vciy

CVEs we hold for Pandora

Records whose assigning authority named Pandora as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-88069Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora…pandora-analysis pandora
CVE-2026-75531Stored Cross-Site Scripting in URL Observables via Lookyloo Submission Handler in Pandorapandora-analysis pandora
CVE-2026-75529Stored Cross-Site Scripting via MIME-Type Confusion in PDF Downloads of Pandorapandora-analysis pandora
CVE-2026-74767Unbounded DAA Decompression in Pandora Allows Denial of Service via Decompression Bombpandora-analysis pandora
CVE-2026-74764Path Traversal in TAR Archive Extraction Allows Arbitrary File Write in Pandorapandora-analysis pandora
CVE-2026-34188OS Command Injection in Event Response ExecutionPandora FMS
CVE-2026-34187SQL Injection in Graph Container ParameterPandora FMS
CVE-2026-34186SQL Injection in Custom Fields leads to Database CompromisePandora FMS
CVE-2026-30813SQL Injection in Module Search leads to Database CompromisePandora FMS
CVE-2026-30812Stored Cross-Site Scripting in Event Comments via Filter BypassPandora FMS
CVE-2026-30811Missing Authorization in Configuration Ajax Endpoint leads to Information DisclosurePandora FMS
CVE-2026-30810Server-Side Request Forgery in API Checker leads to Privilege EscalationPandora FMS
CVE-2026-30809OS Command Injection in WebServerModuleDebug via Blacklist Bypass leads to Remote Code ExecutionPandora FMS
CVE-2026-30808Session Fixation in Authentication leads to Session HijackingPandora FMS
CVE-2026-30807Cross-Site Request Forgery on Extension PagesPandora FMS
CVE-2026-30806OS Command Injection in Network Report leads to Remote Code ExecutionPandora FMS
CVE-2026-30805Insecure Default Initialization in API Authentication leads to Authentication BypassPandora FMS
CVE-2026-30804Unrestricted File Upload in Extension Uploader leads to Remote Code ExecutionPandora FMS
CVE-2025-5306Command Injection in Netflow pathPandora FMS
CVE-2025-4678Remote Code Execution leads to Command InjectionPandora ITSM
CVE-2025-4653Remote Code Execution leads to Command InjectionPandora ITSM
CVE-2024-9987SQL Injection in CSV Module Data CollectionPandora FMS
CVE-2024-35308Post-auth Arbitrary File Read in the Server Plugins SectionPandora FMS
CVE-2024-35307Argument Injection Leading to Remote Code Execution in Realtime Graph ExtensionPandora FMS
CVE-2024-35306OS Command injection in Ajax PHP files through HTTP RequestPandora FMS
CVE-2024-35305Unauth Time-Based SQL Injection via APIPandora FMS
CVE-2024-35304System command injection through Netflow functionPandora FMS
CVE-2024-12992Remote Code Execution leads to Command InjectionPandora FMS
CVE-2024-12971QuickShell Authenticated Command InjectionPandora FMS
CVE-2024-11320Command Injection leading to RCE via LDAP MisconfigurationPandora FMS
CVE-2023-4677Unauthenticated Admin Account Takeover Via Cron Log File BackupsPandora FMS
CVE-2023-44092OS Command InjectionPandora FMS
CVE-2023-44091Unauth Time-Based SQL InjectionPandora FMS
CVE-2023-44090UnautH SQL InjectionPandora FMS
CVE-2023-44089XSS in Visual ConsolePandora FMS
CVE-2023-44088SQL Injection in Visual ConsolePandora FMS
CVE-2023-41815XSS in File managerPandora FMS
CVE-2023-41814XSS Vulnerability MessagesPandora FMS
CVE-2023-41813User notification settings editionPandora FMS
CVE-2023-41812Uploading executables via the file managerPandora FMS
CVE-2023-41811Stored XSS Via Site News PagePandora FMS
CVE-2023-41810Stored XSS Via Dashboard PanelPandora FMS
CVE-2023-41808Arbitrary File Read As Root Via GoTTY PagePandora FMS
CVE-2023-41807Linux Local Privilege Escalation Via GoTTY PagePandora FMS
CVE-2023-41806Misassignment of privileges can cause DOS attackPandora FMS
CVE-2023-41793Path Traversal and Untrusted Upload FilePandora FMS
CVE-2023-41792Lack of Authorization and Stored XSS Via SNMP Trap Editor PagePandora FMS
CVE-2023-41791Lack of Authorization and Stored XSS Via Translation AbusePandora FMS
CVE-2023-41790Traversal Path on PHP filePandora FMS
CVE-2023-41789Unauthenticated Admin Account Takeover Via XSSPandora FMS
CVE-2023-41788Remote Code Execution via File UploaderPandora FMS
CVE-2023-41787Arbitrary File ReadPandora FMS
CVE-2023-41786Database backups availability by low-privileged usersPandora FMS
CVE-2019-9133KMPlayer Subtitles parser Heap Overflow VulnerabilityPandora.tv KMPlayer
CVE-2018-5200KMPlayer Heap Overflow VulnerabilityPandora.tv KMPlayer
CVE-2017-3194no title heldPandora iOS App

56 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.