VendorsPalo Alto Networkspan-osany version
Vulnerabilities

Palo Alto Networks paloaltonetworks pan-os any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

219CVEs
CVE-2020-2014
PAN-OS: OS injection vulnerability in PAN-OS management server
Published 2020-05-13 · Modified
9.0EPSS 0.027
CVE-2016-3654
The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote authenticated administrators to execute arbitrary OS commands via an SSH command parameter.
Published 2016-04-12 · Modified
9.0EPSS 0.026
CVE-2020-2030
PAN-OS: OS command injection vulnerability in the management interface
Published 2020-07-08 · Modified
9.0EPSS 0.025
CVE-2020-2042
PAN-OS: Buffer overflow in the management web interface
Published 2020-09-09 · Modified
9.0EPSS 0.023
CVE-2020-2007
PAN-OS: OS command injection in management server
Published 2020-05-13 · Modified
9.0EPSS 0.022
CVE-2020-2010
PAN-OS: Authenticated user command injection vulnerability
Published 2020-05-13 · Modified
9.0EPSS 0.022
CVE-2020-1990
PAN-OS: Buffer overflow in the management server
Published 2020-04-08 · Modified
9.0EPSS 0.021
CVE-2020-2027
PAN-OS: Buffer overflow in authd authentication response
Published 2020-06-10 · Modified
9.0EPSS 0.021
CVE-2020-2009
PAN-OS: Panorama SD WAN arbitrary file creation
Published 2020-05-13 · Modified
9.0EPSS 0.020
CVE-2020-2015
PAN-OS: Buffer overflow in the management server
Published 2020-05-13 · Modified
9.0EPSS 0.019
CVE-2020-2006
PAN-OS: Buffer overflow in management server payload parser
Published 2020-05-13 · Modified
9.0EPSS 0.019
CVE-2020-2028
PAN-OS: OS command injection vulnerability in FIPS-CC mode certificate verification
Published 2020-06-10 · Modified
9.0EPSS 0.018
CVE-2021-3050
PAN-OS: OS Command Injection Vulnerability in Web Interface
Published 2021-08-11 · Modified
9.0EPSS 0.018
CVE-2020-2029
PAN-OS: OS command injection vulnerability in management interface certificate generator
Published 2020-06-10 · Modified
9.0EPSS 0.018
CVE-2021-3058
PAN-OS: OS Command Injection Vulnerability in Web Interface XML API
Published 2021-11-10 · Modified
9.0EPSS 0.016
CVE-2022-0024
PAN-OS: Improper Neutralization Vulnerability Leads to Unintended Program Execution During Configuration Commit
Published 2022-05-11 · Modified
9.0EPSS 0.015
CVE-2021-3061
PAN-OS: OS Command Injection Vulnerability in the Command Line Interface (CLI)
Published 2021-11-10 · Modified
9.0EPSS 0.009
CVE-2016-4971
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
Published 2016-06-30 · Modified
8.82 PoCEPSS 0.461
CVE-2020-2036
PAN-OS: Reflected Cross-Site Scripting (XSS) vulnerability in management web interface
Published 2020-09-09 · Modified
8.8EPSS 0.239
CVE-2019-1576
Command injection in PAN-0S 9.0.2 and earlier may allow an authenticated attacker to gain access to a remote shell in PAN-OS, and potentially run with the escalated user’s permissions.
Published 2019-07-16 · Modified
8.8EPSS 0.018
CVE-2019-1575
Information disclosure in PAN-OS 7.1.23 and earlier, PAN-OS 8.0.18 and earlier, PAN-OS 8.1.8-h4 and earlier, and PAN-OS 9.0.2 and earlier may allow for an authenticated user with read-only privileges to extract the API key of the device and/or the username/password from the XML API (in PAN-OS) and possibly escalate privileges granted to them.
Published 2019-07-16 · Modified
8.8EPSS 0.017
CVE-2021-3056
PAN-OS: Memory Corruption Vulnerability in GlobalProtect Clientless VPN During SAML Authentication
Published 2021-11-10 · Modified
8.8EPSS 0.015
CVE-2020-1975
Missing XML Validation in PAN-OS Web Interface
Published 2020-02-12 · Modified
8.8EPSS 0.010
CVE-2020-1998
PAN-OS: Improper SAML SSO authorization of shared local users
Published 2020-05-13 · Modified
8.8EPSS 0.009
CVE-2020-2017
PAN-OS: DOM-Based cross site scripting vulnerability in management web interface
Published 2020-05-13 · Modified
8.8EPSS 0.008
CVE-2021-3062
PAN-OS: Improper Access Control Vulnerability Exposing AWS Instance Metadata Endpoint to GlobalProtect Users
Published 2021-11-10 · Modified
8.8EPSS 0.007
CVE-2023-6790
PAN-OS: DOM-Based Cross-Site Scripting (XSS) Vulnerability in the Web Interface
Published 2023-12-13 · Modified
8.8EPSS 0.007
CVE-2020-2013
PAN-OS: Panorama context switch session cookie disclosure
Published 2020-05-13 · Modified
8.8EPSS 0.006
CVE-2024-0008
PAN-OS: Insufficient Session Expiration Vulnerability in the Web Interface
Published 2024-02-14 · Analyzed
8.8EPSS 0.005
CVE-2026-0259
WildFire WF-500 and WF-500-B: Arbitrary File Read and Delete Vulnerability in WildFire Appliance (WF-500, WF-500-B)
Published 2026-05-13 · Analyzed
8.8EPSS 0.003
CVE-2024-3393
PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet
Published 2024-12-27 · Analyzed
8.7KEVEPSS 0.284
CVE-2024-2550
PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway Using a Specially Crafted Packet
Published 2024-11-14 · Analyzed
8.7EPSS 0.005
CVE-2024-2551
PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet
Published 2024-11-14 · Analyzed
8.7EPSS 0.005
CVE-2022-0028
PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering
Published 2022-08-10 · Analyzed
8.6KEVEPSS 0.024
CVE-2024-8686
PAN-OS: Command Injection Vulnerability
Published 2024-09-11 · Analyzed
8.6EPSS 0.014
CVE-2025-4231
PAN-OS: Authenticated Admin Command Injection Vulnerability in the Management Web Interface
Published 2025-06-12 · Analyzed
8.6EPSS 0.010
CVE-2020-2003
PAN-OS: Authenticated administrator can delete arbitrary system file
Published 2020-05-13 · Modified
8.5EPSS 0.009
CVE-2021-3054
PAN-OS: Unsigned Code Execution During Plugin Installation Race Condition Vulnerability
Published 2021-09-08 · Modified
8.5EPSS 0.009
CVE-2020-2016
PAN-OS: Temporary file race condition vulnerability in PAN-OS leads to local privilege escalation
Published 2020-05-13 · Modified
8.5EPSS 0.006
CVE-2020-2050
PAN-OS: Authentication bypass vulnerability in GlobalProtect SSL VPN client certificate verification
Published 2020-11-12 · Modified
8.2EPSS 0.010
← Prev2 / 6Next →