VendorsPalo Alto Networkspan-osany version
Vulnerabilities

Palo Alto Networks paloaltonetworks pan-os any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

219CVEs
CVE-2026-0266
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
Published 2026-06-10 · Modified
4.8EPSS 0.001
CVE-2022-0022
PAN-OS: Use of a Weak Cryptographic Algorithm for Stored Password Hashes
Published 2022-03-09 · Modified
4.6EPSS 0.001
CVE-2023-0008
PAN-OS: Local File Disclosure Vulnerability in the PAN-OS Web Interface
Published 2023-05-10 · Modified
4.4EPSS 0.005
CVE-2021-3036
PAN-OS: Administrator secrets are logged in web server logs when using the PAN-OS XML API incorrectly
Published 2021-04-20 · Modified
4.4EPSS 0.002
CVE-2021-3032
PAN-OS: Configuration secrets for log forwarding may be logged in system logs
Published 2021-01-13 · Modified
4.4EPSS 0.002
CVE-2013-5663
The App-ID cache feature in Palo Alto Networks PAN-OS before 4.0.14, 4.1.x before 4.1.11, and 5.0.x before 5.0.2 allows remote attackers to bypass intended security policies via crafted requests that trigger invalid caching, as demonstrated by incorrect identification of HTTP traffic as SIP traffic, aka Ref ID 47195.
Published 2013-08-31 · Modified
4.3EPSS 0.028
CVE-2018-10140
The PAN-OS Management Web Interface in Palo Alto Networks PAN-OS 8.1.2 and earlier may allow an authenticated user to shut down all management sessions, resulting in all logged in users to be redirected to the login page. PAN-OS 6.1, PAN-OS 7.1 and PAN-OS 8.0 are NOT affected.
Published 2018-08-16 · Modified
4.3EPSS 0.019
CVE-2014-3764
Cross-site scripting (XSS) vulnerability in the web-based device management interface in Palo Alto Networks PAN-OS before 5.0.15, 5.1.x before 5.1.10, and 6.0.x before 6.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Ref ID 64563.
Published 2015-01-06 · Modified
4.3EPSS 0.014
CVE-2017-7217
The Management Web Interface in Palo Alto Networks PAN-OS before 7.0.14 and 7.1.x before 7.1.9 allows remote attackers to write to export files via unspecified parameters.
Published 2017-04-14 · Modified
4.3EPSS 0.011
CVE-2024-2433
PAN-OS: Improper Privilege Management Vulnerability in Panorama Software Leads to Availability Loss
Published 2024-03-13 · Analyzed
4.3EPSS 0.006
CVE-2021-3031
PAN-OS: Information exposure in Ethernet data frame construction (Etherleak)
Published 2021-01-13 · Modified
4.3EPSS 0.005
CVE-2021-3047
PAN-OS: Weak Cryptography Used in Web Interface Authentication
Published 2021-08-11 · Modified
4.2EPSS 0.005
CVE-2015-4162
XML external entity (XXE) vulnerability in the management interface in PAN-OS before 5.0.16, 6.x before 6.0.8, and 6.1.x before 6.1.4 allows remote authenticated administrators to obtain sensitive information via crafted XML data.
Published 2015-06-02 · Modified
4.0EPSS 0.010
CVE-2020-2043
PAN-OS: Passwords may be logged in clear text when using after-change-detail custom syslog field for config logs
Published 2020-09-09 · Modified
4.0EPSS 0.007
CVE-2020-2044
PAN-OS: Passwords may be logged in clear text while storing operational command (op command) history
Published 2020-09-09 · Modified
4.0EPSS 0.007
CVE-2020-2035
PAN-OS: URL filtering policy is not enforced on TLS handshakes for decrypted HTTPS sessions
Published 2020-08-12 · Modified
3.5EPSS 0.008
CVE-2020-2048
PAN-OS: System proxy passwords may be logged in clear text while viewing system state
Published 2020-11-12 · Modified
3.3EPSS 0.003
CVE-2023-6793
PAN-OS: XML API Keys Revoked by Read-Only PAN-OS Administrator
Published 2023-12-13 · Modified
2.7EPSS 0.006
CVE-2021-3037
PAN-OS: Secrets for scheduled configuration exports are logged in system logs
Published 2021-04-20 · Modified
2.3EPSS 0.003
← Prev6 / 6