Pandora FMS

First CVE: Mar 10, 2022Active for: 4 years
58
CVEs Published
More CVEs Published than 61% of tracked CNAs
11.6
Avg CVEs / Year
More Avg CVEs / Year than 57% of tracked CNAs
7.8
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Pandora FMS as a CNA, 89.7% affect products that Pandora FMS develops as a vendor.

89.7%
10.3%
Self-reported: 52Third-party: 6

Of all the CVEs published that affect products developed by Pandora FMS, 62.7% are self-published by Pandora FMS as a CNA.

62.7%
37.3%
Self-published: 52Published by other CNAs: 31

Trends Over Time

The number and severity of CVEs published by Pandora FMS over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 10, 2022
4 years ago
Most Recent CVE
May 12, 2026
76 days ago

Top CVEs

All CVEs published by Pandora FMS as a CNA, regardless of affected vendor or product.

58 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=
Nov 21, 20249.890NOYES
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6
Mar 17, 20258.873NOYES
Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778
Jun 27, 20259.854NOYES
Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects Pandora ITSM 5.0.105.
Jun 10, 20257.035NOYES
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to
Dec 29, 20238.834NOYES
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affects Pandora FMS: from 777 throug
May 12, 20269.831NONO
Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800
May 12, 20269.130NONO
Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800
May 12, 20268.829NONO
Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 through 800
May 12, 20268.829NONO
Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths. This vulnerability allows to access the server
Nov 23, 20239.829NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA58 CVEs
Severity distribution among all CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network58 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low57 (98.3%)
High1 (1.7%)
Unknown0 (0.0%)
User Interaction
None38 (65.5%)
Unknown0 (0.0%)
Required20 (34.5%)
Privileges Required
Low19 (32.8%)
High6 (10.3%)
None33 (56.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (58 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
6.9% of CVEs· 98th percentile
Nuclei
1 CVE
1.7% of CVEs· 84th percentile
ExploitDB
1 CVE
1.7% of CVEs· 87th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Pandora FMS as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Pandora FMS as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs