VYPR

Vendor CVEs

Paloaltonetworks

All CVEs

442 total · sorted by risk
  • CVE-2020-2048LowNov 12, 2020
    risk 0.21cvss 3.3epss 0.00

    An information exposure through log file vulnerability exists where the password for the configured system proxy server for a PAN-OS appliance may be displayed in cleartext when using the CLI in Palo Alto Networks PAN-OS software. This issue impacts: PAN-OS 8.1 versions earlier…

  • CVE-2020-2035LowAug 12, 2020
    risk 0.20cvss 3.0epss 0.01

    When SSL/TLS Forward Proxy Decryption mode has been configured to decrypt the web transactions, the PAN-OS URL filtering feature inspects the HTTP Host and URL path headers for policy enforcement on the decrypted HTTPS web transactions but does not consider Server Name…

  • CVE-2025-4614LowOct 9, 2025
    risk 0.18cvss 2.7epss 0.00

    An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked.   The security…

  • CVE-2023-6793LowDec 13, 2023
    risk 0.18cvss 2.7epss 0.01

    An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage.

  • CVE-2021-3049LowSep 8, 2021
    risk 0.17cvss 2.6epss 0.00

    An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-based attacker with investigation read permissions to download files from incident investigations of which they are aware but are not a part of. This issue…

  • CVE-2026-0303LowSep 10, 2026
    risk 0.16cvss —epss 0.00

    A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.

  • CVE-2025-4234LowSep 12, 2025
    risk 0.16cvss —epss 0.00

    A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This…

  • CVE-2019-1573LowApr 9, 2019
    risk 0.16cvss 2.5epss 0.00

    GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication and/or session tokens and replay them…

  • CVE-2021-3037LowApr 20, 2021
    risk 0.15cvss 2.3epss 0.00

    An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where the connection details for a scheduled configuration export are logged in system logs. Logged information includes the cleartext username, password, and IP address used to…

  • CVE-2025-0138LowMay 14, 2025
    risk 0.13cvss —epss 0.00

    Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access. Compute in Prisma Cloud Enterprise Edition is not affected by this issue.

  • CVE-2026-0228LowFeb 11, 2026
    risk 0.08cvss —epss 0.00

    An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.

  • CVE-2026-0302LowSep 10, 2026
    risk 0.07cvss —epss 0.01

    An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.

  • CVE-2026-0308LowSep 10, 2026
    risk 0.07cvss —epss 0.00

    A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series…

  • CVE-2026-0266LowJun 10, 2026
    risk 0.07cvss —epss 0.00

    A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on…

  • CVE-2025-4617LowNov 14, 2025
    risk 0.07cvss —epss 0.00

    An insufficient policy enforcement vulnerability in Palo Alto Networks Prisma® Browser on Windows allows a locally authenticated non-admin user to bypass the screenshot control feature of the browser. Browser self-protection should be enabled to mitigate this issue.

  • CVE-2025-4616LowNov 14, 2025
    risk 0.07cvss —epss 0.00

    An insufficient validation of an untrusted input vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to revert the browser’s security controls.

  • CVE-2015-2223Apr 14, 2015
    risk 0.03cvss —epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in the web-based console management interface in Palo Alto Networks Traps (formerly Cyvera Endpoint Protection) 3.1.2.1546 allow remote attackers to inject arbitrary web script or HTML via the (1) Arguments, (2) FileName, or…

  • CVE-2010-0475May 14, 2010
    risk 0.03cvss —epss 0.04

    Cross-site scripting (XSS) vulnerability in esp/editUser.esp in the Palo Alto Networks firewall 3.0.x before 3.0.9 and 3.1.x before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the role parameter.

  • CVE-2003-1544Dec 31, 2003
    risk 0.01cvss —epss 0.17

    Unrestricted critical resource lock in Terminal Services for Windows 2000 before SP4 and Windows XP allows remote authenticated users to cause a denial of service (reboot) by obtaining a read lock on msgina.dll, which prevents msgina.dll from being loaded.

  • CVE-2026-0275MedJul 9, 2026
    risk 0.00cvss 6.7epss 0.00

    A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macOS local filesystem to perform actions on the device with root privileges. This issue only affects Prisma® Browser on macOS.

