Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Palo Alto Networks — Vulnerabilities & Security Advisories 342

Browse all 342 CVE security advisories affecting Palo Alto Networks. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Palo Alto Networks operates as a prominent cybersecurity vendor, primarily providing next-generation firewalls, cloud security solutions, and endpoint protection platforms to enterprise clients. The company’s software ecosystem, particularly its PAN-OS operating system, has historically been associated with a significant volume of Common Vulnerabilities and Exposures, currently totaling 280 recorded instances. These vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from input validation errors or improper access controls within management interfaces. While the firm maintains a robust security posture through regular patching cycles and proactive threat intelligence integration, the high CVE count reflects the complexity of its extensive feature set and the broad attack surface inherent in critical infrastructure components. Major incidents have been limited, with most issues resolved via timely updates, though the sheer number of disclosed flaws underscores the challenges of securing large-scale, continuously updated network security appliances.

Found 122 results / 342 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2023-6792 PAN-OS: OS Command Injection Vulnerability in the XML API — PAN-OS CWE-88 5.5 Medium 2023-12-13
CVE-2023-6790 PAN-OS: DOM-Based Cross-Site Scripting (XSS) Vulnerability in the Web Interface — PAN-OS CWE-79 8.8 High 2023-12-13
CVE-2023-38046 PAN-OS: Read System Files and Resources During Configuration Commit — PAN-OS CWE-610 5.5 Medium 2023-07-12
CVE-2023-0010 PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in Captive Portal Authentication — PAN-OS CWE-79 5.4 Medium 2023-06-14
CVE-2023-0008 PAN-OS: Local File Disclosure Vulnerability in the PAN-OS Web Interface — PAN-OS CWE-73 4.4 Medium 2023-05-10
CVE-2023-0007 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Panorama Web Interface — PAN-OS CWE-80 6.5 Medium 2023-05-10
CVE-2023-0005 PAN-OS: Exposure of Sensitive Information Vulnerability — PAN-OS CWE-497 4.1 Medium 2023-04-12
CVE-2023-0004 PAN-OS: Local File Deletion Vulnerability — PAN-OS CWE-703 6.5 Medium 2023-04-12
CVE-2022-0030 PAN-OS: Authentication Bypass in Web Interface — PAN-OS CWE-290 8.1 High 2022-10-12
CVE-2022-0024 PAN-OS: Improper Neutralization Vulnerability Leads to Unintended Program Execution During Configuration Commit — PAN-OS CWE-138 7.2 High 2022-05-11
CVE-2022-0023 PAN-OS: Denial-of-Service (DoS) Vulnerability in DNS Proxy — PAN-OS CWE-755 5.9 Medium 2022-04-13
CVE-2022-0022 PAN-OS: Use of a Weak Cryptographic Algorithm for Stored Password Hashes — PAN-OS CWE-916 4.1 Medium 2022-03-09
CVE-2022-0011 PAN-OS: URL Category Exceptions Match More URLs Than Intended in URL Filtering — PAN-OS CWE-436 6.5 Medium 2022-02-10
CVE-2021-3064 PAN-OS: Memory Corruption Vulnerability in GlobalProtect Portal and Gateway Interfaces — PAN-OS CWE-121 9.8 Critical 2021-11-10
CVE-2021-3063 PAN-OS: Denial-of-Service (DoS) Vulnerability in GlobalProtect Portal and Gateway Interfaces — PAN-OS CWE-755 7.5 High 2021-11-10
CVE-2021-3062 PAN-OS: Improper Access Control Vulnerability Exposing AWS Instance Metadata Endpoint to GlobalProtect Users — PAN-OS CWE-284 8.1 High 2021-11-10
CVE-2021-3061 PAN-OS: OS Command Injection Vulnerability in the Command Line Interface (CLI) — PAN-OS CWE-78 6.4 Medium 2021-11-10
CVE-2021-3060 PAN-OS: OS Command Injection in Simple Certificate Enrollment Protocol (SCEP) — PAN-OS CWE-78 8.1 High 2021-11-10
CVE-2021-3059 PAN-OS: OS Command Injection Vulnerability When Performing Dynamic Updates — PAN-OS CWE-78 8.1 High 2021-11-10
CVE-2021-3058 PAN-OS: OS Command Injection Vulnerability in Web Interface XML API — PAN-OS CWE-78 8.8 High 2021-11-10
CVE-2021-3056 PAN-OS: Memory Corruption Vulnerability in GlobalProtect Clientless VPN During SAML Authentication — PAN-OS CWE-120 8.8 High 2021-11-10
CVE-2021-3055 PAN-OS: XML External Entity (XXE) Reference Vulnerability in the PAN-OS Web Interface — PAN-OS CWE-611 6.5 Medium 2021-09-08
CVE-2021-3054 PAN-OS: Unsigned Code Execution During Plugin Installation Race Condition Vulnerability — PAN-OS CWE-367 7.2 High 2021-09-08
CVE-2021-3053 PAN-OS: Exceptional Condition Denial-of-Service (DoS) — PAN-OS CWE-755 7.5 High 2021-09-08
CVE-2021-3052 PAN-OS: Reflected Cross-Site Scripting (XSS) in Web Interface — PAN-OS CWE-79 8.0 High 2021-09-08
CVE-2021-3050 PAN-OS: OS Command Injection Vulnerability in Web Interface — PAN-OS CWE-78 8.8 High 2021-08-11
CVE-2021-3048 PAN-OS: Invalid URLs in an External Dynamic List (EDL) can Lead to Firewall Outage — PAN-OS CWE-20 5.9 Medium 2021-08-11
CVE-2021-3047 PAN-OS: Weak Cryptography Used in Web Interface Authentication — PAN-OS CWE-338 4.2 Medium 2021-08-11
CVE-2021-3046 PAN-OS: Improper SAML Authentication Vulnerability in GlobalProtect Portal — PAN-OS CWE-287 6.8 Medium 2021-08-11
CVE-2021-3045 PAN-OS: OS Command Argument Injection in Web Interface — PAN-OS CWE-88 4.9 Medium 2021-08-11

This page lists every published CVE security advisory associated with Palo Alto Networks. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.