VendorsPalo Alto Networkspan-osall versions
Vulnerabilities

Palo Alto Networks paloaltonetworks pan-os

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

235CVEs
CVE-2022-0028
PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering
Published 2022-08-10 · Analyzed
8.6KEVEPSS 0.024
CVE-2024-8686
PAN-OS: Command Injection Vulnerability
Published 2024-09-11 · Analyzed
8.6EPSS 0.014
CVE-2025-4231
PAN-OS: Authenticated Admin Command Injection Vulnerability in the Management Web Interface
Published 2025-06-12 · Analyzed
8.6EPSS 0.010
CVE-2020-2003
PAN-OS: Authenticated administrator can delete arbitrary system file
Published 2020-05-13 · Modified
8.5EPSS 0.009
CVE-2021-3054
PAN-OS: Unsigned Code Execution During Plugin Installation Race Condition Vulnerability
Published 2021-09-08 · Modified
8.5EPSS 0.009
CVE-2020-2016
PAN-OS: Temporary file race condition vulnerability in PAN-OS leads to local privilege escalation
Published 2020-05-13 · Modified
8.5EPSS 0.006
CVE-2020-2050
PAN-OS: Authentication bypass vulnerability in GlobalProtect SSL VPN client certificate verification
Published 2020-11-12 · Modified
8.2EPSS 0.010
CVE-2025-0130
PAN-OS: Firewall Denial-of-Service (DoS) in the Web-Proxy Feature via a Burst of Maliciously Crafted Packets
Published 2025-05-14 · Modified
8.2EPSS 0.004
CVE-2024-9468
PAN-OS: Firewall Denial of Service (DoS) via a Maliciously Crafted Packet
Published 2024-10-09 · Analyzed
8.2EPSS 0.004
CVE-2025-0114
PAN-OS: Denial of Service (DoS) in GlobalProtect
Published 2025-03-12 · Analyzed
8.2EPSS 0.004
CVE-2019-1579
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.
Published 2019-07-19 · Analyzed
8.1KEVEPSS 0.462
CVE-2021-3059
PAN-OS: OS Command Injection Vulnerability When Performing Dynamic Updates
Published 2021-11-10 · Modified
8.1EPSS 0.015
CVE-2020-2002
PAN-OS: Spoofed Kerberos key distribution center authentication bypass
Published 2020-05-13 · Modified
8.1EPSS 0.013
CVE-2026-0265
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
Published 2026-05-13 · Analyzed
8.1EPSS 0.011
CVE-2020-1979
PAN-OS: A format string vulnerability in PAN-OS log daemon (logd) on Panorama allows local privilege escalation
Published 2020-03-11 · Modified
8.1EPSS 0.010
CVE-2022-0030
PAN-OS: Authentication Bypass in Web Interface
Published 2022-10-12 · Modified
8.1EPSS 0.009
CVE-2021-3052
PAN-OS: Reflected Cross-Site Scripting (XSS) in Web Interface
Published 2021-09-08 · Modified
8.0EPSS 0.006
CVE-2018-14634
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.
Published 2018-09-25 · Analyzed
7.8KEV1 PoCEPSS 0.147
CVE-2020-2041
PAN-OS: Management web interface denial-of-service (DoS)
Published 2020-09-09 · Modified
7.8EPSS 0.021
CVE-2020-2011
PAN-OS: Panorama registration denial of service
Published 2020-05-13 · Modified
7.8EPSS 0.018
CVE-2016-9151
Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows local users to gain privileges via crafted values of unspecified environment variables.
Published 2016-11-19 · Modified
7.82 PoCEPSS 0.012
CVE-2020-1980
PAN-OS: Shell injection vulnerability in PAN-OS CLI allows execution of shell commands
Published 2020-03-11 · Modified
7.8EPSS 0.006
CVE-2017-7218
The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to gain privileges via unspecified request parameters.
Published 2017-04-14 · Modified
7.8EPSS 0.005
CVE-2020-1981
PAN-OS: Predictable temporary filename vulnerability allows local privilege escalation
Published 2020-03-11 · Modified
7.8EPSS 0.004
CVE-2016-1712
Palo Alto Networks PAN-OS before 5.0.19, 5.1.x before 5.1.12, 6.0.x before 6.0.14, 6.1.x before 6.1.12, and 7.0.x before 7.0.8 might allow local users to gain privileges by leveraging improper sanitization of the root_reboot local invocation.
Published 2016-08-02 · Modified
7.8EPSS 0.004
CVE-2019-17437
PAN-OS: Custom-role users may escalate privileges
Published 2019-12-05 · Modified
7.8EPSS 0.003
CVE-2016-8610
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
Published 2017-11-13 · Modified
7.5EPSS 0.397
CVE-2019-1572
PAN-OS 9.0.0 may allow an unauthenticated remote user to access php files.
Published 2019-03-26 · Modified
7.5EPSS 0.025
CVE-2017-15942
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.13, and 8.0.x before 8.0.6 allows remote attackers to cause a denial of service via vectors related to the management interface.
Published 2017-12-11 · Modified
7.5EPSS 0.022
CVE-2020-2012
PAN-OS: Panorama: XML external entity reference ('XXE') vulnerability leads the to information leak
Published 2020-05-13 · Modified
7.5EPSS 0.019
CVE-2016-3656
The GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote attackers to cause a denial of service (service crash) via a crafted request.
Published 2016-04-12 · Modified
7.5EPSS 0.018
CVE-2020-2022
PAN-OS: Panorama session disclosure during context switch into managed device
Published 2020-11-12 · Modified
7.5EPSS 0.012
CVE-2021-3055
PAN-OS: XML External Entity (XXE) Reference Vulnerability in the PAN-OS Web Interface
Published 2021-09-08 · Modified
7.5EPSS 0.011
CVE-2021-3053
PAN-OS: Exceptional Condition Denial-of-Service (DoS)
Published 2021-09-08 · Modified
7.5EPSS 0.010
CVE-2021-3063
PAN-OS: Denial-of-Service (DoS) Vulnerability in GlobalProtect Portal and Gateway Interfaces
Published 2021-11-10 · Modified
7.5EPSS 0.009
CVE-2024-3382
PAN-OS: Firewall Denial of Service (DoS) via a Burst of Crafted Packets
Published 2024-04-10 · Analyzed
7.5EPSS 0.009
CVE-2024-3385
PAN-OS: Firewall Denial of Service (DoS) when GTP Security is Disabled
Published 2024-04-10 · Analyzed
7.5EPSS 0.009
CVE-2024-3384
PAN-OS: Firewall Denial of Service (DoS) via Malformed NTLM Packets
Published 2024-04-10 · Analyzed
7.5EPSS 0.009
CVE-2026-0288
PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent
Published 2026-07-08 · Modified
7.5EPSS 0.008
CVE-2026-0227
PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal
Published 2026-01-15 · Analyzed
7.5EPSS 0.007
← Prev3 / 6Next →