VYPR
Vendor

Pan

Products
4
CVEs
15
Across products
15
Status
Private

Products

4

Recent CVEs

15
  • CVE-2026-36829CriMay 19, 2026
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem existence check based on a user-controlled cookie value without proper sanitization, allowing…

  • CVE-2024-31601CriApr 26, 2024
    risk 0.64cvss 9.8epss 0.00

    An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v. 20240323 and before allows attackers to execute arbitrary code via the exportpdf.php component.

  • CVE-2026-36828HigMay 19, 2026
    risk 0.57cvss 8.8epss 0.02

    A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component allows authenticated users to execute arbitrary shell commands with root privileges via the action=runcmd parameter.

  • CVE-2020-2015HigMay 13, 2020
    risk 0.57cvss 8.8epss 0.02

    A buffer overflow vulnerability in the PAN-OS management server allows authenticated users to crash system processes or potentially execute arbitrary code with root privileges. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 versions earlier than 8.1.13;…

  • CVE-2024-2014HigMar 21, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in Panabit Panalog 202103080942. This vulnerability affects unknown code of the file /Maintain/sprog_upstatus.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has…

  • CVE-2020-2000HigNov 12, 2020
    risk 0.47cvss 7.2epss 0.03

    An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrupt system processes and potentially execute arbitrary code and OS commands with root privileges. This issue impacts: PAN-OS 8.1…

  • CVE-2020-2030HigJul 8, 2020
    risk 0.47cvss 7.2epss 0.03

    An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; and all versions of PAN-OS 7.1 and PAN-OS…

  • CVE-2020-2027HigJun 10, 2020
    risk 0.47cvss 7.2epss 0.02

    A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges. This issue affects: All versions of PAN-OS 7.1 and PAN-OS 8.0;…

  • CVE-2020-2007HigMay 13, 2020
    risk 0.47cvss 7.2epss 0.02

    An OS command injection vulnerability in the management server component of PAN-OS allows an authenticated user to potentially execute arbitrary commands with root privileges. This issue affects: All PAN-OS 7.1 versions; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0…

  • CVE-2020-2016HigMay 13, 2020
    risk 0.46cvss 7.0epss 0.01

    A race condition due to insecure creation of a file in a temporary directory vulnerability in PAN-OS allows for root privilege escalation from a limited linux user account. This allows an attacker who has escaped the restricted shell as a low privilege administrator, possibly by…

  • CVE-2020-2003MedMay 13, 2020
    risk 0.42cvss 6.5epss 0.01

    An external control of filename vulnerability in the command processing of PAN-OS allows an authenticated administrator to delete arbitrary system files affecting the integrity of the system or causing denial of service to all PAN-OS services. This issue affects: All versions of…

  • CVE-2026-36827MedMay 19, 2026
    risk 0.35cvss 5.4epss 0.01

    A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface invokes the backend helper /usr/sbin/pappiw and passes user-controlled parameters to it. The helper performs unsafe argument processing using eval, which allows…

  • CVE-2020-2031MedJul 8, 2020
    risk 0.32cvss 4.9epss 0.01

    An integer underflow vulnerability in the dnsproxyd component of the PAN-OS management interface allows authenticated administrators to issue a command from the command line interface that causes the component to stop responding. Repeated attempts to send this request result in…

  • CVE-2008-2363Jun 2, 2008
    risk 0.00cvss epss 0.06

    The PartsBatch class in Pan 0.132 and earlier does not properly manage the data structures for Parts batches, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .nzb file that triggers a heap-based…

  • CVE-2003-0855Nov 3, 2003
    risk 0.00cvss epss 0.02

    Pan 0.13.3 and earlier allows remote attackers to cause a denial of service (crash) via a news post with a long author email address.