VendorsPalo Alto Networkspan-osall versions
Vulnerabilities

Palo Alto Networks paloaltonetworks pan-os

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

235CVEs
CVE-2026-0287
PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
Published 2026-07-09 · Modified
7.5EPSS 0.006
CVE-2026-0262
PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing
Published 2026-05-13 · Analyzed
7.5EPSS 0.004
CVE-2026-0301
PAN-OS: Information Disclosure Vulnerability in URL Filtering
Published 2026-08-13 · Analyzed
7.5EPSS 0.003
CVE-2024-9474
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
Published 2024-11-18 · Analyzed
7.2KEVEPSS 0.947
CVE-2016-5195
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."
Published 2016-11-10 · Analyzed
7.2KEV5 PoCEPSS 0.835
CVE-2026-0286
PAN-OS: Authenticated Command Injection in CLI
Published 2026-07-09 · Modified
7.2EPSS 0.017
CVE-2026-0261
PAN-OS: Authenticated Admin Command Injection Vulnerability
Published 2026-05-13 · Analyzed
7.2EPSS 0.014
CVE-2026-0273
PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI
Published 2026-06-10 · Modified
7.2EPSS 0.013
CVE-2019-1582
Memory corruption in PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow an administrative user to cause arbitrary memory corruption by rekeying the current client interactive session.
Published 2019-08-23 · Modified
7.2EPSS 0.010
CVE-2025-4615
PAN-OS: Improper Neutralization of Input in the Management Web Interface
Published 2025-10-09 · Modified
7.2EPSS 0.008
CVE-2026-0283
PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)
Published 2026-07-09 · Modified
7.2EPSS 0.004
CVE-2026-0280
PAN-OS: IPv6 Firewall Policy Bypass
Published 2026-07-09 · Modified
7.2EPSS 0.003
CVE-2026-0272
PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI)
Published 2026-06-10 · Modified
7.2EPSS 0.003
CVE-2025-0111
PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface
Published 2025-02-12 · Analyzed
7.1KEVEPSS 0.020
CVE-2020-2005
PAN-OS: GlobalProtect Clientless VPN session hijacking
Published 2020-05-13 · Modified
7.1EPSS 0.008
CVE-2024-8687
PAN-OS: Cleartext Exposure of GlobalProtect Portal Passcodes
Published 2024-09-11 · Analyzed
7.1EPSS 0.004
CVE-2024-8691
PAN-OS: User Impersonation in GlobalProtect Portal
Published 2024-09-11 · Analyzed
7.1EPSS 0.003
CVE-2026-0281
PAN-OS: Information Disclosure Vulnerability in Management Web Interface
Published 2026-07-09 · Modified
7.1EPSS 0.003
CVE-2024-5911
PAN-OS: File Upload Vulnerability in the Panorama Web Interface
Published 2024-07-10 · Analyzed
7.0EPSS 0.006
CVE-2020-1995
PAN-OS: Management server rasmgr denial of service
Published 2020-05-13 · Modified
6.8EPSS 0.011
CVE-2020-2031
PAN-OS: Integer underflow in the management interface
Published 2020-07-08 · Modified
6.8EPSS 0.011
CVE-2021-3046
PAN-OS: Improper SAML Authentication Vulnerability in GlobalProtect Portal
Published 2021-08-11 · Modified
6.8EPSS 0.011
CVE-2024-2552
PAN-OS: Arbitrary File Delete Vulnerability in the Command Line Interface (CLI)
Published 2024-11-14 · Analyzed
6.8EPSS 0.005
CVE-2024-0007
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Panorama Web Interface
Published 2024-02-14 · Analyzed
6.8EPSS 0.004
CVE-2024-5913
PAN-OS: Improper Input Validation Vulnerability in PAN-OS
Published 2024-07-10 · Analyzed
6.8EPSS 0.002
CVE-2024-8688
PAN-OS: Arbitrary File Read Vulnerability in the Command Line Interface (CLI)
Published 2024-09-11 · Analyzed
6.7EPSS 0.002
CVE-2018-9242
The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier may allow an attacker to delete files in the system via specific request parameters.
Published 2018-07-03 · Modified
6.6EPSS 0.004
CVE-2018-18065
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
Published 2018-10-08 · Modified
6.51 PoCEPSS 0.175
CVE-2016-9149
The Addresses Object parser in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 mishandles single quote characters, which allows remote authenticated users to conduct XPath injection attacks via a crafted string.
Published 2016-11-19 · Modified
6.5EPSS 0.020
CVE-2017-5583
The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated users to read arbitrary files via unspecified vectors.
Published 2017-03-15 · Modified
6.5EPSS 0.015
CVE-2017-7216
The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to obtain sensitive information via unspecified request parameters.
Published 2017-05-02 · Modified
6.5EPSS 0.012
CVE-2023-0004
PAN-OS: Local File Deletion Vulnerability
Published 2023-04-12 · Modified
6.5EPSS 0.011
CVE-2017-7644
The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1.x before 7.1.9 allows remote authenticated users to obtain sensitive information by leveraging incorrect permission validation, aka PAN-SA-2017-0013 and PAN-70541.
Published 2017-04-29 · Modified
6.5EPSS 0.010
CVE-2022-0011
PAN-OS: URL Category Exceptions Match More URLs Than Intended in URL Filtering
Published 2022-02-10 · Modified
6.5EPSS 0.007
CVE-2023-0007
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Panorama Web Interface
Published 2023-05-10 · Modified
6.5EPSS 0.004
CVE-2024-5919
PAN-OS: Authenticated XML External Entities (XXE) Injection Vulnerability
Published 2024-11-14 · Analyzed
6.5EPSS 0.003
CVE-2026-0282
PAN-OS: File Deletion Vulnerability in Management Web Interface
Published 2026-07-09 · Modified
6.5EPSS 0.003
CVE-2012-6597
Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to cause a denial of service (management-server crash) by using the command-line interface for a crafted command, aka Ref ID 35254.
Published 2013-08-31 · Modified
6.3EPSS 0.013
CVE-2023-6792
PAN-OS: OS Command Injection Vulnerability in the XML API
Published 2023-12-13 · Modified
6.3EPSS 0.011
CVE-2024-0009
PAN-OS: Improper IP Address Verification in GlobalProtect Gateway
Published 2024-02-14 · Analyzed
6.3EPSS 0.002
← Prev4 / 6Next →