Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2023-0003 A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface… Cortex Xsoar 6.10.0.185964+ Fix from $1,6002023-02-08 MEDIUM 6.7 CVE-2022-0031 A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a l… Cortex Xsoar Mitigation only Fix from $1,6002022-11-09 HIGH 8.1 CVE-2022-0030 An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of … Pan Os 8.1.24+ Fix from $1,9502022-10-12 MEDIUM 5.5 CVE-2022-0029 An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the … Cortex Xdr Agent 5.0.12 / 7.5.101+ Fix from $1,6002022-09-14 HIGH 8.6 CVE-2022-0028 KEV A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) a… Pan Os 8.1.23 / 9.0.16+ Fix from $1,9502022-08-10 HIGH 7.2 CVE-2022-0024 A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated network-based PAN-OS administrator to upload a specificall… Pan Os 8.1.23 / 9.0.16+ Fix from $1,9502022-05-11 MEDIUM 6.7 CVE-2022-0025 A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local… Cortex Xdr Agent 7.7.1.62043+ Fix from $1,6002022-05-11 MEDIUM 6.7 CVE-2022-0026 A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local… Cortex Xdr Agent Mitigation only Fix from $1,6002022-05-11 MEDIUM 5.9 CVE-2022-0023 An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-OS software that enables a med… Pan Os 8.1.22 / 9.0.16+ Fix from $1,6002022-04-13 HIGH 7.8 CVE-2022-0016 An improper handling of exceptional conditions vulnerability exists within the Connect Before Logon feature of the Palo Alto Networks GlobalProtect a… Globalprotect 5.2.9+ Fix from $1,9502022-02-10 HIGH 7.8 CVE-2022-0017 An improper link resolution before file access ('link following') vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that en… Globalprotect 5.1.10 / 5.2.5+ Fix from $1,9502022-02-10 MEDIUM 6.5 CVE-2022-0011 PAN-OS software provides options to exclude specific websites from URL category enforcement and those websites are blocked or allowed (depending on y… Pan Os 8.1.21 / 9.1.12+ Fix from $1,6002022-02-10 MEDIUM 6.5 CVE-2022-0018 An information exposure vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows and MacOS where the credentials of the local user… Globalprotect 5.1.10 / 5.2.9+ Fix from $1,6002022-02-10 MEDIUM 5.5 CVE-2022-0019 An insufficiently protected credentials vulnerability exists in the Palo Alto Networks GlobalProtect app on Linux that exposes the hashed credentials… Globalprotect 5.1.10 / 5.3.2+ Fix from $1,6002022-02-10 MEDIUM 5.5 CVE-2022-0021 An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that logs the cleartext credenti… Globalprotect 5.2.9+ Fix from $1,6002022-02-10 MEDIUM 5.4 CVE-2022-0020 A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to … Cortex Xsoar No fix yet Fix from $1,6002022-02-10 HIGH 7.8 CVE-2022-0015 A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute… Cortex Xdr Agent 5.0.12 / 6.1.9+ Fix from $1,9502022-01-12 HIGH 7.3 CVE-2022-0014 An untrusted search path vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker with file creation privilege i… Cortex Xdr Agent 5.0.12 / 6.1.9+ Fix from $1,9502022-01-12 HIGH 7.1 CVE-2022-0012 An improper link resolution before file access vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables a lo… Cortex Xdr Agent 5.0.12 / 6.1.9+ Fix from $1,9502022-01-12 MEDIUM 5.5 CVE-2022-0013 A file information exposure vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker to read the contents of arb… Cortex Xdr Agent 5.0.12 / 6.1.9+ Fix from $1,6002022-01-12 CRITICAL 9.8 CVE-2021-3064EPSS 19% A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-ba… Pan Os 8.1.17+ Fix from $2,3002021-11-10 HIGH 8.8 CVE-2021-3062 An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to co… Pan Os 8.1.20 / 9.0.14+ Fix from $1,9502021-11-10 HIGH 8.1 CVE-2021-3059 An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates. This vulnerabilit… Pan Os 10.0.8 / 10.1.3+ Fix from $1,9502021-11-10 HIGH 8.1 CVE-2021-3060EPSS 34% An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated netwo… Prisma Access 10.0.8 / 10.1.3+ Fix from $1,9502021-11-10 HIGH 7.5 CVE-2021-3063 An improper handling of exceptional conditions vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an… Pan Os 8.1.21 / 10.1.3+ Fix from $1,9502021-11-10 HIGH 7.2 CVE-2021-3061 An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with acces… Prisma Access 10.0.8 / 10.1.3+ Fix from $1,9502021-11-10 HIGH 8.8 CVE-2021-3056 A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary co… Pan Os 8.1.20 / 9.0.14+ Fix from $1,9502021-11-10 HIGH 7.2 CVE-2021-3058 An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use X… Pan Os 10.0.8 / 10.1.3+ Fix from $1,9502021-11-10 HIGH 8.1 CVE-2021-3057 A stack-based buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the-middle attacker to disrupt s… Globalprotect 5.1.9 / 5.2.8+ Fix from $1,9502021-10-13 HIGH 7.5 CVE-2021-3053 An improper handling of exceptional conditions vulnerability exists in the Palo Alto Networks PAN-OS dataplane that enables an unauthenticated networ… Pan Os 8.1.20 / 9.0.14+ Fix from $1,9502021-09-08