Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pan Os MEDIUM 6.6
CVE-2021-3054

A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administ…

Fix: 8.1.20 / 9.0.14+
Fix from $1,600 2021-09-08
Pan Os MEDIUM 6.5
CVE-2021-3055

An improper restriction of XML external entity (XXE) reference vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated …

Fix: 8.1.20 / 9.0.14+
Fix from $1,600 2021-09-08
Pan Os MEDIUM 5.4
CVE-2021-3052

A reflected cross-site scripting (XSS) vulnerability in the Palo Alto Network PAN-OS web interface enables an authenticated network-based attacker to…

Fix: 8.1.20 / 9.0.14+
Fix from $1,600 2021-09-08
Cortex Xsoar HIGH 8.1
CVE-2021-3051

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-…

Mitigation only
Fix from $1,950 2021-09-08
Pan Os HIGH 8.8
CVE-2021-3050

An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to execute arbitrary OS c…

Fix: 9.0.15 / 9.1.11+
Fix from $1,950 2021-08-11
Pan Os MEDIUM 6.5
CVE-2021-3046

An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any o…

Fix: 8.1.19 / 9.0.14+
Fix from $1,600 2021-08-11
Pan Os MEDIUM 5.9
CVE-2021-3048

Certain invalid URL entries contained in an External Dynamic List (EDL) cause the Device Server daemon (devsrvr) to stop responding. This condition c…

Fix: 9.0.14 / 9.1.9+
Fix from $1,600 2021-08-11
Cortex Xdr Agent HIGH 7.8
CVE-2021-3042

A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated …

Mitigation only
Fix from $1,950 2021-07-15
Cortex Xsoar CRITICAL 9.8
CVE-2021-3044

An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Corte…

Mitigation only
Fix from $2,300 2021-06-22
Cortex Xdr Agent HIGH 7.8
CVE-2021-3041

A local privilege escalation vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local…

Fix: 5.0.11 / 6.1.8+
Fix from $1,950 2021-06-10
Bridgecrew Checkov HIGH 7.2
CVE-2021-3040

An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform f…

Fix: 2.0.139+
Fix from $1,950 2021-06-10
Bridgecrew Checkov HIGH 7.2
CVE-2021-3035

An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform f…

Fix: 2.0.26+
Fix from $1,950 2021-04-20
Globalprotect MEDIUM 5.5
CVE-2021-3038

A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect app on Windows systems allows a limited Windows user to send specifically…

Fix: 5.1.8 / 5.2.4+
Fix from $1,600 2021-04-20
Cortex Xsoar MEDIUM 5.1
CVE-2021-3034

An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO)…

Mitigation only
Fix from $1,600 2021-03-10
Prisma Cloud CRITICAL 9.8
CVE-2021-3033

An improper verification of cryptographic signature vulnerability exists in the Palo Alto Networks Prisma Cloud Compute console. This vulnerability e…

Mitigation only
Fix from $2,300 2021-02-10
Cortex Xdr Agent HIGH 7.8
CVE-2020-2049

A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local W…

Fix: after 7.2.2
Fix from $1,950 2020-12-09
Cortex Xdr Agent MEDIUM 5.5
CVE-2020-2020

An improper handling of exceptional conditions vulnerability in Cortex XDR Agent allows a local authenticated Windows user to create files in the sof…

Fix: 5.0.10 / 6.1.7+
Fix from $1,600 2020-12-09
Pan Os HIGH 8.2
CVE-2020-2050

An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to…

Fix: 8.1.17 / 9.0.11+
Fix from $1,950 2020-11-12
Pan Os HIGH 7.5
CVE-2020-2022

An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administ…

Fix: 8.1.17 / 9.0.11+
Fix from $1,950 2020-11-12
Pan Os HIGH 7.2
CVE-2020-2000

An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrup…

Fix: 8.1.16 / 9.0.10+
Fix from $1,950 2020-11-12
Pan Os MEDIUM 5.3
CVE-2020-1999

A vulnerability exists in the Palo Alto Network PAN-OS signature-based threat detection engine that allows an attacker to communicate with devices in…

Fix: 8.1.17 / 9.0.11+
Fix from $1,600 2020-11-12
Pan Os HIGH 7.2
CVE-2020-2042

A buffer overflow vulnerability in the PAN-OS management web interface allows authenticated administrators to disrupt system processes and potentiall…

Fix: 10.0.1+
Fix from $1,950 2020-09-09
Pan Os CRITICAL 9.8
CVE-2020-2040

A buffer overflow vulnerability in PAN-OS allows an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with …

Fix: 8.1.15 / 9.0.9+
Fix from $2,300 2020-09-09
Pan Os HIGH 8.8
CVE-2020-2036EPSS 24%

A reflected cross-site scripting (XSS) vulnerability exists in the PAN-OS management web interface. A remote attacker able to convince an administrat…

Fix: 8.1.16 / 9.0.9+
Fix from $1,950 2020-09-09
Pan Os HIGH 7.5
CVE-2020-2041

An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 allows a remote unauthenticated user to send a specifically crafted r…

Fix: 8.1.16+
Fix from $1,950 2020-09-09
Pan Os HIGH 7.2
CVE-2020-2037

An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands wi…

Fix: 8.1.16 / 9.0.10+
Fix from $1,950 2020-09-09
Pan Os HIGH 7.2
CVE-2020-2038EPSS 86%

An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands wi…

Fix: 9.0.10 / 9.1.4+
Fix from $1,950 2020-09-09
Pan Os MEDIUM 5.3
CVE-2020-2039EPSS 46%

An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user to upload temporary files th…

Fix: 8.1.16 / 9.0.10+
Fix from $1,600 2020-09-09
Pan Os HIGH 8.1
CVE-2020-2034EPSS 7%

An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacker to execute arbitrary OS com…

Fix: 8.1.15 / 9.0.9+
Fix from $1,950 2020-07-08
Pan Os HIGH 7.2
CVE-2020-2030

An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands wi…

Fix: 8.1.15+
Fix from $1,950 2020-07-08