Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 10.0
CVE-2020-2021 KEV
When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (uncheck…
Pan Os
8.1.15 / 9.0.9+
HIGH 7.2
CVE-2020-2027
A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processe…
Pan Os
8.1.13 / 9.0.7+
HIGH 7.2
CVE-2020-2028
An OS Command Injection vulnerability in PAN-OS management server allows authenticated administrators to execute arbitrary OS commands with root priv…
Pan Os
8.1.13 / 9.0.7+
HIGH 7.2
CVE-2020-2029
An OS Command Injection vulnerability in the PAN-OS web management interface allows authenticated administrators to execute arbitrary OS commands wit…
Pan Os
7.1.26 / 8.1.13+
HIGH 7.0
CVE-2020-2032
A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to execute programs with SYSTEM pr…
Globalprotect
5.0.10 / 5.1.4+
MEDIUM 5.3
CVE-2020-2033
When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authenti…
Globalprotect
5.0.10 / 5.1.4+
CRITICAL 9.0
CVE-2020-2018
An authentication bypass vulnerability in the Panorama context switching feature allows an attacker with network access to a Panorama's management in…
Pan Os
7.1.26 / 8.1.12+
HIGH 8.8
CVE-2020-2013
A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administ…
Pan Os
8.1.13 / 9.0.6+
HIGH 8.8
CVE-2020-2014
An OS Command Injection vulnerability in PAN-OS management server allows authenticated users to inject and execute arbitrary shell commands with root…
Pan Os
after 9.0.6
HIGH 8.8
CVE-2020-2015
A buffer overflow vulnerability in the PAN-OS management server allows authenticated users to crash system processes or potentially execute arbitrary…
Pan Os
7.1.26 / 8.1.13+
HIGH 7.0
CVE-2020-2016
A race condition due to insecure creation of a file in a temporary directory vulnerability in PAN-OS allows for root privilege escalation from a limi…
Pan Os
7.1.26 / 8.1.13+
MEDIUM 6.1
CVE-2020-2017
A DOM-Based Cross Site Scripting Vulnerability exists in PAN-OS and Panorama Management Web Interfaces. A remote attacker able to convince an authent…
Pan Os
7.1.26 / 8.1.13+
HIGH 8.8
CVE-2020-2006
A stack-based buffer overflow vulnerability in the management server component of PAN-OS that allows an authenticated user to potentially execute arb…
Pan Os
after 8.1.13
HIGH 7.5
CVE-2020-2011
An improper input validation vulnerability in the configuration daemon of Palo Alto Networks PAN-OS Panorama allows for a remote unauthenticated user…
Pan Os
8.1.14 / 9.1.0+
HIGH 7.5
CVE-2020-2012
Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthent…
Pan Os
8.1.13 / 9.0.7+
HIGH 7.2
CVE-2020-2007
An OS command injection vulnerability in the management server component of PAN-OS allows an authenticated user to potentially execute arbitrary comm…
Pan Os
after 9.0.6
HIGH 7.2
CVE-2020-2008
An OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS allows authenticated administrators to execute co…
Pan Os
after 8.1.13
HIGH 7.2
CVE-2020-2009
An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an authenticated administrator to …
Pan Os
after 9.0.6
HIGH 7.2
CVE-2020-2010
An OS command injection vulnerability in PAN-OS management interface allows an authenticated administrator to execute arbitrary OS commands with root…
Pan Os
after 9.0.6
MEDIUM 6.5
CVE-2020-2003
An external control of filename vulnerability in the command processing of PAN-OS allows an authenticated administrator to delete arbitrary system fi…
Pan Os
9.1.1+
MEDIUM 6.1
CVE-2020-2005
A cross-site scripting (XSS) vulnerability exists when visiting malicious websites with the Palo Alto Networks GlobalProtect Clientless VPN that can …
Pan Os
7.1.26 / 8.1.13+
MEDIUM 5.5
CVE-2020-2004
Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are collected for troubleshootin…
Globalprotect
5.0.9 / 5.1.2+
CRITICAL 9.8
CVE-2020-2001
An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT processing logic that allows an unauthenticated use…
Pan Os
8.1.12 / 9.0.6+
HIGH 8.8
CVE-2020-1998
An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions …
Pan Os
7.1.26 / 8.1.13+
HIGH 8.1
CVE-2020-2002
An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing…
Pan Os
7.1.26 / 8.1.13+
MEDIUM 6.1
CVE-2020-1997
An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection …
Pan Os
7.1.26 / 8.0.14+
MEDIUM 5.4
CVE-2020-1993
The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which allows session fixation attacks…
Pan Os
after 9.0.7
MEDIUM 5.3
CVE-2020-1996
A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthenticated user to inject messages i…
Pan Os
after 9.0.8
CRITICAL 9.8
CVE-2020-1992
A format string vulnerability in the Varrcvr daemon of PAN-OS on PA-7000 Series devices with a Log Forwarding Card (LFC) allows remote attackers to c…
Pan Os
9.0.7 / 9.1.2+
HIGH 7.2
CVE-2020-1990
A stack-based buffer overflow vulnerability in the management server component of PAN-OS allows an authenticated user to upload a corrupted PAN-OS co…
Pan Os
8.1.13 / 9.0.7+