paloaltonetworks records
383 published records for vendor paloaltonetworks.
Researcher profile
- Entered KEV
- 17 · 4.4%
- Weaponized
- 19 · 5%
- Pre-auth RCE
- 32
- With a fix record
- 73.4%
- Median publish → KEV
- 16 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')44
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')38
- CWE-20 Improper Input Validation22
- CWE-269 Improper Privilege Management13
- CWE-532 Insertion of Sensitive Information into Log File11
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
The weakness classes this vendor ships most often: where to look.
CWEAll records
383 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2024-3400Weaponized | PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtectpaloaltonetworks · pan-os · CWE-20 | Critical10.0 | KEV | 100.0% | Apr 12, 2024 |
99Now | CVE-2024-9463Weaponized | Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosurepaloaltonetworks · expedition · CWE-78 | Critical9.9 | KEV | 98.5% | Oct 9, 2024 |
98Now | CVE-2017-15944Weaponized | Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to executepaloaltonetworks · pan-os · CWE-20 | Critical9.8 | KEV | 98.3% | Dec 11, 2017 |
97Now | CVE-2024-0012Weaponized | PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)paloaltonetworks · pan-os · CWE-306 | Critical9.3 | KEV | 99.8% | Nov 18, 2024 |
96Now | CVE-2024-9465Weaponized | Expedition: SQL Injection Leads to Firewall Admin Credential Disclosurepaloaltonetworks · expedition · CWE-89 | Critical9.2 | KEV | 99.6% | Oct 9, 2024 |
95Now | CVE-2025-0108Weaponized | PAN-OS: Authentication Bypass in the Management Web Interfacepaloaltonetworks · pan-os · CWE-306 | High8.8 | KEV | 98.5% | Feb 12, 2025 |
95Now | CVE-2024-5910Weaponized | Expedition: Missing Authentication Leads to Admin Account Takeoverpaloaltonetworks · expedition · CWE-306 | Critical9.3 | KEV | 91.8% | Jul 10, 2024 |
90Now | CVE-2026-0257Weaponized | PAN-OS: GlobalProtect Authentication Bypass Vulnerabilitiespaloaltonetworks · pan-os · CWE-565 | High7.8 | KEV | 96.4% | May 13, 2026 |
85Now | CVE-2024-9474Weaponized | PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interfacepaloaltonetworks · pan-os · CWE-78 | Medium6.9 | KEV | 94.7% | Nov 18, 2024 |
83Now | CVE-2016-5195Weaponized | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect halinux · linux kernel · CWE-362 | High7.0 | KEV | 83.5% | Nov 10, 2016 |
77This week | CVE-2026-0300Weaponized | PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portalpaloaltonetworks · pan-os · CWE-787 | Critical9.3 | KEV | 31.7% | May 6, 2026 |
76This week | CVE-2019-1579Weaponized | Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or paloaltonetworks · pan-os · CWE-134 | High8.1 | KEV | 46.2% | Jul 19, 2019 |
73This week | CVE-2024-3393Weaponized | PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packetpaloaltonetworks · pan-os · CWE-754 | High8.7 | KEV | 28.4% | Dec 27, 2024 |
71This week | CVE-2020-2021Weaponized | PAN-OS: Authentication Bypass in SAML Authenticationpaloaltonetworks · pan-os · CWE-347 | Critical10.0 | KEV | 4.4% | Jun 29, 2020 |
65This week | CVE-2018-14634Weaponized | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function.linux · linux kernel · CWE-190 | High7.8 | KEV | 14.7% | Sep 25, 2018 |
65This week | CVE-2022-0028Weaponized | PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filteringpaloaltonetworks · pan-os · CWE-406 | High8.6 | KEV | 2.4% | Aug 10, 2022 |
62This week | CVE-2024-9464Proof of concept | Expedition: Authenticated OS Command Injection Vulnerability Leads to Firewall Admin Credential Disclosurepaloaltonetworks · expedition · CWE-78 | Critical9.3 | — | 82.6% | Oct 9, 2024 |
59Plan | CVE-2025-0111Weaponized | PAN-OS: Authenticated File Read Vulnerability in the Management Web Interfacepaloaltonetworks · pan-os · CWE-73 | High7.1 | KEV | 2.0% | Feb 12, 2025 |
54Plan | CVE-2020-2038Weaponized | PAN-OS: OS command injection vulnerability in the management web interfacepaloaltonetworks · pan-os · CWE-78 | High7.2 | — | 86.1% | Sep 9, 2020 |
54Plan | CVE-2025-0107Proof of concept | Expedition: OS Command Injection Vulnerabilitypaloaltonetworks · expedition · CWE-78 | High7.7 | — | 78.5% | Jan 10, 2025 |
49Plan | CVE-2016-4971Proof of concept | GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.gnu · wget | High8.8 | — | 46.1% | Jun 30, 2016 |
49Plan | CVE-2016-9150Proof of concept | Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x paloaltonetworks · pan-os · CWE-119 | Critical9.8 | — | 34.8% | Nov 19, 2016 |
