VendorsPalo Alto Networkspan-osany version
Vulnerabilities

Palo Alto Networks paloaltonetworks pan-os any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

219CVEs
CVE-2019-1582
Memory corruption in PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow an administrative user to cause arbitrary memory corruption by rekeying the current client interactive session.
Published 2019-08-23 · Modified
7.2EPSS 0.010
CVE-2025-4615
PAN-OS: Improper Neutralization of Input in the Management Web Interface
Published 2025-10-09 · Modified
7.2EPSS 0.008
CVE-2026-0283
PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)
Published 2026-07-09 · Modified
7.2EPSS 0.004
CVE-2026-0280
PAN-OS: IPv6 Firewall Policy Bypass
Published 2026-07-09 · Modified
7.2EPSS 0.003
CVE-2026-0272
PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI)
Published 2026-06-10 · Modified
7.2EPSS 0.003
CVE-2025-0111
PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface
Published 2025-02-12 · Analyzed
7.1KEVEPSS 0.020
CVE-2020-2005
PAN-OS: GlobalProtect Clientless VPN session hijacking
Published 2020-05-13 · Modified
7.1EPSS 0.008
CVE-2024-8687
PAN-OS: Cleartext Exposure of GlobalProtect Portal Passcodes
Published 2024-09-11 · Analyzed
7.1EPSS 0.004
CVE-2024-8691
PAN-OS: User Impersonation in GlobalProtect Portal
Published 2024-09-11 · Analyzed
7.1EPSS 0.003
CVE-2026-0281
PAN-OS: Information Disclosure Vulnerability in Management Web Interface
Published 2026-07-09 · Modified
7.1EPSS 0.003
CVE-2024-5911
PAN-OS: File Upload Vulnerability in the Panorama Web Interface
Published 2024-07-10 · Analyzed
7.0EPSS 0.006
CVE-2020-1995
PAN-OS: Management server rasmgr denial of service
Published 2020-05-13 · Modified
6.8EPSS 0.011
CVE-2020-2031
PAN-OS: Integer underflow in the management interface
Published 2020-07-08 · Modified
6.8EPSS 0.011
CVE-2021-3046
PAN-OS: Improper SAML Authentication Vulnerability in GlobalProtect Portal
Published 2021-08-11 · Modified
6.8EPSS 0.011
CVE-2024-2552
PAN-OS: Arbitrary File Delete Vulnerability in the Command Line Interface (CLI)
Published 2024-11-14 · Analyzed
6.8EPSS 0.005
CVE-2024-0007
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Panorama Web Interface
Published 2024-02-14 · Analyzed
6.8EPSS 0.004
CVE-2024-5913
PAN-OS: Improper Input Validation Vulnerability in PAN-OS
Published 2024-07-10 · Analyzed
6.8EPSS 0.002
CVE-2024-8688
PAN-OS: Arbitrary File Read Vulnerability in the Command Line Interface (CLI)
Published 2024-09-11 · Analyzed
6.7EPSS 0.002
CVE-2018-9242
The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier may allow an attacker to delete files in the system via specific request parameters.
Published 2018-07-03 · Modified
6.6EPSS 0.004
CVE-2018-18065
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
Published 2018-10-08 · Modified
6.51 PoCEPSS 0.175
CVE-2016-9149
The Addresses Object parser in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 mishandles single quote characters, which allows remote authenticated users to conduct XPath injection attacks via a crafted string.
Published 2016-11-19 · Modified
6.5EPSS 0.020
CVE-2017-5583
The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated users to read arbitrary files via unspecified vectors.
Published 2017-03-15 · Modified
6.5EPSS 0.015
CVE-2017-7216
The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to obtain sensitive information via unspecified request parameters.
Published 2017-05-02 · Modified
6.5EPSS 0.012
CVE-2023-0004
PAN-OS: Local File Deletion Vulnerability
Published 2023-04-12 · Modified
6.5EPSS 0.011
CVE-2017-7644
The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1.x before 7.1.9 allows remote authenticated users to obtain sensitive information by leveraging incorrect permission validation, aka PAN-SA-2017-0013 and PAN-70541.
Published 2017-04-29 · Modified
6.5EPSS 0.010
CVE-2022-0011
PAN-OS: URL Category Exceptions Match More URLs Than Intended in URL Filtering
Published 2022-02-10 · Modified
6.5EPSS 0.007
CVE-2023-0007
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Panorama Web Interface
Published 2023-05-10 · Modified
6.5EPSS 0.004
CVE-2024-5919
PAN-OS: Authenticated XML External Entities (XXE) Injection Vulnerability
Published 2024-11-14 · Analyzed
6.5EPSS 0.003
CVE-2026-0282
PAN-OS: File Deletion Vulnerability in Management Web Interface
Published 2026-07-09 · Modified
6.5EPSS 0.003
CVE-2012-6597
Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to cause a denial of service (management-server crash) by using the command-line interface for a crafted command, aka Ref ID 35254.
Published 2013-08-31 · Modified
6.3EPSS 0.013
CVE-2023-6792
PAN-OS: OS Command Injection Vulnerability in the XML API
Published 2023-12-13 · Modified
6.3EPSS 0.011
CVE-2024-0009
PAN-OS: Improper IP Address Verification in GlobalProtect Gateway
Published 2024-02-14 · Analyzed
6.3EPSS 0.002
CVE-2018-10141
GlobalProtect Portal Login page in Palo Alto Networks PAN-OS before 8.1.4 allows an unauthenticated attacker to inject arbitrary JavaScript or HTML.
Published 2018-10-12 · Modified
6.1EPSS 0.039
CVE-2018-10139
The PAN-OS response for GlobalProtect Gateway in Palo Alto Networks PAN-OS 6.1.21 and earlier, PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and earlier may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML. PAN-OS 8.1 is NOT affected.
Published 2018-08-16 · Modified
6.1EPSS 0.015
CVE-2017-9459
Cross-site scripting (XSS) vulnerability in the management web interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2017-08-02 · Modified
6.1EPSS 0.012
CVE-2017-9467
Cross-site scripting (XSS) vulnerability in the GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2017-08-02 · Modified
6.1EPSS 0.012
CVE-2017-12416
Cross-site scripting (XSS) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to improper request parameter validation.
Published 2017-09-07 · Modified
6.1EPSS 0.012
CVE-2017-15941
Cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.7, when the GlobalProtect gateway or portal is configured, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2018-01-10 · Modified
6.1EPSS 0.012
CVE-2019-1566
The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML.
Published 2019-01-30 · Modified
6.1EPSS 0.012
CVE-2017-16878
Cross-site scripting (XSS) vulnerability in the Captive Portal function in Palo Alto Networks PAN-OS before 8.0.7 allows remote attackers to inject arbitrary web script or HTML by leveraging an unspecified configuration.
Published 2018-01-10 · Modified
6.1EPSS 0.011
← Prev4 / 6Next →