7.5

CVSS3.1

CVE-2024-45254 - VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Script…

VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

πŸ“… Published: Nov. 14, 2024, 9:46 a.m. πŸ”„ Last Modified: Nov. 15, 2024, 1:58 p.m.

7.5

CVSS3.1

CVE-2024-45253 - Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

πŸ“… Published: Nov. 14, 2024, 9:43 a.m. πŸ”„ Last Modified: Nov. 15, 2024, 1:58 p.m.

8.7

CVSS4.0

CVE-2024-2550 - PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway Using a Specially Crafted Packet

A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially crafted packet that causes a denial of service (DoS) condition. Repeated attempts …

πŸ“… Published: Nov. 14, 2024, 9:40 a.m. πŸ”„ Last Modified: Jan. 24, 2025, 4:02 p.m.

4.6

CVSS4.0

CVE-2024-5920 - PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in PAN-OS Enables Impersonation of a Legiti…

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions …

πŸ“… Published: Nov. 14, 2024, 9:40 a.m. πŸ”„ Last Modified: April 30, 2025, 6:39 p.m.

2.1

CVSS4.0

CVE-2024-5917 - PAN-OS: Server-Side Request Forgery in WildFire

A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.

πŸ“… Published: Nov. 14, 2024, 9:39 a.m. πŸ”„ Last Modified: Jan. 24, 2025, 4:04 p.m.

6.8

CVSS4.0

CVE-2024-2552 - PAN-OS: Arbitrary File Delete Vulnerability in the Command Line Interface (CLI)

A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the management plane and delete files on the firewall.

πŸ“… Published: Nov. 14, 2024, 9:39 a.m. πŸ”„ Last Modified: Jan. 24, 2025, 4:04 p.m.

5.3

CVSS4.0

CVE-2024-5918 - PAN-OS: Improper Certificate Validation Enables Impersonation of a Legitimate GlobalProtect User

An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "…

πŸ“… Published: Nov. 14, 2024, 9:38 a.m. πŸ”„ Last Modified: Oct. 1, 2025, 6:41 p.m.

5.1

CVSS4.0

CVE-2024-5919 - PAN-OS: Authenticated XML External Entities (XXE) Injection Vulnerability

A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management interface.

πŸ“… Published: Nov. 14, 2024, 9:36 a.m. πŸ”„ Last Modified: Jan. 24, 2025, 4:06 p.m.

8.7

CVSS4.0

CVE-2024-2551 - PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet

A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) condition. Repeated attempts to trigger this cond…

πŸ“… Published: Nov. 14, 2024, 9:36 a.m. πŸ”„ Last Modified: Jan. 24, 2025, 4:03 p.m.

8.7

CVSS4.0

CVE-2024-9472 - PAN-OS: Firewall Denial of Service (DoS) Using Specially Crafted Traffic

A null pointer dereference in Palo Alto Networks PAN-OS software on PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series hardware platforms when Decryption policy is enabled allows an unauthenticated attacker to crash PAN-OS by sending specific traffic through the data plane, resulting…

πŸ“… Published: Nov. 14, 2024, 9:34 a.m. πŸ”„ Last Modified: Nov. 15, 2024, 1:58 p.m.
Total resulsts: 343944
Page 7357 of 34,395
Β« previous page Β» next page
Filters