VendorsPalo Alto Networkspan-osany version
Vulnerabilities

Palo Alto Networks paloaltonetworks pan-os any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

219CVEs
CVE-2017-7409
Palo Alto Networks PAN-OS before 7.0.15 has XSS in the GlobalProtect external interface via crafted request parameters, aka PAN-SA-2017-0011 and PAN-70674.
Published 2017-04-21 · Modified
6.1EPSS 0.010
CVE-2020-1997
PAN-OS: GlobalProtect registration open redirect
Published 2020-05-13 · Modified
6.1EPSS 0.009
CVE-2026-0279
PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities
Published 2026-07-09 · Modified
6.1EPSS 0.008
CVE-2024-0010
PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Portal
Published 2024-02-14 · Analyzed
6.1EPSS 0.005
CVE-2024-0011
PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in Captive Portal Authentication
Published 2024-02-14 · Analyzed
6.1EPSS 0.004
CVE-2024-5916
PAN-OS: Cleartext Exposure of External System Secrets
Published 2024-08-14 · Analyzed
6.0EPSS 0.002
CVE-2019-1559
0-byte record padding oracle
Published 2019-02-27 · Modified
5.9EPSS 0.171
CVE-2021-3048
PAN-OS: Invalid URLs in an External Dynamic List (EDL) can Lead to Firewall Outage
Published 2021-08-11 · Modified
5.9EPSS 0.008
CVE-2022-0023
PAN-OS: Denial-of-Service (DoS) Vulnerability in DNS Proxy
Published 2022-04-13 · Modified
5.9EPSS 0.007
CVE-2024-3387
PAN-OS: Weak Certificate Strength in Panorama Software Leads to Sensitive Information Disclosure
Published 2024-04-10 · Analyzed
5.9EPSS 0.002
CVE-2020-1982
PAN-OS: TLS 1.0 usage for certain communications with Palo Alto Networks cloud delivered services
Published 2020-07-08 · Modified
5.8EPSS 0.005
CVE-2026-0269
PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing
Published 2026-06-10 · Modified
5.7EPSS 0.002
CVE-2023-6795
PAN-OS: OS Command Injection Vulnerability in the Web Interface
Published 2023-12-13 · Modified
5.5EPSS 0.011
CVE-2023-6794
PAN-OS: File Upload Vulnerability in the Web Interface
Published 2023-12-13 · Modified
5.5EPSS 0.006
CVE-2023-38046
PAN-OS: Read System Files and Resources During Configuration Commit
Published 2023-07-12 · Modified
5.5EPSS 0.005
CVE-2020-1993
PAN-OS: GlobalProtect Portal PHP session fixation vulnerability
Published 2020-05-13 · Modified
5.5EPSS 0.004
CVE-2018-9334
The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.8 and earlier, and PAN-OS 8.1.0 may allow an attacker to access the GlobalProtect password hashes of local users via manipulation of the HTML markup.
Published 2018-07-03 · Modified
5.5EPSS 0.004
CVE-2018-9335
The PAN-OS session browser in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier, and PAN-OS 8.1.1 and earlier may allow an attacker to inject arbitrary JavaScript or HTML.
Published 2018-07-03 · Modified
5.4EPSS 0.010
CVE-2018-9337
The PAN-OS web interface administration page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.17 and earlier, PAN-OS 8.0.10 and earlier, and PAN-OS 8.1.1 and earlier may allow an attacker to inject arbitrary JavaScript or HTML.
Published 2018-07-03 · Modified
5.4EPSS 0.010
CVE-2019-1565
The PAN-OS external dynamics lists in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an attacker that is authenticated in Next Generation Firewall with write privileges to External Dynamic List configuration to inject arbitrary JavaScript or HTML.
Published 2019-01-30 · Modified
5.4EPSS 0.007
CVE-2023-0010
PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in Captive Portal Authentication
Published 2023-06-14 · Modified
5.4EPSS 0.004
CVE-2020-2039
PAN-OS: Management web interface denial-of-service (DoS) through unauthenticated file upload
Published 2020-09-09 · Modified
5.3EPSS 0.464
CVE-2017-15943
The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, and 7.1.x before 7.1.14 allows remote attackers to conduct server-side request forgery (SSRF) attacks and consequently obtain sensitive information via vectors related to parsing of external entities.
Published 2017-12-11 · Modified
5.3EPSS 0.017
CVE-2020-1999
PAN-OS: Threat signatures are evaded by specifically crafted packets
Published 2020-11-12 · Modified
5.3EPSS 0.013
CVE-2020-1996
PAN-OS: Panorama management server log injection
Published 2020-05-13 · Modified
5.3EPSS 0.009
CVE-2024-3386
PAN-OS: Predefined Decryption Exclusions Does Not Work as Intended
Published 2024-04-10 · Analyzed
5.3EPSS 0.004
CVE-2024-5918
PAN-OS: Improper Certificate Validation Enables Impersonation of a Legitimate GlobalProtect User
Published 2024-11-14 · Analyzed
5.3EPSS 0.002
CVE-2025-0124
PAN-OS: Authenticated File Deletion Vulnerability on the Management Web Interface
Published 2025-04-11 · Analyzed
5.1EPSS 0.003
CVE-2024-9471
PAN-OS: Privilege Escalation (PE) Vulnerability in XML API
Published 2024-10-09 · Analyzed
5.1EPSS 0.003
CVE-2024-3388
PAN-OS: User Impersonation in GlobalProtect SSL VPN
Published 2024-04-10 · Analyzed
5.0EPSS 0.003
CVE-2021-3045
PAN-OS: OS Command Argument Injection in Web Interface
Published 2021-08-11 · Modified
4.9EPSS 0.008
CVE-2023-6791
PAN-OS: Plaintext Disclosure of External System Integration Credentials
Published 2023-12-13 · Modified
4.9EPSS 0.006
CVE-2024-5917
PAN-OS: Server-Side Request Forgery in WildFire
Published 2024-11-14 · Analyzed
4.9EPSS 0.005
CVE-2026-0285
PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface
Published 2026-07-09 · Modified
4.9EPSS 0.004
CVE-2023-0005
PAN-OS: Exposure of Sensitive Information Vulnerability
Published 2023-04-12 · Modified
4.9EPSS 0.003
CVE-2020-1994
PAN-OS: Predictable temporary file vulnerability
Published 2020-05-13 · Modified
4.9EPSS 0.002
CVE-2023-6789
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
Published 2023-12-13 · Modified
4.8EPSS 0.004
CVE-2024-5920
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in PAN-OS Enables Impersonation of a Legitimate Administrator
Published 2024-11-14 · Analyzed
4.8EPSS 0.003
CVE-2025-4614
PAN-OS: Session Token Disclosure Vulnerability
Published 2025-10-09 · Analyzed
4.8EPSS 0.003
CVE-2026-0256
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
Published 2026-05-13 · Analyzed
4.8EPSS 0.002
← Prev5 / 6Next →