VendorsPalo Alto Networksexpeditionall versions
Vulnerabilities

Palo Alto Networks Expedition

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2018-10143
The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system level commands on the device hosting this service/application.
Published 2018-12-12 · Modified
10.0EPSS 0.248
CVE-2024-9463
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
Published 2024-10-09 · Analyzed
9.9KEVEPSS 0.985
CVE-2024-5910
Expedition: Missing Authentication Leads to Admin Account Takeover
Published 2024-07-10 · Analyzed
9.8KEV1 PoCEPSS 0.918
CVE-2025-0107
Expedition: OS Command Injection Vulnerability
Published 2025-01-11 · Analyzed
9.8EPSS 0.785
CVE-2024-9464
Expedition: Authenticated OS Command Injection Vulnerability Leads to Firewall Admin Credential Disclosure
Published 2024-10-09 · Modified
9.3EPSS 0.826
CVE-2024-9465
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
Published 2024-10-09 · Analyzed
9.2KEVEPSS 0.996
CVE-2025-0103
Expedition: SQL Injection Vulnerability
Published 2025-01-11 · Analyzed
9.2EPSS 0.006
CVE-2025-0105
Expedition: Arbitrary File Deletion Vulnerability
Published 2025-01-11 · Analyzed
9.1EPSS 0.133
CVE-2024-9466
Expedition: Cleartext Storage of Information Leads to Firewall Admin Credential Disclosure
Published 2024-10-09 · Modified
8.2EPSS 0.136
CVE-2018-10142
The Expedition Migration tool 1.0.106 and earlier may allow an unauthenticated attacker to enumerate files on the operating system.
Published 2018-11-27 · Modified
7.5EPSS 0.022
CVE-2024-9467
Expedition: Reflected Cross-Site Scripting Vulnerability Leads to Expedition Session Disclosure
Published 2024-10-09 · Analyzed
7.0EPSS 0.007
CVE-2025-0104
Expedition: Cross-Site Scripting (XSS) Vulnerability
Published 2025-01-11 · Analyzed
7.0EPSS 0.004
CVE-2025-0106
Expedition: Wildcard Expansion Vulnerability
Published 2025-01-11 · Analyzed
6.9EPSS 0.005
CVE-2019-1569
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings for account name of admin user.
Published 2019-03-26 · Modified
4.8EPSS 0.011
CVE-2019-1570
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the LDAP server settings.
Published 2019-03-26 · Modified
4.8EPSS 0.011
CVE-2019-1571
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the RADIUS server settings.
Published 2019-03-26 · Modified
4.8EPSS 0.011