46Plan | CVE-2018-10143No exploit | The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system paloaltonetworks · expedition · CWE-269 | Critical9.8 | — | 24.8% | Dec 11, 2018 |
45Plan | CVE-2021-3064Proof of concept | PAN-OS: Memory Corruption Vulnerability in GlobalProtect Portal and Gateway Interfacespaloaltonetworks · pan-os · CWE-121 | Critical9.8 | — | 20.1% | Nov 10, 2021 |
42Plan | CVE-2016-8610Proof of concept | A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processiopenssl · openssl · CWE-400 | High7.5 | — | 39.7% | Nov 13, 2017 |
- CVE-2024-3400100Now
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
CriticalCVSS 10.0KEVWeaponizedEPSS 100%paloaltonetworks · pan-osApr 12, 2024
- CVE-2024-946399Now
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
CriticalCVSS 9.9KEVWeaponizedEPSS 99%paloaltonetworks · expeditionOct 9, 2024
- CVE-2017-1594498Now
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute
CriticalCVSS 9.8KEVWeaponizedEPSS 98%paloaltonetworks · pan-osDec 11, 2017
- CVE-2024-001297Now
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
CriticalCVSS 9.3KEVWeaponizedEPSS 100%paloaltonetworks · pan-osNov 18, 2024
- CVE-2024-946596Now
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
CriticalCVSS 9.2KEVWeaponizedEPSS 100%paloaltonetworks · expeditionOct 9, 2024
- CVE-2025-010895Now
PAN-OS: Authentication Bypass in the Management Web Interface
HighCVSS 8.8KEVWeaponizedEPSS 98%paloaltonetworks · pan-osFeb 12, 2025
- CVE-2024-591095Now
Expedition: Missing Authentication Leads to Admin Account Takeover
CriticalCVSS 9.3KEVWeaponizedEPSS 92%paloaltonetworks · expeditionJul 10, 2024
- CVE-2026-025790Now
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
HighCVSS 7.8KEVWeaponizedEPSS 96%paloaltonetworks · pan-osMay 13, 2026
- CVE-2024-947485Now
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
MediumCVSS 6.9KEVWeaponizedEPSS 95%paloaltonetworks · pan-osNov 18, 2024
- CVE-2016-519583Now
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect ha
HighCVSS 7.0KEVWeaponizedEPSS 84%linux · linux kernelNov 10, 2016
- CVE-2026-030077This week
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
CriticalCVSS 9.3KEVWeaponizedEPSS 32%paloaltonetworks · pan-osMay 6, 2026
- CVE-2019-157976This week
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or
HighCVSS 8.1KEVWeaponizedEPSS 46%paloaltonetworks · pan-osJul 19, 2019
- CVE-2024-339373This week
PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet
HighCVSS 8.7KEVWeaponizedEPSS 28%paloaltonetworks · pan-osDec 27, 2024
- CVE-2020-202171This week
PAN-OS: Authentication Bypass in SAML Authentication
CriticalCVSS 10.0KEVWeaponizedEPSS 4%paloaltonetworks · pan-osJun 29, 2020
- CVE-2018-1463465This week
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function.
HighCVSS 7.8KEVWeaponizedEPSS 15%linux · linux kernelSep 25, 2018
- CVE-2022-002865This week
PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering
HighCVSS 8.6KEVWeaponizedEPSS 2%paloaltonetworks · pan-osAug 10, 2022
- CVE-2024-946462This week
Expedition: Authenticated OS Command Injection Vulnerability Leads to Firewall Admin Credential Disclosure
CriticalCVSS 9.3Proof of conceptEPSS 83%paloaltonetworks · expeditionOct 9, 2024
- CVE-2025-011159Plan
PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface
HighCVSS 7.1KEVWeaponizedEPSS 2%paloaltonetworks · pan-osFeb 12, 2025
- CVE-2020-203854Plan
PAN-OS: OS command injection vulnerability in the management web interface
HighCVSS 7.2WeaponizedEPSS 86%paloaltonetworks · pan-osSep 9, 2020
- CVE-2025-010754Plan
Expedition: OS Command Injection Vulnerability
HighCVSS 7.7Proof of conceptEPSS 79%paloaltonetworks · expeditionJan 10, 2025
- CVE-2016-497149Plan
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
HighCVSS 8.8Proof of conceptEPSS 46%gnu · wgetJun 30, 2016
- CVE-2016-915049Plan
Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x
CriticalCVSS 9.8Proof of conceptEPSS 35%paloaltonetworks · pan-osNov 19, 2016
- CVE-2018-1014346Plan
The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system
CriticalCVSS 9.8No exploitEPSS 25%paloaltonetworks · expeditionDec 11, 2018
- CVE-2021-306445Plan
PAN-OS: Memory Corruption Vulnerability in GlobalProtect Portal and Gateway Interfaces
CriticalCVSS 9.8Proof of conceptEPSS 20%paloaltonetworks · pan-osNov 10, 2021
- CVE-2016-861042Plan
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processi
HighCVSS 7.5Proof of conceptEPSS 40%openssl · opensslNov 13, 2017