Vulnerabilidades em Pandora FMS
48 resultadosAnálise Vexday
Pandora FMS apresenta 48 vulnerabilidades catalogadas, sendo 4 críticas, com fraqueza predominante em injeção XSS (CWE-79) que afeta a segurança da interface web. Embora nenhuma vulnerabilidade esteja sob exploração ativa no momento, o ritmo recente de descobertas (5 nos últimos 90 dias) indica que a plataforma segue sendo alvo de pesquisa em segurança, recomendando monitoramento contínuo das correções disponibilizadas.
CVE-2023-41808HIGHArbitrary File Read As Root Via GoTTY PageEPSS 0.5%CVE-2023-41787MEDIUMArbitrary File ReadEPSS 0.5%CVE-2023-4677HIGHUnauthenticated Admin Account Takeover Via Cron Log File BackupsEPSS 0.5%CVE-2023-41806HIGHMisassignment of privileges can cause DOS attackEPSS 0.5%CVE-2023-41789HIGHUnauthenticated Admin Account Takeover Via XSSEPSS 0.5%CVE-2023-44091HIGHUnauth Time-Based SQL InjectionEPSS 0.5%CVE-2023-41791HIGHLack of Authorization and Stored XSS Via Translation AbuseEPSS 0.5%CVE-2026-30804HIGHUnrestricted File Upload in Extension Uploader leads to Remote Code ExecutionEPSS 0.4%CVE-2024-9987HIGHSQL Injection in CSV Module Data CollectionEPSS 0.4%CVE-2023-41793MEDIUMPath Traversal and Untrusted Upload FileEPSS 0.4%CVE-2024-35305HIGHUnauth Time-Based SQL Injection via APIEPSS 0.4%CVE-2026-30805CRITICALInsecure Default Initialization in API Authentication leads to Authentication BypassEPSS 0.3%CVE-2026-30813HIGHSQL Injection in Module Search leads to Database CompromiseEPSS 0.3%CVE-2023-44090MEDIUMUnautH SQL InjectionEPSS 0.3%CVE-2023-41811MEDIUMStored XSS Via Site News PageEPSS 0.3%CVE-2023-41810MEDIUMStored XSS Via Dashboard PanelEPSS 0.3%CVE-2026-30810HIGHServer-Side Request Forgery in API Checker leads to Privilege EscalationEPSS 0.3%CVE-2023-41813LOWUser notification settings editionEPSS 0.3%CVE-2023-41815HIGHXSS in File managerEPSS 0.3%CVE-2026-34187HIGHSQL Injection in Graph Container ParameterEPSS 0.3%