paloaltonetworks

310 tracked vulnerabilities.

CVE-2024-5910 CRITICAL KEVNUCLEI
Palo Alto Expedition Remote Code Execution (CVE-2024-5910 and CVE-2024-9464)
Jul 10, 2024
CVSS 9.8
EPSS 0.91
CVE-2024-5909 MEDIUM
Cortex XDR Agent 7.9-7.9.101 and 8.1-8.1.1 - Local Privilege Escalation via Agent Disabling
Jun 12, 2024
CVSS 5.5
EPSS 0.01
CVE-2024-5908 HIGH
GlobalProtect 5.1-5.1.11 - Sensitive Information Exposure in Application Logs
Jun 12, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-5907 HIGH
Palo Alto Networks Cortex XDR Agent 7.9-7.9.101 and 8.1-8.2.2 - Local Privilege Escalation via Race Condition
Jun 12, 2024
CVSS 7.0
EPSS 0.00
CVE-2024-5906 MEDIUM
Prisma Cloud < 32.05.124 - Stored Cross-Site Scripting via Identity Provider Configuration
Jun 12, 2024
CVSS 4.8
EPSS 0.00
CVE-2024-5905 MEDIUM
Cortex XDR Agent 7.9.0-7.9.101 and 8.1-8.1.1 - Local Denial of Service via Protection Mechanism Bypass
Jun 12, 2024
CVSS 4.4
EPSS 0.00
CVE-2024-3661 HIGH
FortiClient 6.4.0-7.2.4 - Unauthenticated VPN Traffic Leak via DHCP Classless Static Route Option
May 06, 2024
CVSS 7.6
EPSS 0.03
CVE-2024-3400 CRITICAL KEVNUCLEI
Palo Alto Networks PAN-OS Unauthenticated Remote Code Execution
Apr 12, 2024
CVSS 10.0
EPSS 0.94
CVE-2024-3388 MEDIUM
Palo Alto Networks PAN-OS - Privilege Escalation
Apr 10, 2024
CVSS 4.1
EPSS 0.00
CVE-2024-3387 MEDIUM
Palo Alto Networks Panorama - Info Disclosure
Apr 10, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-3386 MEDIUM
Palo Alto Networks PAN-OS - Info Disclosure
Apr 10, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-3385 HIGH
Palo Alto Networks PAN-OS PA-5400/PA-7000 - Packet Processing Denial of Service
Apr 10, 2024
CVSS 7.5
EPSS 0.03
CVE-2024-3384 HIGH
Palo Alto Networks PAN-OS - NTLM Packet Denial of Service
Apr 10, 2024
CVSS 7.5
EPSS 0.01
CVE-2024-3383 HIGH
Palo Alto Networks PAN-OS - Privilege Escalation
Apr 10, 2024
CVSS 7.4
EPSS 0.00
CVE-2024-3382 HIGH
Palo Alto Networks PAN-OS - Memory Corruption
Apr 10, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-2433 MEDIUM
Palo Alto Networks Panorama - Privilege Escalation
Mar 13, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-2432 MEDIUM
Palo Alto Networks GlobalProtect < - Privilege Escalation
Mar 13, 2024
CVSS 4.5
EPSS 0.00
CVE-2024-2431 MEDIUM
Palo Alto Networks GlobalProtect - Privilege Escalation
Mar 13, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-0011 MEDIUM
PAN-OS 8.1.0-8.1.23 - Reflected Cross-Site Scripting in Captive Portal
Feb 14, 2024
CVSS 4.3
EPSS 0.01
CVE-2024-0010 MEDIUM
Palo Alto Networks PAN-OS 10.1.0-10.1.10 - Reflected Cross-Site Scripting in GlobalProtect Portal
Feb 14, 2024
CVSS 4.3
EPSS 0.04
CVE-2024-0009 MEDIUM
Palo Alto Networks PAN-OS 10.2.0-10.2.3 - Authenticated VPN Connection from Unauthorized IP via GlobalProtect Gateway
Feb 14, 2024
CVSS 6.3
EPSS 0.00
CVE-2024-0008 MEDIUM
PAN-OS >=10.2.0 <10.2.5 - Insufficient Session Expiration
Feb 14, 2024
CVSS 6.6
EPSS 0.00
CVE-2024-0007 MEDIUM
PAN-OS 8.1.0-8.1.23 - Authenticated Stored Cross-Site Scripting via Web Interface
Feb 14, 2024
CVSS 6.8
EPSS 0.01
CVE-2023-6795 MEDIUM
PAN-OS 8.1.0-8.1.23 - Authenticated OS Command Injection
Dec 13, 2023
CVSS 5.5
EPSS 0.00
CVE-2023-6794 MEDIUM
PAN-OS 8.1.0-8.1.25 - Authenticated Arbitrary File Upload
Dec 13, 2023
CVSS 5.5
EPSS 0.00