Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Traps HIGH 7.1
CVE-2020-1991

An insecure temporary file vulnerability in Palo Alto Networks Traps allows a local authenticated Windows user to escalate privileges or overwrite sy…

Fix: 5.0.8 / 6.1.4+
Fix from $1,950 2020-04-08
Secdo HIGH 7.8
CVE-2020-1984

Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create folders or append data' access t…

Mitigation only
Fix from $1,950 2020-04-08
Secdo HIGH 7.8
CVE-2020-1985

Incorrect Default Permissions on C:\Programdata\Secdo\Logs folder in Secdo allows local authenticated users to overwrite system files and gain escala…

Mitigation only
Fix from $1,950 2020-04-08
Globalprotect HIGH 7.8
CVE-2020-1989

An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global Protect Agent for Linux on A…

Fix: 5.0.8 / 5.1.1+
Fix from $1,950 2020-04-08
Globalprotect MEDIUM 6.7
CVE-2020-1988

An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges…

Fix: 4.1.13 / 5.0.5+
Fix from $1,600 2020-04-08
Secdo MEDIUM 5.5
CVE-2020-1986

Improper input validation vulnerability in Secdo allows an authenticated local user with 'create folders or append data' access to the root of the OS…

Mitigation only
Fix from $1,600 2020-04-08
Pan Os HIGH 7.8
CVE-2020-1979

A format string vulnerability in the PAN-OS log daemon (logd) on Panorama allows a network based attacker with knowledge of registered firewall devic…

Fix: 8.1.13+
Fix from $1,950 2020-03-11
Pan Os HIGH 7.8
CVE-2020-1980

A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted shell and escalate privileges. T…

Fix: 8.1.13+
Fix from $1,950 2020-03-11
Pan Os HIGH 7.8
CVE-2020-1981

A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation. This issue allows a local attacker who bypassed the restr…

Fix: 8.1.13+
Fix from $1,950 2020-03-11
Pan Os HIGH 8.8
CVE-2020-1975

Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary…

Fix: 8.1.12 / 9.0.6+
Fix from $1,950 2020-02-12
Expedition Migration Tool HIGH 8.8
CVE-2020-1977

Insufficient Cross-Site Request Forgery (XSRF) protection on Expedition Migration Tool allows remote unauthenticated attackers to hijack the authenti…

Fix: after 1.1.51
Fix from $1,950 2020-02-12
Globalprotect MEDIUM 5.5
CVE-2020-1976

A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect software running on Mac OS allows authenticated local users to cause the …

Fix: after 5.0.5
Fix from $1,600 2020-02-12
Pan Os CRITICAL 9.8
CVE-2019-17440

Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation Switch Management Card (SMC) may…

Fix: after 9.0.5
Fix from $2,300 2019-12-20
Pan Os HIGH 7.8
CVE-2019-17437

An improper authentication check in Palo Alto Networks PAN-OS may allow an authenticated low privileged non-superuser custom role user to elevate pri…

Fix: 7.1.25 / 8.0.20+
Fix from $1,950 2019-12-05
Globalprotect HIGH 7.1
CVE-2019-17436

A Local Privilege Escalation vulnerability exists in GlobalProtect Agent for Linux and Mac OS X version 5.0.4 and earlier and version 4.1.12 and earl…

Fix: after 5.0.4
Fix from $1,950 2019-10-16
Globalprotect MEDIUM 5.5
CVE-2019-17435

A Local Privilege Escalation vulnerability exists in the GlobalProtect Agent for Windows 5.0.3 and earlier, and GlobalProtect Agent for Windows 4.1.1…

Fix: after 5.0.3
Fix from $1,600 2019-10-16
Pan Os CRITICAL 9.8
CVE-2019-1580

Memory corruption in PAN-OS 7.1.24 and earlier, PAN-OS 8.0.19 and earlier, PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow a remote…

Fix: after 9.0.3
Fix from $2,300 2019-08-23
Pan Os CRITICAL 9.8
CVE-2019-1581

A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access…

Fix: after 9.0.3
Fix from $2,300 2019-08-23
Twistlock HIGH 8.0
CVE-2019-1583

Escalation of privilege vulnerability in the Palo Alto Networks Twistlock console 19.07.358 and earlier allows a Twistlock user with Operator capabil…

Fix: after 19.07.357
Fix from $1,950 2019-08-23
Pan Os HIGH 7.2
CVE-2019-1582

Memory corruption in PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow an administrative user to cause arbitrary memory corruption by…

Fix: after 9.0.3
Fix from $1,950 2019-08-23
Pan Os HIGH 8.1
CVE-2019-1579 KEVEPSS 46%

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalPro…

Fix: 7.1.19 / 8.0.12+
Fix from $1,950 2019-07-19
Pan Os HIGH 8.8
CVE-2019-1575

Information disclosure in PAN-OS 7.1.23 and earlier, PAN-OS 8.0.18 and earlier, PAN-OS 8.1.8-h4 and earlier, and PAN-OS 9.0.2 and earlier may allow f…

Fix: 7.1.24 / 8.0.19+
Fix from $1,950 2019-07-16
Pan Os HIGH 8.8
CVE-2019-1576

Command injection in PAN-0S 9.0.2 and earlier may allow an authenticated attacker to gain access to a remote shell in PAN-OS, and potentially run wit…

Fix: after 9.0.2
Fix from $1,950 2019-07-16
Traps MEDIUM 6.3
CVE-2019-1577

Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject arbitrary JavaScript or HTML.

Fix: after 5.0.5
Fix from $1,600 2019-07-01
Minemeld MEDIUM 6.1
CVE-2019-1578

Cross-site scripting vulnerability in Palo Alto Networks MineMeld version 0.9.60 and earlier may allow a remote attacker able to convince an authenti…

Fix: after 0.9.60
Fix from $1,600 2019-07-01
Demisto MEDIUM 6.1
CVE-2019-1568

Cross-site scripting (XSS) vulnerability in Palo Alto Networks Demisto 4.5 build 40249 may allow an unauthenticated attacker to run arbitrary JavaScr…

Mitigation only
Fix from $1,600 2019-05-09
Expedition Migration Tool MEDIUM 5.4
CVE-2019-1574

Cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition Migration tool 1.1.12 and earlier may allow an authenticated attacker to ru…

Fix: after 1.1.12
Fix from $1,600 2019-04-12
Expedition Migration Tool MEDIUM 5.4
CVE-2019-1567

The Expedition Migration tool 1.1.6 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings.

Fix: after 1.1.6
Fix from $1,600 2019-04-09
Pan Os HIGH 7.5
CVE-2019-1572

PAN-OS 9.0.0 may allow an unauthenticated remote user to access php files.

Mitigation only
Fix from $1,950 2019-03-26
Pan Os MEDIUM 6.1
CVE-2019-1566

The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an unauthenticat…

Fix: 7.1.22 / 8.0.15+
Fix from $1,600 2019-01-30