VYPR

Vendor CVEs

Paloaltonetworks

All CVEs

433 total · sorted by risk
  • CVE-2026-0241HigMay 13, 2026
    risk 0.47cvss 7.2epss 0.00

    Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources.

  • CVE-2025-4615HigOct 9, 2025
    risk 0.47cvss 7.2epss 0.01

    An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issue is significantly…

  • CVE-2025-4235HigSep 12, 2025
    risk 0.47cvss epss 0.00

    An information exposure vulnerability in the Palo Alto Networks User-ID Credential Agent (Windows-based) can expose the service account password under specific non-default configurations. This allows an unprivileged Domain User to escalate privileges by exploiting the…

  • CVE-2025-4231HigJun 13, 2025
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user. The attacker must have network access to the management web interface and successfully authenticate to exploit this issue. Cloud…

  • CVE-2024-8686HigSep 11, 2024
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall.

  • CVE-2022-0024HigMay 11, 2022
    risk 0.47cvss 7.2epss 0.02

    A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated network-based PAN-OS administrator to upload a specifically created configuration that disrupts system processes and potentially execute arbitrary code with root privileges when the…

  • CVE-2022-0020MedFeb 10, 2022
    risk 0.47cvss 6.8epss 0.02

    A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on behalf of…

  • CVE-2021-3054HigSep 8, 2021
    risk 0.47cvss 7.2epss 0.01

    A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges. This issue impacts: PAN-OS 8.1…

  • CVE-2020-2000HigNov 12, 2020
    risk 0.47cvss 7.2epss 0.03

    An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrupt system processes and potentially execute arbitrary code and OS commands with root privileges. This issue impacts: PAN-OS 8.1…

  • CVE-2020-2042HigSep 9, 2020
    risk 0.47cvss 7.2epss 0.02

    A buffer overflow vulnerability in the PAN-OS management web interface allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges. This issue impacts only PAN-OS 10.0 versions earlier than PAN-OS 10.0.1.

  • CVE-2020-2037HigSep 9, 2020
    risk 0.47cvss 7.2epss 0.04

    An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PAN-OS 9.0 versions earlier than PAN-OS…

  • CVE-2020-2030HigJul 8, 2020
    risk 0.47cvss 7.2epss 0.03

    An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; and all versions of PAN-OS 7.1 and PAN-OS…

  • CVE-2020-2029HigJun 10, 2020
    risk 0.47cvss 7.2epss 0.02

    An OS Command Injection vulnerability in the PAN-OS web management interface allows authenticated administrators to execute arbitrary OS commands with root privileges by sending a malicious request to generate new certificates for use in the PAN-OS configuration. This issue…

  • CVE-2020-2028HigJun 10, 2020
    risk 0.47cvss 7.2epss 0.02

    An OS Command Injection vulnerability in PAN-OS management server allows authenticated administrators to execute arbitrary OS commands with root privileges when uploading a new certificate in FIPS-CC mode. This issue affects: All versions of PAN-OS 7.1 and PAN-OS 8.0; PAN-OS 8.1…

  • CVE-2020-2027HigJun 10, 2020
    risk 0.47cvss 7.2epss 0.02

    A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges. This issue affects: All versions of PAN-OS 7.1 and PAN-OS 8.0;…

  • CVE-2020-2010HigMay 13, 2020
    risk 0.47cvss 7.2epss 0.02

    An OS command injection vulnerability in PAN-OS management interface allows an authenticated administrator to execute arbitrary OS commands with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions…

  • CVE-2020-2009HigMay 13, 2020
    risk 0.47cvss 7.2epss 0.02

    An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an authenticated administrator to send a request that results in the creation and write of an arbitrary file on all firewalls managed by the Panorama. In some cases…

  • CVE-2020-2008HigMay 13, 2020
    risk 0.47cvss 7.2epss 0.03

    An OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS allows authenticated administrators to execute code with root privileges or delete arbitrary system files and impact the system's integrity or cause a denial of service condition.…

  • CVE-2020-2007HigMay 13, 2020
    risk 0.47cvss 7.2epss 0.02

    An OS command injection vulnerability in the management server component of PAN-OS allows an authenticated user to potentially execute arbitrary commands with root privileges. This issue affects: All PAN-OS 7.1 versions; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0…

  • CVE-2020-2006HigMay 13, 2020
    risk 0.47cvss 7.2epss 0.02

    A stack-based buffer overflow vulnerability in the management server component of PAN-OS that allows an authenticated user to potentially execute arbitrary code with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14.

  • CVE-2020-1990HigApr 8, 2020
    risk 0.47cvss 7.2epss 0.02

    A stack-based buffer overflow vulnerability in the management server component of PAN-OS allows an authenticated user to upload a corrupted PAN-OS configuration and potentially execute code with root privileges. This issue affects Palo Alto Networks PAN-OS 8.1 versions before…

  • CVE-2019-1582HigAug 23, 2019
    risk 0.47cvss 7.2epss 0.01

    Memory corruption in PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow an administrative user to cause arbitrary memory corruption by rekeying the current client interactive session.

