CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-34187HIGH | SQL Injection in Graph Container ParameterImproper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affects Pandora FMS: from 777 through 800 CWE-89May 12, 2026 | CVSS7.6v4.0 | EPSS0.274% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-30810HIGH | Server-Side Request Forgery in API Checker leads to Privilege EscalationServer-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800 CWE-918May 12, 2026 | CVSS7.1v4.0 | EPSS0.302% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-30808HIGH | Session Fixation in Authentication leads to Session HijackingSession Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777 through 800 CWE-384May 12, 2026 | CVSS7.6v4.0 | EPSS0.267% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-30807HIGH | Cross-Site Request Forgery on Extension PagesCross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 through 800 CWE-352May 12, 2026 | CVSS7.1v4.0 | EPSS0.144% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-30805CRITICAL | Insecure Default Initialization in API Authentication leads to Authentication BypassInsecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800 CWE-1188May 12, 2026 | CVSS9.1v4.0 | EPSS0.341% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-34188HIGH | OS Command Injection in Event Response ExecutionImproper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Event Response execution. This issue affects Pandora FMS: from 777 through 800 CWE-78Apr 13, 2026 | CVSS7.5v4.0 | EPSS1.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-34186HIGH | SQL Injection in Custom Fields leads to Database CompromiseImproper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via custom fields. This issue affects Pandora FMS: from 777 through 800 CWE-89Apr 13, 2026 | CVSS8.7v4.0 | EPSS0.249% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-30813HIGH | SQL Injection in Module Search leads to Database CompromiseImproper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via module search. This issue affects Pandora FMS: from 777 through 800 CWE-89Apr 13, 2026 | CVSS8.7v4.0 | EPSS0.339% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Stored Cross-Site Scripting in Event Comments via Filter BypassImproper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event comments. This issue affects Pandora FMS: from 777 through 800 CWE-79Apr 13, 2026 | CVSS2.1v4.0 | EPSS0.179% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-30811HIGH | Missing Authorization in Configuration Ajax Endpoint leads to Information DisclosureMissing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affects Pandora FMS: from 777 through 800 CWE-276Apr 13, 2026 | CVSS8.4v4.0 | EPSS0.269% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-30809HIGH | OS Command Injection in WebServerModuleDebug via Blacklist Bypass leads to Remote Code ExecutionImproper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via WebServerModuleDebug. This issue affects Pandora FMS: from 777 through 800 CWE-78Apr 13, 2026 | CVSS8.7v4.0 | EPSS0.938% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-30806HIGH | OS Command Injection in Network Report leads to Remote Code ExecutionImproper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Network Report. This issue affects Pandora FMS: from 777 through 800 CWE-78Apr 13, 2026 | CVSS8.7v4.0 | EPSS0.938% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-30804HIGH | Unrestricted File Upload in Extension Uploader leads to Remote Code ExecutionUnrestricted Upload of File with Dangerous Type vulnerability allows Remote Code Execution via file upload. This issue affects Pandora FMS: from 777 through 800 CWE-434Apr 13, 2026 | CVSS8.6v4.0 | EPSS0.432% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-5306HIGH | Command Injection in Netflow pathImproper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778 CWE-77Jun 27, 2025 | CVSS7.0v4.0 | EPSS22.8% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-12992HIGH | Remote Code Execution leads to Command InjectionImproper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection via RCE. This issue affects Pandora FMS from 700 to 777.6 . CWE-77Mar 17, 2025 | CVSS8.6v4.0 | EPSS1.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-12971HIGH | QuickShell Authenticated Command InjectionImproper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6 CWE-77Mar 17, 2025 | CVSS8.6v4.0 | EPSS58.2% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-11320MEDIUM | Command Injection leading to RCE via LDAP MisconfigurationArbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4 | CVSS6.9v4.0 | EPSS91.1% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-35308HIGH | Post-auth Arbitrary File Read in the Server Plugins SectionA post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: from 700 through <777.3. CWE-22Oct 22, 2024 | CVSS8.3v4.0 | EPSS0.605% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-9987HIGH | SQL Injection in CSV Module Data CollectionA post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv functionality. This issue affects Pandora FMS: from 700 through <777.3. CWE-89Oct 22, 2024 | CVSS8.6v4.0 | EPSS0.419% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-35307CRITICAL | Argument Injection Leading to Remote Code Execution in Realtime Graph ExtensionArgument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777. CWE-88Jun 10, 2024 | CVSS9.4v4.0 | EPSS0.913% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-35306HIGH | OS Command injection in Ajax PHP files through HTTP RequestOS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This issue affects Pandora FMS: from 700 through <777. CWE-78Jun 10, 2024 | CVSS8.7v4.0 | EPSS0.926% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-35305HIGH | Unauth Time-Based SQL Injection via APIUnauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777. CWE-89Jun 10, 2024 | CVSS8.9v4.0 | EPSS0.374% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-35304CRITICAL | System command injection through Netflow functionSystem command injection through Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. This issue affects Pandora FMS: from 700 through <777. CWE-78Jun 10, 2024 | CVSS9.3v4.0 | EPSS1.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41793MEDIUM | Path Traversal and Untrusted Upload File: Path Traversal vulnerability in Pandora FMS on all allows Path Traversal. This vulnerability allowed changing directories and creating files and downloading them outside the allowed directories. This issue affects Pandora FMS: from 700 through <776. CWE-35Mar 19, 2024 | CVSS6.7v3.1 | EPSS0.389% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-44092HIGH | OS Command InjectionImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Pandora FMS on all allows OS Command Injection. This vulnerability allowed to create a reverse shell and execute commands in the OS. This issue affects Pandora FMS: from 700 through <776. CWE-78Mar 19, 2024 | CVSS7.6v3.1 | EPSS0.846% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |