5.1

CVSS4.0

CVE-2024-9471 - PAN-OS: Privilege Escalation (PE) Vulnerability in XML API

A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privileged PAN-OS administrator. For example, an administrator with…

πŸ“… Published: Oct. 9, 2024, 5:06 p.m. πŸ”„ Last Modified: Oct. 18, 2024, 11:58 a.m.

5.3

CVSS4.0

CVE-2024-9470 - Cortex XSOAR: Information Disclosure Vulnerability

A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view the data.

πŸ“… Published: Oct. 9, 2024, 5:06 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS4.0

CVE-2024-9469 - Cortex XDR Agent: Local Windows User Can Disable the Agent

A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.

πŸ“… Published: Oct. 9, 2024, 5:05 p.m. πŸ”„ Last Modified: Oct. 18, 2024, 11:55 a.m.

8.2

CVSS4.0

CVE-2024-9468 - PAN-OS: Firewall Denial of Service (DoS) via a Maliciously Crafted Packet

A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condition will result in PAN-OS entering mai…

πŸ“… Published: Oct. 9, 2024, 5:05 p.m. πŸ”„ Last Modified: Dec. 1, 2025, 5:19 p.m.

7

CVSS4.0

CVE-2024-9467 - Expedition: Reflected Cross-Site Scripting Vulnerability Leads to Expedition Session Disclosure

A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a malicious link, allowing phishing attacks that could lead to Expedition browser session theft.

πŸ“… Published: Oct. 9, 2024, 5:04 p.m. πŸ”„ Last Modified: Oct. 18, 2024, 11:52 a.m.

8.2

CVSS4.0

CVE-2024-9466 - Expedition: Cleartext Storage of Information Leads to Firewall Admin Credential Disclosure

A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials.

πŸ“… Published: Oct. 9, 2024, 5:04 p.m. πŸ”„ Last Modified: Sept. 4, 2025, 3:09 p.m.

9.2

CVSS4.0

CVE-2024-9465 - Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition …

πŸ“… Published: Oct. 9, 2024, 5:04 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 4:49 p.m.

9.3

CVSS4.0

CVE-2024-9464 - Expedition: Authenticated OS Command Injection Vulnerability Leads to Firewall Admin Credential Dis…

An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

πŸ“… Published: Oct. 9, 2024, 5:03 p.m. πŸ”„ Last Modified: Oct. 18, 2024, 3:40 p.m.

9.9

CVSS4.0

CVE-2024-9463 - Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclos…

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

πŸ“… Published: Oct. 9, 2024, 5:03 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 4:48 p.m.

7.4

CVSS3.1

CVE-2024-43610 - Copilot Studio Information Disclosure Vulnerability

Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector

πŸ“… Published: Oct. 9, 2024, 4:26 p.m. πŸ”„ Last Modified: July 8, 2025, 3:39 p.m.
Total resulsts: 349182
Page 8337 of 34,919
Β« previous page Β» next page
Filters