... | 9.8 - CRITICAL | 2023-06-13 | 2023-06-23 |
| CVE-2023-0828 json | Cross-site Scripting (XSS) vulnerability in Syslog Section of Pandora FMS allows attacker to cause that users cookie value wi... | 6.1 - MEDIUM | 2023-10-03 | 2023-10-04 |
| CVE-2022-47373 json | Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vulnerab... | 6.1 - MEDIUM | 2023-02-15 | 2023-02-23 |
| CVE-2022-47372 json | Stored cross-site scripting vulnerability in the Create event section in Pandora FMS Console v766 and lower. An attacker typi... | 5.4 - MEDIUM | 2023-02-15 | 2023-10-18 |
| CVE-2022-45437 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artica PFMS Pandora FMS... | 4.8 - MEDIUM | 2023-02-15 | 2023-10-18 |
| CVE-2022-45436 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artica PFMS Pandora FMS... | 4.8 - MEDIUM | 2023-02-15 | 2023-10-18 |
| CVE-2022-43980 json | There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An attack... | 5.4 - MEDIUM | 2023-01-27 | 2023-02-22 |
| CVE-2022-43979 json | There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that the pa... | 9.8 - CRITICAL | 2023-01-27 | 2023-02-06 |
| CVE-2022-43978 json | There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid ses... | 3.7 - LOW | 2023-01-27 | 2023-06-27 |
Known software with vulnerabilities from Pandorafms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Pandorafms | Pandora Fms | 1.2 |