CVEs we hold for Pandora
Records whose assigning authority named Pandora as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-88069Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora…pandora-analysis pandora CVE-2026-75531Stored Cross-Site Scripting in URL Observables via Lookyloo Submission Handler in Pandorapandora-analysis pandora CVE-2026-75529Stored Cross-Site Scripting via MIME-Type Confusion in PDF Downloads of Pandorapandora-analysis pandora CVE-2026-74767Unbounded DAA Decompression in Pandora Allows Denial of Service via Decompression Bombpandora-analysis pandora CVE-2026-74764Path Traversal in TAR Archive Extraction Allows Arbitrary File Write in Pandorapandora-analysis pandora CVE-2026-34188OS Command Injection in Event Response ExecutionPandora FMS CVE-2026-34186SQL Injection in Custom Fields leads to Database CompromisePandora FMS CVE-2026-30813SQL Injection in Module Search leads to Database CompromisePandora FMS CVE-2026-30812Stored Cross-Site Scripting in Event Comments via Filter BypassPandora FMS CVE-2026-30811Missing Authorization in Configuration Ajax Endpoint leads to Information DisclosurePandora FMS CVE-2026-30810Server-Side Request Forgery in API Checker leads to Privilege EscalationPandora FMS CVE-2026-30809OS Command Injection in WebServerModuleDebug via Blacklist Bypass leads to Remote Code ExecutionPandora FMS CVE-2026-30808Session Fixation in Authentication leads to Session HijackingPandora FMS CVE-2026-30807Cross-Site Request Forgery on Extension PagesPandora FMS CVE-2026-30806OS Command Injection in Network Report leads to Remote Code ExecutionPandora FMS CVE-2026-30805Insecure Default Initialization in API Authentication leads to Authentication BypassPandora FMS CVE-2026-30804Unrestricted File Upload in Extension Uploader leads to Remote Code ExecutionPandora FMS CVE-2025-4678Remote Code Execution leads to Command InjectionPandora ITSM CVE-2025-4653Remote Code Execution leads to Command InjectionPandora ITSM CVE-2024-9987SQL Injection in CSV Module Data CollectionPandora FMS CVE-2024-35308Post-auth Arbitrary File Read in the Server Plugins SectionPandora FMS CVE-2024-35307Argument Injection Leading to Remote Code Execution in Realtime Graph ExtensionPandora FMS CVE-2024-35306OS Command injection in Ajax PHP files through HTTP RequestPandora FMS CVE-2024-35304System command injection through Netflow functionPandora FMS CVE-2024-12992Remote Code Execution leads to Command InjectionPandora FMS CVE-2024-11320Command Injection leading to RCE via LDAP MisconfigurationPandora FMS CVE-2023-4677Unauthenticated Admin Account Takeover Via Cron Log File BackupsPandora FMS CVE-2023-41807Linux Local Privilege Escalation Via GoTTY PagePandora FMS CVE-2023-41806Misassignment of privileges can cause DOS attackPandora FMS CVE-2023-41792Lack of Authorization and Stored XSS Via SNMP Trap Editor PagePandora FMS CVE-2023-41791Lack of Authorization and Stored XSS Via Translation AbusePandora FMS CVE-2023-41789Unauthenticated Admin Account Takeover Via XSSPandora FMS CVE-2023-41786Database backups availability by low-privileged usersPandora FMS CVE-2019-9133KMPlayer Subtitles parser Heap Overflow VulnerabilityPandora.tv KMPlayer CVE-2018-5200KMPlayer Heap Overflow VulnerabilityPandora.tv KMPlayer 56 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.