Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Globalprotect HIGH 7.8
CVE-2024-5915

A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs wit…

Fix: 6.1.5 / 6.2.4+
Fix from $1,950 2024-08-14
Expedition CRITICAL 9.8
CVE-2024-5910 KEVEPSS 92%

Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with n…

Fix: 1.2.92+
Fix from $2,300 2024-07-10
Pan Os MEDIUM 6.8
CVE-2024-5913

An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical fil…

Fix: 10.1.14 / 10.2.10+
Fix from $1,600 2024-07-10
Globalprotect HIGH 7.5
CVE-2024-5908

A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, i…

Fix: 5.1.12 / 6.0.8+
Fix from $1,950 2024-06-12
Cortex Xdr Agent HIGH 7.0
CVE-2024-5907

A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with…

Fix: 7.9.102 / 8.2.3+
Fix from $1,950 2024-06-12
Cortex Xdr Agent MEDIUM 5.5
CVE-2024-5909

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to dis…

Fix: 7.9.102 / 8.1.2+
Fix from $1,600 2024-06-12
Pan Os CRITICAL 10.0
CVE-2024-3400 KEVEPSS 100%

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for speci…

Mitigation only
Fix from $2,300 2024-04-12
Pan Os CRITICAL 9.1
CVE-2024-3383

A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of Use…

Fix: 10.1.11 / 10.2.5+
Fix from $2,300 2024-04-10
Pan Os HIGH 7.5
CVE-2024-3384

A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receiving Windows New Technology LAN …

Fix: 8.1.24 / 9.0.17+
Fix from $1,950 2024-04-10
Pan Os HIGH 7.5
CVE-2024-3385

A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks ev…

Fix: 9.1.17 / 10.1.12+
Fix from $1,950 2024-04-10
Pan Os MEDIUM 5.9
CVE-2024-3387

A weak (low bit strength) device certificate in Palo Alto Networks Panorama software enables an attacker to perform a meddler-in-the-middle (MitM) at…

Fix: 10.1.12 / 10.2.7+
Fix from $1,600 2024-04-10
Pan Os MEDIUM 5.3
CVE-2024-3386

An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as inte…

Fix: 9.0.16 / 9.1.17+
Fix from $1,600 2024-04-10
Pan Os MEDIUM 5.0
CVE-2024-3388

A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and …

Fix: 8.1.26 / 9.0.17+
Fix from $1,600 2024-04-10
Pan Os HIGH 7.5
CVE-2024-3382

A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that even…

Fix: 10.2.7 / 11.0.4+
Fix from $1,950 2024-04-10
Globalprotect HIGH 7.0
CVE-2024-2432

A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs wit…

Fix: 5.1.12 / 6.0.8+
Fix from $1,950 2024-03-13
Globalprotect MEDIUM 5.5
CVE-2024-2431

An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a us…

Fix: 5.1.12 / 6.0.4+
Fix from $1,600 2024-03-13
Pan Os HIGH 8.8
CVE-2024-0008

Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthor…

Fix: 9.0.17 / 9.1.17+
Fix from $1,950 2024-02-14
Pan Os MEDIUM 6.3
CVE-2024-0009

An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stole…

Fix: 10.2.4+
Fix from $1,600 2024-02-14
Pan Os MEDIUM 6.1
CVE-2024-0010

A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of m…

Fix: 9.0.17 / 9.1.17+
Fix from $1,600 2024-02-14
Pan Os MEDIUM 6.1
CVE-2024-0011

A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software enables execution of malicio…

Fix: 8.1.24 / 9.0.17+
Fix from $1,600 2024-02-14
Pan Os MEDIUM 6.3
CVE-2023-6792

An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system proces…

Fix: 8.1.24 / 9.0.17+
Fix from $1,600 2023-12-13
Pan Os MEDIUM 6.1
CVE-2023-6790

A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to execute a JavaScript payload …

Fix: 8.1.25 / 9.0.17+
Fix from $1,600 2023-12-13
Cortex Xsoar MEDIUM 6.7
CVE-2023-3282

A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a …

Fix: 6.10.0+
Fix from $1,600 2023-11-08
Cortex Xdr Agent MEDIUM 5.5
CVE-2023-3280

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to disable the agent.

Fix: 7.9.3 / 7.9.101+
Fix from $1,600 2023-09-13
Globalprotect HIGH 7.8
CVE-2023-0009

A local privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows enables a local user to execute programs with …

Fix: 5.2.13 / 6.0.5+
Fix from $1,950 2023-06-14
Pan Os MEDIUM 5.4
CVE-2023-0010

A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript paylo…

Fix: after 10.2.2
Fix from $1,600 2023-06-14
Pan Os MEDIUM 6.5
CVE-2023-0004

A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file …

Fix: 8.1.24 / 9.0.17+
Fix from $1,600 2023-04-12
Globalprotect MEDIUM 6.3
CVE-2023-0006

A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the end…

Fix: 5.2.13 / 6.0.4+
Fix from $1,600 2023-04-12
Cortex Xdr Agent HIGH 7.8
CVE-2023-0002

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool …

Fix: 5.0.12.22203+
Fix from $1,950 2023-02-08
Cortex Xdr Agent MEDIUM 6.7
CVE-2023-0001

An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose t…

Fix: 7.5.101+
Fix from $1,600 2023-02-08