Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cortex Xsoar MEDIUM 6.5
CVE-2023-0003

A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface…

Fix: 6.10.0.185964+
Fix from $1,600 2023-02-08
Cortex Xsoar MEDIUM 6.7
CVE-2022-0031

A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a l…

Mitigation only
Fix from $1,600 2022-11-09
Pan Os HIGH 8.1
CVE-2022-0030

An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of …

Fix: 8.1.24+
Fix from $1,950 2022-10-12
Cortex Xdr Agent MEDIUM 5.5
CVE-2022-0029

An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the …

Fix: 5.0.12 / 7.5.101+
Fix from $1,600 2022-09-14
Pan Os HIGH 8.6
CVE-2022-0028 KEV

A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) a…

Fix: 8.1.23 / 9.0.16+
Fix from $1,950 2022-08-10
Pan Os HIGH 7.2
CVE-2022-0024

A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated network-based PAN-OS administrator to upload a specificall…

Fix: 8.1.23 / 9.0.16+
Fix from $1,950 2022-05-11
Cortex Xdr Agent MEDIUM 6.7
CVE-2022-0025

A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local…

Fix: 7.7.1.62043+
Fix from $1,600 2022-05-11
Cortex Xdr Agent MEDIUM 6.7
CVE-2022-0026

A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local…

Mitigation only
Fix from $1,600 2022-05-11
Pan Os MEDIUM 5.9
CVE-2022-0023

An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-OS software that enables a med…

Fix: 8.1.22 / 9.0.16+
Fix from $1,600 2022-04-13
Globalprotect HIGH 7.8
CVE-2022-0016

An improper handling of exceptional conditions vulnerability exists within the Connect Before Logon feature of the Palo Alto Networks GlobalProtect a…

Fix: 5.2.9+
Fix from $1,950 2022-02-10
Globalprotect HIGH 7.8
CVE-2022-0017

An improper link resolution before file access ('link following') vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that en…

Fix: 5.1.10 / 5.2.5+
Fix from $1,950 2022-02-10
Pan Os MEDIUM 6.5
CVE-2022-0011

PAN-OS software provides options to exclude specific websites from URL category enforcement and those websites are blocked or allowed (depending on y…

Fix: 8.1.21 / 9.1.12+
Fix from $1,600 2022-02-10
Globalprotect MEDIUM 6.5
CVE-2022-0018

An information exposure vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows and MacOS where the credentials of the local user…

Fix: 5.1.10 / 5.2.9+
Fix from $1,600 2022-02-10
Globalprotect MEDIUM 5.5
CVE-2022-0019

An insufficiently protected credentials vulnerability exists in the Palo Alto Networks GlobalProtect app on Linux that exposes the hashed credentials…

Fix: 5.1.10 / 5.3.2+
Fix from $1,600 2022-02-10
Globalprotect MEDIUM 5.5
CVE-2022-0021

An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that logs the cleartext credenti…

Fix: 5.2.9+
Fix from $1,600 2022-02-10
Cortex Xsoar MEDIUM 5.4
CVE-2022-0020

A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to …

No fix yet
Fix from $1,600 2022-02-10
Cortex Xdr Agent HIGH 7.8
CVE-2022-0015

A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute…

Fix: 5.0.12 / 6.1.9+
Fix from $1,950 2022-01-12
Cortex Xdr Agent HIGH 7.3
CVE-2022-0014

An untrusted search path vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker with file creation privilege i…

Fix: 5.0.12 / 6.1.9+
Fix from $1,950 2022-01-12
Cortex Xdr Agent HIGH 7.1
CVE-2022-0012

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables a lo…

Fix: 5.0.12 / 6.1.9+
Fix from $1,950 2022-01-12
Cortex Xdr Agent MEDIUM 5.5
CVE-2022-0013

A file information exposure vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker to read the contents of arb…

Fix: 5.0.12 / 6.1.9+
Fix from $1,600 2022-01-12
Pan Os CRITICAL 9.8
CVE-2021-3064EPSS 19%

A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-ba…

Fix: 8.1.17+
Fix from $2,300 2021-11-10
Pan Os HIGH 8.8
CVE-2021-3062

An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to co…

Fix: 8.1.20 / 9.0.14+
Fix from $1,950 2021-11-10
Pan Os HIGH 8.1
CVE-2021-3059

An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates. This vulnerabilit…

Fix: 10.0.8 / 10.1.3+
Fix from $1,950 2021-11-10
Prisma Access HIGH 8.1
CVE-2021-3060EPSS 34%

An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated netwo…

Fix: 10.0.8 / 10.1.3+
Fix from $1,950 2021-11-10
Pan Os HIGH 7.5
CVE-2021-3063

An improper handling of exceptional conditions vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an…

Fix: 8.1.21 / 10.1.3+
Fix from $1,950 2021-11-10
Prisma Access HIGH 7.2
CVE-2021-3061

An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with acces…

Fix: 10.0.8 / 10.1.3+
Fix from $1,950 2021-11-10
Pan Os HIGH 8.8
CVE-2021-3056

A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary co…

Fix: 8.1.20 / 9.0.14+
Fix from $1,950 2021-11-10
Pan Os HIGH 7.2
CVE-2021-3058

An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use X…

Fix: 10.0.8 / 10.1.3+
Fix from $1,950 2021-11-10
Globalprotect HIGH 8.1
CVE-2021-3057

A stack-based buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the-middle attacker to disrupt s…

Fix: 5.1.9 / 5.2.8+
Fix from $1,950 2021-10-13
Pan Os HIGH 7.5
CVE-2021-3053

An improper handling of exceptional conditions vulnerability exists in the Palo Alto Networks PAN-OS dataplane that enables an unauthenticated networ…

Fix: 8.1.20 / 9.0.14+
Fix from $1,950 2021-09-08