- EPSS 45.41%
- Published 31.07.2025 15:15:34
- Last modified 31.07.2025 18:42:37
An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web interface, which listens on TCP port 8023. The anyterm-module endpoint accepts unsanitized user input via the p pa...
- EPSS 70.82%
- Published 25.07.2025 16:15:25
- Last modified 29.07.2025 14:14:55
An unauthenticated SQL injection vulnerability exists in Pandora FMS version 5.0 SP2 and earlier. The mobile/index.php endpoint fails to properly sanitize user input in the loginhash_data parameter, allowing attackers to extract administrator credent...
CVE-2025-34088
- EPSS 55.05%
- Published 03.07.2025 19:46:38
- Last modified 16.09.2025 19:44:41
An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenticated users to execute arbitrary OS commands via the select_ips parameter when performing network too...
CVE-2025-5306
- EPSS 46.29%
- Published 27.06.2025 07:48:15
- Last modified 16.09.2025 13:25:41
Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778
CVE-2024-12992
- EPSS 0.22%
- Published 17.03.2025 09:21:39
- Last modified 16.09.2025 15:53:40
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection via RCE. This issue affects Pandora FMS from 700 to 777.6 .
CVE-2024-12971
- EPSS 69.52%
- Published 17.03.2025 09:19:31
- Last modified 16.09.2025 15:55:43
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6
CVE-2024-35307
- EPSS 5.66%
- Published 10.06.2024 15:15:51
- Last modified 16.09.2025 15:56:22
Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777.
CVE-2024-35306
- EPSS 0.36%
- Published 10.06.2024 15:15:51
- Last modified 16.09.2025 15:53:01
OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This issue affects Pandora FMS: from 700 through <777.
CVE-2024-35305
- EPSS 0.37%
- Published 10.06.2024 15:15:51
- Last modified 16.09.2025 15:52:37
Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.
CVE-2024-35304
- EPSS 1.33%
- Published 10.06.2024 15:15:51
- Last modified 16.09.2025 15:52:02
System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. This issue affects Pandora FMS: from 700 through <777.