VendorsPalo Alto Networkspan-osall versions
Vulnerabilities

Palo Alto Networks paloaltonetworks pan-os

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

235CVEs
CVE-2018-10141
GlobalProtect Portal Login page in Palo Alto Networks PAN-OS before 8.1.4 allows an unauthenticated attacker to inject arbitrary JavaScript or HTML.
Published 2018-10-12 · Modified
6.1EPSS 0.039
CVE-2018-10139
The PAN-OS response for GlobalProtect Gateway in Palo Alto Networks PAN-OS 6.1.21 and earlier, PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and earlier may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML. PAN-OS 8.1 is NOT affected.
Published 2018-08-16 · Modified
6.1EPSS 0.015
CVE-2017-9459
Cross-site scripting (XSS) vulnerability in the management web interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2017-08-02 · Modified
6.1EPSS 0.012
CVE-2017-9467
Cross-site scripting (XSS) vulnerability in the GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2017-08-02 · Modified
6.1EPSS 0.012
CVE-2017-12416
Cross-site scripting (XSS) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to improper request parameter validation.
Published 2017-09-07 · Modified
6.1EPSS 0.012
CVE-2017-15941
Cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.7, when the GlobalProtect gateway or portal is configured, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2018-01-10 · Modified
6.1EPSS 0.012
CVE-2019-1566
The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML.
Published 2019-01-30 · Modified
6.1EPSS 0.012
CVE-2017-16878
Cross-site scripting (XSS) vulnerability in the Captive Portal function in Palo Alto Networks PAN-OS before 8.0.7 allows remote attackers to inject arbitrary web script or HTML by leveraging an unspecified configuration.
Published 2018-01-10 · Modified
6.1EPSS 0.011
CVE-2018-7636
The URL filtering "continue page" hosted by PAN-OS 8.0.10 and earlier may allow an attacker to inject arbitrary JavaScript or HTML via specially crafted URLs.
Published 2018-07-03 · Modified
6.1EPSS 0.011
CVE-2017-7409
Palo Alto Networks PAN-OS before 7.0.15 has XSS in the GlobalProtect external interface via crafted request parameters, aka PAN-SA-2017-0011 and PAN-70674.
Published 2017-04-21 · Modified
6.1EPSS 0.010
CVE-2020-1997
PAN-OS: GlobalProtect registration open redirect
Published 2020-05-13 · Modified
6.1EPSS 0.009
CVE-2026-0279
PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities
Published 2026-07-09 · Modified
6.1EPSS 0.008
CVE-2024-0010
PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Portal
Published 2024-02-14 · Analyzed
6.1EPSS 0.005
CVE-2024-0011
PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in Captive Portal Authentication
Published 2024-02-14 · Analyzed
6.1EPSS 0.004
CVE-2024-5916
PAN-OS: Cleartext Exposure of External System Secrets
Published 2024-08-14 · Analyzed
6.0EPSS 0.002
CVE-2019-1559
0-byte record padding oracle
Published 2019-02-27 · Modified
5.9EPSS 0.171
CVE-2017-17841
Palo Alto Networks PAN-OS 6.1, 7.1, and 8.0.x before 8.0.7, when an interface implements SSL decryption with RSA enabled or hosts a GlobalProtect portal or gateway, might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
Published 2018-01-10 · Modified
5.9EPSS 0.024
CVE-2021-3048
PAN-OS: Invalid URLs in an External Dynamic List (EDL) can Lead to Firewall Outage
Published 2021-08-11 · Modified
5.9EPSS 0.008
CVE-2022-0023
PAN-OS: Denial-of-Service (DoS) Vulnerability in DNS Proxy
Published 2022-04-13 · Modified
5.9EPSS 0.007
CVE-2024-3387
PAN-OS: Weak Certificate Strength in Panorama Software Leads to Sensitive Information Disclosure
Published 2024-04-10 · Analyzed
5.9EPSS 0.002
CVE-2020-1982
