CVE-2024-12992
- EPSS 0.58%
- Veröffentlicht 17.03.2025 09:21:39
- Zuletzt bearbeitet 16.09.2025 15:53:40
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection via RCE. This issue affects Pandora FMS from 700 to 777.6 .
CVE-2024-12971
- EPSS 73.65%
- Veröffentlicht 17.03.2025 09:19:31
- Zuletzt bearbeitet 16.09.2025 15:55:43
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6
CVE-2024-11320
- EPSS 92.62%
- Veröffentlicht 21.11.2024 11:15:24
- Zuletzt bearbeitet 26.11.2024 17:26:33
Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4
CVE-2024-9987
- EPSS 0.53%
- Veröffentlicht 22.10.2024 09:15:03
- Zuletzt bearbeitet 25.10.2024 19:06:35
A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv functionality. This issue affects Pandora FMS: from 700 through <777.3.
CVE-2024-35308
- EPSS 1.02%
- Veröffentlicht 22.10.2024 09:15:02
- Zuletzt bearbeitet 25.10.2024 19:06:14
A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: from 700 through <777.3.
CVE-2024-35307
- EPSS 15.35%
- Veröffentlicht 10.06.2024 15:15:51
- Zuletzt bearbeitet 16.09.2025 15:56:22
Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777.
CVE-2024-35304
- EPSS 1.8%
- Veröffentlicht 10.06.2024 15:15:51
- Zuletzt bearbeitet 16.09.2025 15:52:02
System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. This issue affects Pandora FMS: from 700 through <777.
CVE-2024-35305
- EPSS 0.39%
- Veröffentlicht 10.06.2024 15:15:51
- Zuletzt bearbeitet 16.09.2025 15:52:37
Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.
CVE-2024-35306
- EPSS 0.49%
- Veröffentlicht 10.06.2024 15:15:51
- Zuletzt bearbeitet 16.09.2025 15:53:01
OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This issue affects Pandora FMS: from 700 through <777.
CVE-2023-44092
- EPSS 0.13%
- Veröffentlicht 19.03.2024 17:15:08
- Zuletzt bearbeitet 16.09.2025 15:51:17
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Pandora FMS on all allows OS Command Injection. This vulnerability allowed to create a reverse shell and execute commands in the OS. This issu...