  • CVE-2015-4162Jun 2, 2015
    risk 0.00cvss —epss 0.01

    XML external entity (XXE) vulnerability in the management interface in PAN-OS before 5.0.16, 6.x before 6.0.8, and 6.1.x before 6.1.4 allows remote authenticated administrators to obtain sensitive information via crafted XML data.

  • CVE-2014-3764Jan 6, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the web-based device management interface in Palo Alto Networks PAN-OS before 5.0.15, 5.1.x before 5.1.10, and 6.0.x before 6.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Ref ID 64563.

  • CVE-2013-5664Aug 31, 2013
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the web-based device-management API browser in Palo Alto Networks PAN-OS before 4.1.13 and 5.0.x before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via crafted data, aka Ref ID 50908.

  • CVE-2013-5663Aug 31, 2013
    risk 0.00cvss —epss 0.03

    The App-ID cache feature in Palo Alto Networks PAN-OS before 4.0.14, 4.1.x before 4.1.11, and 5.0.x before 5.0.2 allows remote attackers to bypass intended security policies via crafted requests that trigger invalid caching, as demonstrated by incorrect identification of HTTP…

  • CVE-2012-6606Aug 31, 2013
    risk 0.00cvss —epss 0.01

    Palo Alto Networks GlobalProtect before 1.1.7, and NetConnect, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof portal servers and obtain sensitive information via a crafted certificate.

  • CVE-2012-6605Aug 31, 2013
    risk 0.00cvss —epss 0.03

    The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka Ref ID 34896.

  • CVE-2012-6604Aug 31, 2013
    risk 0.00cvss —epss 0.03

    The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka Ref ID 35249.

  • CVE-2012-6603Aug 31, 2013
    risk 0.00cvss —epss 0.04

    The web management UI in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to bypass authentication and obtain administrator privileges via unspecified vectors, aka Ref ID 37034.

  • CVE-2012-6602Aug 31, 2013
    risk 0.00cvss —epss 0.03

    The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 30122.

  • CVE-2012-6601Aug 31, 2013
    risk 0.00cvss —epss 0.04

    The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to execute arbitrary code via unspecified vectors, aka Ref ID 36983.

  • CVE-2012-6600Aug 31, 2013
    risk 0.00cvss —epss 0.03

    The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 34502.

  • CVE-2012-6599Aug 31, 2013
    risk 0.00cvss —epss 0.03

    The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 and 4.1.x before 4.1.1 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 33476.

  • CVE-2012-6598Aug 31, 2013
    risk 0.00cvss —epss 0.03

    The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 33080.

  • CVE-2012-6597Aug 31, 2013
    risk 0.00cvss —epss 0.01

    Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to cause a denial of service (management-server crash) by using the command-line interface for a crafted command, aka Ref ID 35254.

  • CVE-2012-6596Aug 31, 2013
    risk 0.00cvss —epss 0.01

    Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.3 stores cleartext LDAP bind passwords in authd.log, which allows context-dependent attackers to obtain sensitive information by reading this file, aka Ref ID 35493.

  • CVE-2012-6595Aug 31, 2013
    risk 0.00cvss —epss 0.03

    The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 34595.

  • CVE-2012-6594Aug 31, 2013
    risk 0.00cvss —epss 0.03

    The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11, 4.0.x before 4.0.8, and 4.1.x before 4.1.1 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 34299.

  • CVE-2012-6593Aug 31, 2013
    risk 0.00cvss —epss 0.04

    Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref ID 30088.

  • CVE-2012-6592Aug 31, 2013
    risk 0.00cvss —epss 0.04

    Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref ID 31091.

  • CVE-2012-6591Aug 31, 2013
    risk 0.00cvss —epss 0.03

    The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 31116.

  • CVE-2012-6590Aug 31, 2013
    risk 0.00cvss —epss 0.02

    The web-based management UI in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 allows remote attackers to obtain verbose error information via crafted input, aka Ref ID 33139.

  • CVE-2012-4043Jul 26, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in global-protect/login.esp in Palo Alto Networks Global Protect Portal, Global Protect Gateway, and SSL VPN portals 3.1.x through 3.1.11 and 4.0.x through 4.0.5 allows remote attackers to inject arbitrary web script or HTML via the…

Page 9 of 9