Paloaltonetworks
paloaltonetworks
371 CVEs • 125 products
Products (125)
Click to collapseToggle
Products (125)
Click to collapse
CVEs (371)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, dev...Show more |
A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by...Show more |
1Paloaltonetworks 1Cortex Xdr Agent Jun 17, 2026 Sep 11, 2024 5.6 MEDIUM· v4 4.4 MEDIUM· v3 N/A· v2 A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to disable the agent. This issue may be leveraged by malware to disa...Show more |
An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access to the CLI...Show more |
1Paloaltonetworks 3Globalprotect Pan OsPrisma AccessJun 17, 2026 Sep 11, 2024 6.9 MEDIUM· v4 7.1 HIGH· v3 N/A· v2 An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconn...Show more |
A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall. |
An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator w...Show more |
1Paloaltonetworks 1Globalprotect Jun 17, 2026 Aug 14, 2024 5.2 MEDIUM· v4 7.8 HIGH· v3 N/A· v2 A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. |
1Paloaltonetworks 1Cortex Xsoar Commonscripts Jun 17, 2026 Aug 14, 2024 7.0 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container. |
An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical file system to elevate privileges. |
An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the Panorama. Repeat...Show more |
1Paloaltonetworks 1Expedition Jun 17, 2026 Jul 10, 2024 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in conf...Show more |
1Paloaltonetworks 1Cortex Xdr Agent Jun 17, 2026 Jun 12, 2024 6.8 MEDIUM· v4 5.5 MEDIUM· v3 N/A· v2 A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the C...Show more |
1Paloaltonetworks 1Globalprotect Jun 17, 2026 Jun 12, 2024 5.5 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, in application logs. Normally, these application logs are only viewable...Show more |
1Paloaltonetworks 1Cortex Xdr Agent Jun 17, 2026 Jun 12, 2024 5.2 MEDIUM· v4 7.0 HIGH· v3 N/A· v2 A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to...Show more |
1Paloaltonetworks 1Prisma Cloud Jun 17, 2026 Jun 12, 2024 4.8 MEDIUM· v4 4.8 MEDIUM· v3 N/A· v2 A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious administrator with add/edit permissions for identity providers to store a JavaScript payload using the we...Show more |
1Paloaltonetworks 1Cortex Xdr Agent Jun 17, 2026 Jun 12, 2024 2.0 LOW· v4 4.4 MEDIUM· v3 N/A· v2 A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to dis...Show more |
7Cisco CitrixF5+4 more9Anyconnect Vpn Client Big Ip Access Policy ManagerClient Connector+6 moreJun 17, 2026 May 6, 2024 N/A· v4 7.6 HIGH· v3 N/A· v2 DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface....Show more |
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an u...Show more |
1Paloaltonetworks 2Pan Os Prisma AccessJun 17, 2026 Apr 10, 2024 N/A· v4 5.0 MEDIUM· v3 N/A· v2 A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability do...Show more |