paloaltonetworks

310 tracked vulnerabilities.

CVE-2024-5919 MEDIUM
PAN-OS 10.1.0-10.1.9 - Authenticated XML External Entity Injection
Nov 14, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-5918 MEDIUM
Palo Alto Networks PAN-OS - Improper Certificate Validation in GlobalProtect Portal/Gateway
Nov 14, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-5917 MEDIUM
PAN-OS 10.1.0-10.1.6 - Authenticated Server-Side Request Forgery via Administrative Web Interface
Nov 14, 2024
CVSS 4.9
EPSS 0.00
CVE-2024-2552 MEDIUM
PAN-OS >=10.2.0 <10.2.7 - Authenticated Command Injection via Management Plane
Nov 14, 2024
CVSS 6.0
EPSS 0.00
CVE-2024-2551 HIGH
Palo Alto Networks PAN-OS 10.1.0-10.1.13 - Unauthenticated Denial of Service via Crafted Data Plane Packet
Nov 14, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-2550 HIGH
Palo Alto Networks PAN-OS 10.2.0-10.2.6 DoS via GlobalProtect Gateway Null Pointer Dereference
Nov 14, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-9473 HIGH
Palo Alto Networks GlobalProtect - Privilege Escalation via MSI Installer Repair Functionality
Oct 09, 2024
CVSS 7.8
EPSS 0.00
CVE-2024-9471 MEDIUM
Palo Alto Networks PAN-OS 9.0.0-9.9.9 - Authenticated Privilege Escalation via XML API Key Misuse
Oct 09, 2024
CVSS 4.7
EPSS 0.00
CVE-2024-9469 MEDIUM
Cortex XDR Agent 7.9-7.9.101 - Detection Mechanism Bypass via Non-Administrative Privileges
Oct 09, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-9468 HIGH
Palo Alto Networks PAN-OS >= 10.2.0 < 10.2.4 - Unauthenticated Denial of Service via Crafted Data Plane Packet
Oct 09, 2024
CVSS 7.5
EPSS 0.01
CVE-2024-9467 MEDIUM
Palo Alto Networks Expedition 1.2.0-1.2.95 - Reflected Cross-Site Scripting
Oct 09, 2024
CVSS 6.1
EPSS 0.01
CVE-2024-9466 MEDIUM
Palo Alto Networks Expedition 1.2.0-1.2.95 - Authenticated Sensitive Information Disclosure in Log Files
Oct 09, 2024
CVSS 6.5
EPSS 0.20
CVE-2024-9465 CRITICAL KEVNUCLEI
Palo Alto Networks Expedition 1.2.0-1.2.95 - Unauthenticated SQL Injection and Arbitrary File Write
Oct 09, 2024
CVSS 9.1
EPSS 0.94
CVE-2024-9464 MEDIUM
Palo Alto Networks Expedition 1.2.0-1.2.95 - Authenticated OS Command Injection
Oct 09, 2024
CVSS 6.5
EPSS 0.85
CVE-2024-9463 HIGH KEVNUCLEI
Palo Alto Networks Expedition 1.2.0-1.2.95 - Unauthenticated OS Command Injection
Oct 09, 2024
CVSS 7.5
EPSS 0.94
CVE-2024-8691 HIGH
Palo Alto Networks PAN-OS - Privilege Escalation
Sep 11, 2024
CVSS 7.1
EPSS 0.00
CVE-2024-8690 MEDIUM
Palo Alto Networks Cortex XDR < - Privilege Escalation
Sep 11, 2024
CVSS 4.4
EPSS 0.00
CVE-2024-8688 MEDIUM
Palo Alto Networks PAN-OS - Info Disclosure
Sep 11, 2024
CVSS 4.4
EPSS 0.00
CVE-2024-8687 HIGH
Palo Alto Networks PAN-OS - Info Disclosure
Sep 11, 2024
CVSS 7.1
EPSS 0.00
CVE-2024-8686 HIGH
Palo Alto Networks PAN-OS - Command Injection
Sep 11, 2024
CVSS 7.2
EPSS 0.00
CVE-2024-5916 MEDIUM
Palo Alto Networks PAN-OS - Info Disclosure
Aug 14, 2024
CVSS 4.4
EPSS 0.00
CVE-2024-5915 HIGH
GlobalProtect 5.1.0-5.1.8 - Privilege Escalation
Aug 14, 2024
CVSS 7.8
EPSS 0.00
CVE-2024-5914 CRITICAL
Cortex XSOAR CommonScripts < 1.12.33 - Unauthenticated Command Injection
Aug 14, 2024
CVSS 9.8
EPSS 0.02
CVE-2024-5913 MEDIUM
Palo Alto Networks PAN-OS 10.1.0-10.1.13 - Privilege Escalation via Physical File System Tampering
Jul 10, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-5911 MEDIUM
Palo Alto Networks Pan-OS 10.1.0-10.1.8 - Authenticated Arbitrary File Upload
Jul 10, 2024
CVSS 4.9
EPSS 0.00