Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Globalprotect HIGH 7.0
CVE-2025-0120

A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated …

Fix: 6.0.12 / 6.2.7-1077+
Fix from $1,950 2025-04-11
Globalprotect HIGH 8.0
CVE-2025-0118

A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an auth…

Fix: 6.0.11 / 6.1.6+
Fix from $1,950 2025-03-12
Pan Os HIGH 7.5
CVE-2025-0114

A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to ren…

Fix: 10.1.14 / 10.2.5+
Fix from $1,950 2025-03-12
Pan Os CRITICAL 9.1
CVE-2025-0108 KEVEPSS 98%

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web inte…

Fix: 10.1.14 / 10.2.7+
Fix from $2,300 2025-02-12
Pan Os MEDIUM 6.5
CVE-2025-0111 KEV

An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the manag…

Fix: 10.1.14 / 10.2.7+
Fix from $1,600 2025-02-12
Expedition CRITICAL 9.8
CVE-2025-0107EPSS 79%

An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-da…

Fix: 1.2.101+
Fix from $2,300 2025-01-11
Expedition CRITICAL 9.1
CVE-2025-0105EPSS 13%

An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to…

Fix: 1.2.101+
Fix from $2,300 2025-01-11
Expedition HIGH 8.8
CVE-2025-0103

An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as pas…

Fix: 1.2.101+
Fix from $1,950 2025-01-11
Expedition MEDIUM 6.1
CVE-2025-0104

A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the c…

Fix: 1.2.101+
Fix from $1,600 2025-01-11
Expedition MEDIUM 5.3
CVE-2025-0106

A wildcard expansion vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to enumerate files on the host filesystem.

Fix: 1.2.101+
Fix from $1,600 2025-01-11
Pan Os HIGH 7.5
CVE-2024-3393 KEVEPSS 29%

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a mali…

Fix: 11.2.3+
Fix from $1,950 2024-12-27
Globalprotect HIGH 8.8
CVE-2024-5921

An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbi…

Fix: 6.1.6 / 6.1.7+
Fix from $1,950 2024-11-27
Pan Os HIGH 7.2
CVE-2024-9474 KEVEPSS 95%

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface …

Fix: 10.1.14 / 10.2.12+
Fix from $1,950 2024-11-18
Pan Os CRITICAL 9.8
CVE-2024-0012 KEVEPSS 100%

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interfac…

Mitigation only
Fix from $2,300 2024-11-18
Pan Os MEDIUM 6.5
CVE-2024-5919

A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate…

Fix: 10.1.10 / 10.2.5+
Fix from $1,600 2024-11-14
Pan Os HIGH 7.5
CVE-2024-2550

A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to st…

Fix: 10.2.7 / 11.0.6+
Fix from $1,950 2024-11-14
Pan Os HIGH 7.5
CVE-2024-2551

A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on t…

Fix: 10.1.14 / 10.2.4+
Fix from $1,950 2024-11-14
Pan Os MEDIUM 6.0
CVE-2024-2552

A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the m…

Fix: 10.2.7 / 11.0.6+
Fix from $1,600 2024-11-14
Globalprotect HIGH 7.8
CVE-2024-9473

A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows…

Fix: 6.2.5+
Fix from $1,950 2024-10-09
Expedition CRITICAL 9.1
CVE-2024-9465 KEVEPSS 100%

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as pa…

Fix: 1.2.96+
Fix from $2,300 2024-10-09
Pan Os HIGH 7.5
CVE-2024-9468

A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet th…

Fix: 10.2.4 / 10.2.7+
Fix from $1,950 2024-10-09
Expedition MEDIUM 6.5
CVE-2024-9464EPSS 82%

An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Exped…

Fix: 1.2.96+
Fix from $1,600 2024-10-09
Expedition MEDIUM 6.5
CVE-2024-9466EPSS 13%

A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usern…

Fix: 1.2.96+
Fix from $1,600 2024-10-09
Expedition MEDIUM 6.1
CVE-2024-9467

A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expeditio…

Fix: 1.2.96+
Fix from $1,600 2024-10-09
Cortex Xdr Agent MEDIUM 5.5
CVE-2024-9469

A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative pri…

Fix: 7.9.102+
Fix from $1,600 2024-10-09
Expedition HIGH 7.5
CVE-2024-9463 KEVEPSS 98%

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Exp…

Fix: 1.2.96+
Fix from $1,950 2024-10-09
Pan Os HIGH 7.2
CVE-2024-8686

A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run …

Fix: after 11.2.2
Fix from $1,950 2024-09-11
Pan Os HIGH 7.1
CVE-2024-8687

An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured…

Fix: 5.1.12 / 5.2.13+
Fix from $1,950 2024-09-11
Pan Os HIGH 7.1
CVE-2024-8691

A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate…

Fix: 9.1.17 / 10.1.11+
Fix from $1,950 2024-09-11
Cortex Xsoar Commonscripts CRITICAL 9.8
CVE-2024-5914

A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands with…

Fix: 1.12.33+
Fix from $2,300 2024-08-14