CVE Tools

Symantec Privileged Access Management

19 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Symantec Privileged Access Management, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.

Symantec Privileged Access Management CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Symantec Privileged Access Management CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-018
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 19 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical133%
  • High133%
  • Medium133%

Latest CVEs

The 15 most recently published vulnerabilities affecting Symantec Privileged Access Management.

  1. CVE-2025-24507This vulnerability allows appliance compromise at boot time.—
  2. CVE-2025-24506A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.—
  3. CVE-2025-24505This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file.—
  4. CVE-2025-24504An improper input validation the CSRF filter results in unsanitized user input written to the application logs.—
  5. CVE-2025-24503A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.9.6
  6. CVE-2025-24502An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.—
  7. CVE-2025-24501An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request.—
  8. CVE-2025-24500The vulnerability allows an unauthenticated attacker to access information in PAM database.—
  9. CVE-2024-38496Symantec Privileged Access Manager Insecure Direct Object Reference vulnerability—
  10. CVE-2024-38495Symantec Privileged Access Manager User Enumeration vulnerability—
  11. CVE-2024-38494Symantec Privileged Access Manager Remote Command Execution vulnerability—
  12. CVE-2024-38493Symantec Privileged Access Manager Reflected Cross Site Scripting vulnerability6.1
  13. CVE-2024-38492Symantec Privileged Access Manager Remote Command Execution vulnerability—
  14. CVE-2024-38491Symantec Privileged Access Manager SQL Injection vulnerability—
  15. CVE-2024-36458Symantec Privileged Access Manager Privilege Escalation vulnerability—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store