imPC@ndo EN

Vulnerabilità Palo Alto

371 CVE

CVE-2017-9459
Media 6.1

Cross-site scripting (XSS) vulnerability in the management web interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vec…

paloaltonetworks pan-os
0.01EPSS
CVE-2019-1566
Media 6.1

The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML.

paloaltonetworks pan-os
0.01EPSS
CVE-2019-1583
Alta 8.0

Escalation of privilege vulnerability in the Palo Alto Networks Twistlock console 19.07.358 and earlier allows a Twistlock user with Operator capabilities to escalate privileges to that of another user. Active interaction with an affected component is required…

paloaltonetworks twistlock
0.01EPSS
CVE-2026-0286
Alta 7.2

A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI acces…

paloaltonetworks pan-os
0.01EPSS
CVE-2023-6792
Media 5.5

An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.

paloaltonetworks pan-os
0.01EPSS
CVE-2020-1995
Media 4.9

A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a request that causes the rasmgr daemon to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by r…

paloaltonetworks pan-os
0.01EPSS
CVE-2023-6795
Media 5.5

An OS command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.

paloaltonetworks pan-os
0.01EPSS
CVE-2020-2031
Media 4.9

An integer underflow vulnerability in the dnsproxyd component of the PAN-OS management interface allows authenticated administrators to issue a command from the command line interface that causes the component to stop responding. Repeated attempts to send this…

paloaltonetworks pan-os
0.01EPSS
CVE-2023-0004
Media 6.5

A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and system components that impact the integrity …

fedoraproject fedora · paloaltonetworks pan-os
0.01EPSS
CVE-2017-16878
Media 6.1

Cross-site scripting (XSS) vulnerability in the Captive Portal function in Palo Alto Networks PAN-OS before 8.0.7 allows remote attackers to inject arbitrary web script or HTML by leveraging an unspecified configuration.

paloaltonetworks pan-os
0.01EPSS
CVE-2021-3046
Media 6.8

An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when they are configured to use SAML authentica…

paloaltonetworks pan-os
0.01EPSS
CVE-2018-7636
Media 6.1

The URL filtering "continue page" hosted by PAN-OS 8.0.10 and earlier may allow an attacker to inject arbitrary JavaScript or HTML via specially crafted URLs.

paloaltonetworks pan-os
0.01EPSS
CVE-2021-3055
Media 6.5

An improper restriction of XML external entity (XXE) reference vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the fi…

paloaltonetworks pan-os
0.01EPSS
CVE-2019-1578
Media 6.1

Cross-site scripting vulnerability in Palo Alto Networks MineMeld version 0.9.60 and earlier may allow a remote attacker able to convince an authenticated MineMeld admin to type malicious input in the MineMeld UI could execute arbitrary JavaScript code in the …

paloaltonetworks minemeld
0.01EPSS
CVE-2017-7217
Media 4.3

The Management Web Interface in Palo Alto Networks PAN-OS before 7.0.14 and 7.1.x before 7.1.9 allows remote attackers to write to export files via unspecified parameters.

paloaltonetworks pan-os
0.01EPSS
CVE-2019-1571
Media 4.8

The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the RADIUS server settings.

paloaltonetworks expedition
0.01EPSS
CVE-2019-1570
Media 4.8

The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the LDAP server settings.

paloaltonetworks expedition
0.01EPSS
CVE-2019-1569
Media 4.8

The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings for account name of admin user.

paloaltonetworks expedition
0.01EPSS
CVE-2019-1582
Alta 7.2

Memory corruption in PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow an administrative user to cause arbitrary memory corruption by rekeying the current client interactive session.

paloaltonetworks pan-os
0.01EPSS
CVE-2020-2050
Alta 8.2

An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to bypass all client certificate checks with an invalid certificate. A remote attacker can successfully authentic…

paloaltonetworks pan-os
0.01EPSS
CVE-2015-4162
Media 4.0

XML external entity (XXE) vulnerability in the management interface in PAN-OS before 5.0.16, 6.x before 6.0.8, and 6.1.x before 6.1.4 allows remote authenticated administrators to obtain sensitive information via crafted XML data.

paloaltonetworks pan-os
0.01EPSS
CVE-2025-4231
Alta 7.2

A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user. The attacker must have network access to the management web interface and successfully authenticate to exploit th…

paloaltonetworks pan-os
0.01EPSS
CVE-2017-7644
Media 6.5

The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1.x before 7.1.9 allows remote authenticated users to obtain sensitive information by leveraging incorrect permission validation, aka PAN-SA-2017-0013 and PAN-705…

paloaltonetworks pan-os
0.01EPSS
CVE-2018-9337
Media 5.4

The PAN-OS web interface administration page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.17 and earlier, PAN-OS 8.0.10 and earlier, and PAN-OS 8.1.1 and earlier may allow an attacker to inject arbitrary JavaScript or HTML.

paloaltonetworks pan-os
0.01EPSS
CVE-2018-9335
Media 5.4

The PAN-OS session browser in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier, and PAN-OS 8.1.1 and earlier may allow an attacker to inject arbitrary JavaScript or HTML.

paloaltonetworks pan-os
0.01EPSS