PAN-OS: TLS 1.0 usage for certain communications with Palo Alto Networks cloud delivered services
Published 2020-07-08 · Modified
5.8EPSS 0.005
CVE-2020-1978
VM-Series on Microsoft Azure: Inadvertent collection of credentials in Tech support files on HA configured VMs
Published 2020-04-08 · Modified
5.8EPSS 0.003
CVE-2026-0269
PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing
Published 2026-06-10 · Modified
5.7EPSS 0.002
CVE-2023-6795
PAN-OS: OS Command Injection Vulnerability in the Web Interface
Published 2023-12-13 · Modified
5.5EPSS 0.011
CVE-2023-6794
PAN-OS: File Upload Vulnerability in the Web Interface
Published 2023-12-13 · Modified
5.5EPSS 0.006
CVE-2023-38046
PAN-OS: Read System Files and Resources During Configuration Commit
Published 2023-07-12 · Modified
5.5EPSS 0.005
CVE-2020-1993
PAN-OS: GlobalProtect Portal PHP session fixation vulnerability
Published 2020-05-13 · Modified
5.5EPSS 0.004
CVE-2018-9334
The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.8 and earlier, and PAN-OS 8.1.0 may allow an attacker to access the GlobalProtect password hashes of local users via manipulation of the HTML markup.
Published 2018-07-03 · Modified
5.5EPSS 0.004
CVE-2018-9335
The PAN-OS session browser in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier, and PAN-OS 8.1.1 and earlier may allow an attacker to inject arbitrary JavaScript or HTML.
Published 2018-07-03 · Modified
5.4EPSS 0.010
CVE-2018-9337
The PAN-OS web interface administration page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.17 and earlier, PAN-OS 8.0.10 and earlier, and PAN-OS 8.1.1 and earlier may allow an attacker to inject arbitrary JavaScript or HTML.
Published 2018-07-03 · Modified
5.4EPSS 0.010
CVE-2017-5584
Cross-site scripting (XSS) vulnerability in the Management Web Interface in Palo Alto Networks PAN-OS 5.1, 6.x before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Published 2017-03-15 · Modified
5.4EPSS 0.008
CVE-2016-2219
Cross-site scripting (XSS) vulnerability in the management interface in Palo Alto Networks PAN-OS 7.x before 7.0.8 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Published 2016-07-12 · Modified
5.4EPSS 0.008
CVE-2019-1565
The PAN-OS external dynamics lists in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an attacker that is authenticated in Next Generation Firewall with write privileges to External Dynamic List configuration to inject arbitrary JavaScript or HTML.
Published 2019-01-30 · Modified
5.4EPSS 0.007
CVE-2023-0010
PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in Captive Portal Authentication
Published 2023-06-14 · Modified
5.4EPSS 0.004
CVE-2020-2039
PAN-OS: Management web interface denial-of-service (DoS) through unauthenticated file upload
Published 2020-09-09 · Modified
5.3EPSS 0.464
CVE-2017-15943
The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, and 7.1.x before 7.1.14 allows remote attackers to conduct server-side request forgery (SSRF) attacks and consequently obtain sensitive information via vectors related to parsing of external entities.
Published 2017-12-11 · Modified
5.3EPSS 0.017
CVE-2020-1999
PAN-OS: Threat signatures are evaded by specifically crafted packets
Published 2020-11-12 · Modified
5.3EPSS 0.013
CVE-2020-1996
PAN-OS: Panorama management server log injection
Published 2020-05-13 · Modified
5.3EPSS 0.009
CVE-2024-3386
PAN-OS: Predefined Decryption Exclusions Does Not Work as Intended
Published 2024-04-10 · Analyzed
5.3EPSS 0.004
CVE-2024-5918
PAN-OS: Improper Certificate Validation Enables Impersonation of a Legitimate GlobalProtect User
Published 2024-11-14 · Analyzed
5.3EPSS 0.002
← Prev5 / 6Next →