CVEs (16)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Paloaltonetworks 1Expedition Jun 17, 2026 Jan 11, 2025 7.7 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cl...Show more |
1Paloaltonetworks 1Expedition Jun 17, 2026 Jan 11, 2025 6.9 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 A wildcard expansion vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to enumerate files on the host filesystem. |
1Paloaltonetworks 1Expedition Jun 17, 2026 Jan 11, 2025 6.9 MEDIUM· v4 9.1 CRITICAL· v3 N/A· v2 An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to the www-data user on the host filesystem. |
A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authentica...Show more |
1Paloaltonetworks 1Expedition Jun 17, 2026 Jan 11, 2025 9.2 CRITICAL· v4 8.8 HIGH· v3 N/A· v2 An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. Th...Show more |
A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a malicious link, allowing phis...Show more |
A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials. |
1Paloaltonetworks 1Expedition Jun 17, 2026 Oct 9, 2024 9.2 CRITICAL· v4 9.1 CRITICAL· v3 N/A· v2 An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. W...Show more |
1Paloaltonetworks 1Expedition Jun 17, 2026 Oct 9, 2024 9.3 CRITICAL· v4 6.5 MEDIUM· v3 N/A· v2 An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, devic...Show more |
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, dev...Show more |
1Paloaltonetworks 1Expedition Jun 17, 2026 Jul 10, 2024 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in conf...Show more |
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the RADIUS server settings. |
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the LDAP server settings. |
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings for account name of admin user. |
1Paloaltonetworks 1Expedition Nov 21, 2024 Dec 12, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system level commands on the device hosting this service/application. |
The Expedition Migration tool 1.0.106 and earlier may allow an unauthenticated attacker to enumerate files on the operating system. |