  • CVE-2016-3654HigApr 12, 2016
    risk 0.47cvss 7.2epss 0.03

    The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote authenticated administrators to execute arbitrary OS commands via an SSH command…

  • CVE-2026-0281HigJul 9, 2026
    risk 0.46cvss 7.1epss 0.00

    An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web session tokens. This requires a legitimate user to first click on a malicious link provided by…

  • CVE-2025-0131HigMay 14, 2025
    risk 0.46cvss epss 0.00

    An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT…

  • CVE-2025-0127HigApr 11, 2025
    risk 0.46cvss epss 0.01

    A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. This issue is only applicable to PAN-OS VM-Series. This issue does not affect firewalls that…

  • CVE-2025-0120HigApr 11, 2025
    risk 0.46cvss 7.0epss 0.00

    A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution requires that the local…

  • CVE-2025-0117HigMar 12, 2025
    risk 0.46cvss epss 0.00

    A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. GlobalProtect App on macOS, Linux, iOS, Android,…

  • CVE-2024-8691HigSep 11, 2024
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are…

  • CVE-2024-8687HigSep 11, 2024
    risk 0.46cvss 7.1epss 0.00

    An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end…

  • CVE-2024-5907HigJun 12, 2024
    risk 0.46cvss 7.0epss 0.00

    A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this…

  • CVE-2022-0017HigFeb 10, 2022
    risk 0.46cvss 7.0epss 0.00

    An improper link resolution before file access ('link following') vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that enables a local attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges under certain…

  • CVE-2020-2032HigJun 10, 2020
    risk 0.46cvss 7.0epss 0.00

    A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to execute programs with SYSTEM privileges. This issue can be exploited only while performing a GlobalProtect app upgrade. This issue affects: GlobalProtect app 5.0…

  • CVE-2020-2016HigMay 13, 2020
    risk 0.46cvss 7.0epss 0.01

    A race condition due to insecure creation of a file in a temporary directory vulnerability in PAN-OS allows for root privilege escalation from a limited linux user account. This allows an attacker who has escaped the restricted shell as a low privilege administrator, possibly by…

  • CVE-2020-2005HigMay 13, 2020
    risk 0.46cvss 7.1epss 0.01

    A cross-site scripting (XSS) vulnerability exists when visiting malicious websites with the Palo Alto Networks GlobalProtect Clientless VPN that can compromise the user's active session. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 versions earlier…

  • CVE-2020-1989HigApr 8, 2020
    risk 0.46cvss 7.0epss 0.00

    An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global Protect Agent for Linux on ARM platform allows a local authenticated user to gain root privileges on the system. This issue affects Palo Alto Networks Global…

  • CVE-2020-1981HigMar 11, 2020
    risk 0.46cvss 7.0epss 0.00

    A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation. This issue allows a local attacker who bypassed the restricted shell to execute commands as a low privileged user and gain root access on the PAN-OS hardware or virtual appliance. This…

  • CVE-2019-17436HigOct 16, 2019
    risk 0.46cvss 7.1epss 0.00

    A Local Privilege Escalation vulnerability exists in GlobalProtect Agent for Linux and Mac OS X version 5.0.4 and earlier and version 4.1.12 and earlier, that can allow non-root users to overwrite root files on the file system.

  • CVE-2025-0132MedMay 14, 2025
    risk 0.45cvss epss 0.00

    A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM.  The attacker must have network access to the Broker VM to exploit this issue.

  • CVE-2025-0125MedApr 11, 2025
    risk 0.45cvss epss 0.00

    An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. The attacker must have…

  • CVE-2025-0109MedFeb 12, 2025
    risk 0.45cvss epss 0.01

    An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unauthenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and…

  • CVE-2025-2179MedJul 29, 2025
    risk 0.44cvss epss 0.00

    An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on Linux devices enables a locally authenticated non administrative user to disable the app even if the GlobalProtect app configuration would not normally permit them to do so. The…

  • CVE-2025-0140MedJul 9, 2025
    risk 0.44cvss epss 0.00

    An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app even if the GlobalProtect app configuration would not normally permit them to do so. The…

  • CVE-2025-0121MedApr 11, 2025
    risk 0.44cvss epss 0.00

    A null pointer dereference vulnerability in the Palo Alto Networks Cortex® XDR agent on Windows devices allows a low-privileged local Windows user to crash the agent. Additionally, malware can use this vulnerability to perform malicious activity without Cortex XDR being able to…

  • CVE-2025-0116MedMar 12, 2025
    risk 0.44cvss epss 0.00

    A Denial of Service (DoS) vulnerability in Palo Alto Networks PAN-OS software causes the firewall to unexpectedly reboot when processing a specially crafted LLDP frame sent by an unauthenticated adjacent attacker. Repeated attempts to initiate this condition causes the firewall…

  • CVE-2025-0115MedMar 12, 2025
    risk 0.44cvss epss 0.00

    A vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated admin on the PAN-OS CLI to read arbitrary files. The attacker must have network access to the management interface (web, SSH, console, or telnet) and successfully authenticate to exploit this…

  • CVE-2025-0112MedFeb 20, 2025
    risk 0.44cvss epss 0.00

    A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This vulnerability can also be leveraged by malware to disable the Cortex XDR agent and then perform…

  • CVE-2024-5912MedJul 10, 2024
    risk 0.44cvss epss 0.00

    An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking capabilities and run untrusted executables on the device. This issue can be leveraged to execute untrusted software without being…

  • CVE-2024-0007MedFeb 14, 2024
    risk 0.44cvss 6.8epss 0.00

    A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation of another authenticated…

  • CVE-2022-0031MedNov 9, 2022
    risk 0.44cvss 6.7epss 0.00

    A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges.

Page 4 of 9