VendorsPalo Alto Networkspan-osall versions
Vulnerabilities

Palo Alto Networks paloaltonetworks pan-os

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

235CVEs
CVE-2025-0124
PAN-OS: Authenticated File Deletion Vulnerability on the Management Web Interface
Published 2025-04-11 · Analyzed
5.1EPSS 0.003
CVE-2024-9471
PAN-OS: Privilege Escalation (PE) Vulnerability in XML API
Published 2024-10-09 · Analyzed
5.1EPSS 0.003
CVE-2012-6596
Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.3 stores cleartext LDAP bind passwords in authd.log, which allows context-dependent attackers to obtain sensitive information by reading this file, aka Ref ID 35493.
Published 2013-08-31 · Modified
5.0EPSS 0.013
CVE-2024-3388
PAN-OS: User Impersonation in GlobalProtect SSL VPN
Published 2024-04-10 · Analyzed
5.0EPSS 0.003
CVE-2021-3045
PAN-OS: OS Command Argument Injection in Web Interface
Published 2021-08-11 · Modified
4.9EPSS 0.008
CVE-2023-6791
PAN-OS: Plaintext Disclosure of External System Integration Credentials
Published 2023-12-13 · Modified
4.9EPSS 0.006
CVE-2024-5917
PAN-OS: Server-Side Request Forgery in WildFire
Published 2024-11-14 · Analyzed
4.9EPSS 0.005
CVE-2026-0285
PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface
Published 2026-07-09 · Modified
4.9EPSS 0.004
CVE-2023-0005
PAN-OS: Exposure of Sensitive Information Vulnerability
Published 2023-04-12 · Modified
4.9EPSS 0.003
CVE-2020-1994
PAN-OS: Predictable temporary file vulnerability
Published 2020-05-13 · Modified
4.9EPSS 0.002
CVE-2023-6789
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
Published 2023-12-13 · Modified
4.8EPSS 0.004
CVE-2024-5920
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in PAN-OS Enables Impersonation of a Legitimate Administrator
Published 2024-11-14 · Analyzed
4.8EPSS 0.003
CVE-2025-4614
PAN-OS: Session Token Disclosure Vulnerability
Published 2025-10-09 · Analyzed
4.8EPSS 0.003
CVE-2026-0256
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
Published 2026-05-13 · Analyzed
4.8EPSS 0.002
CVE-2026-0266
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
Published 2026-06-10 · Modified
4.8EPSS 0.001
CVE-2022-0022
PAN-OS: Use of a Weak Cryptographic Algorithm for Stored Password Hashes
Published 2022-03-09 · Modified
4.6EPSS 0.001
CVE-2023-0008
PAN-OS: Local File Disclosure Vulnerability in the PAN-OS Web Interface
Published 2023-05-10 · Modified
4.4EPSS 0.005
CVE-2021-3036
PAN-OS: Administrator secrets are logged in web server logs when using the PAN-OS XML API incorrectly
Published 2021-04-20 · Modified
4.4EPSS 0.002
CVE-2021-3032
PAN-OS: Configuration secrets for log forwarding may be logged in system logs
Published 2021-01-13 · Modified
4.4EPSS 0.002
CVE-2013-5663
The App-ID cache feature in Palo Alto Networks PAN-OS before 4.0.14, 4.1.x before 4.1.11, and 5.0.x before 5.0.2 allows remote attackers to bypass intended security policies via crafted requests that trigger invalid caching, as demonstrated by incorrect identification of HTTP traffic as SIP traffic, aka Ref ID 47195.
Published 2013-08-31 · Modified
4.3EPSS 0.028
CVE-2013-5664
Cross-site scripting (XSS) vulnerability in the web-based device-management API browser in Palo Alto Networks PAN-OS before 4.1.13 and 5.0.x before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via crafted data, aka Ref ID 50908.
Published 2013-08-31 · Modified
4.3EPSS 0.023
CVE-2018-10140
The PAN-OS Management Web Interface in Palo Alto Networks PAN-OS 8.1.2 and earlier may allow an authenticated user to shut down all management sessions, resulting in all logged in users to be redirected to the login page. PAN-OS 6.1, PAN-OS 7.1 and PAN-OS 8.0 are NOT affected.
Published 2018-08-16 · Modified
4.3EPSS 0.019
CVE-2012-6590
The web-based management UI in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 allows remote attackers to obtain verbose error information via crafted input, aka Ref ID 33139.
Published 2013-08-31 · Modified
4.3EPSS 0.016
CVE-2014-3764
Cross-site scripting (XSS) vulnerability in the web-based device management interface in Palo Alto Networks PAN-OS before 5.0.15, 5.1.x before 5.1.10, and 6.0.x before 6.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Ref ID 64563.
Published 2015-01-06 · Modified
4.3EPSS 0.014
CVE-2017-7217
The Management Web Interface in Palo Alto Networks PAN-OS before 7.0.14 and 7.1.x before 7.1.9 allows remote attackers to write to export files via unspecified parameters.
Published 2017-04-14 · Modified
4.3EPSS 0.011
CVE-2024-2433
PAN-OS: Improper Privilege Management Vulnerability in Panorama Software Leads to Availability Loss
Published 2024-03-13 · Analyzed
4.3EPSS 0.006
CVE-2021-3031
PAN-OS: Information exposure in Ethernet data frame construction (Etherleak)
Published 2021-01-13 · Modified
4.3EPSS 0.005
CVE-2021-3047
PAN-OS: Weak Cryptography Used in Web Interface Authentication
Published 2021-08-11 · Modified
4.2EPSS 0.005
CVE-2015-4162
XML external entity (XXE) vulnerability in the management interface in PAN-OS before 5.0.16, 6.x before 6.0.8, and 6.1.x before 6.1.4 allows remote authenticated administrators to obtain sensitive information via crafted XML data.
Published 2015-06-02 · Modified
4.0EPSS 0.010
CVE-2020-2043
PAN-OS: Passwords may be logged in clear text when using after-change-detail custom syslog field for config logs
Published 2020-09-09 · Modified
4.0EPSS 0.007
CVE-2020-2044
PAN-OS: Passwords may be logged in clear text while storing operational command (op command) history
Published 2020-09-09 · Modified
4.0EPSS 0.007
CVE-2020-2035
PAN-OS: URL filtering policy is not enforced on TLS handshakes for decrypted HTTPS sessions
Published 2020-08-12 · Modified
3.5EPSS 0.008
CVE-2020-2048
PAN-OS: System proxy passwords may be logged in clear text while viewing system state
Published 2020-11-12 · Modified
3.3EPSS 0.003
CVE-2023-6793
PAN-OS: XML API Keys Revoked by Read-Only PAN-OS Administrator
Published 2023-12-13 · Modified
2.7EPSS 0.006
CVE-2021-3037
PAN-OS: Secrets for scheduled configuration exports are logged in system logs
Published 2021-04-20 · Modified
2.3EPSS 0.003
← Prev6 / 6