Juniper
Juniper Junos Space: vulnerabilidades y CVE
Juniper Junos Space tiene 79 vulnerabilidades publicadas, 28 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE79
Últimos 12 meses28
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-21904 | Media (5.1) | 0.21% | — | 9 abr 2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the list filter field that, when visited… |
| CVE-2026-21907 | Alta (8.2) | 0.20% | — | 15 ene 2026 | A Use of a Broken or Risky Cryptographic Algorithm vulnerability in the TLS/SSL server of Juniper Networks Junos Space allows the use of static key ciphers (ssl-static-key-ciphers), reducing the confidentiality of… |
| CVE-2025-60009 | Media (5.1) | 0.22% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the CLI Configlet page that, when visited… |
| CVE-2025-60002 | Media (5.1) | 0.22% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Template Definitions page that, when… |
| CVE-2025-60000 | Media (5.1) | 0.22% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Generate Report page that, when… |
| CVE-2025-59999 | Media (5.1) | 0.24% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the API Access Profiles page that, when… |
| CVE-2025-59998 | Media (5.1) | 0.22% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Archive Log screen that, when visited… |
| CVE-2025-59997 | Media (5.1) | 0.22% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the CLI Configlets pages that, when… |
| CVE-2025-59996 | Media (5.1) | 0.22% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Configuration View page that, when… |
| CVE-2025-59995 | Media (5.1) | 0.22% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Quick Template page that, when… |
| CVE-2025-59994 | Media (5.1) | 0.22% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Quick Template page that, when… |
| CVE-2025-59993 | Media (5.1) | 0.22% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Space Node Setting fields that, when… |
| CVE-2025-59992 | Media (5.1) | 0.22% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Secure Console page that, when… |
| CVE-2025-59991 | Media (5.1) | 0.22% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Device Management pages that, when… |
| CVE-2025-59989 | Media (5.1) | 0.24% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Device Discovery page that, when… |
| CVE-2025-59988 | Media (5.1) | 0.22% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Generate Report page that, when… |
| CVE-2025-59987 | Media (5.1) | 0.22% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the arbitrary device search field that,… |
| CVE-2025-59986 | Media (5.1) | 0.22% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the input fields in Model Devices that,… |
| CVE-2025-59985 | Media (5.1) | 0.22% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in a field on the Purging Policy page that,… |
| CVE-2025-59984 | Media (5.1) | 0.22% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in Global Search that, when visited by… |
| CVE-2025-59983 | Media (5.1) | 0.27% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Template Definition page, when… |
| CVE-2025-59982 | Media (5.1) | 0.27% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the dashboard search field that, when… |
| CVE-2025-59981 | Media (5.1) | 0.27% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Device Template Definition page that,… |
| CVE-2025-59978 | Crítica (9.4) | 0.53% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by… |
| CVE-2025-59976 | Alta (7.1) | 0.29% | — | 9 oct 2025 | An arbitrary file download vulnerability in the web interface of Juniper Networks Junos Space allows a network-based authenticated attacker using a crafted GET method to access any file on the file system. Using… |
| CVE-2025-59975 | Alta (8.7) | 0.41% | — | 9 oct 2025 | An Uncontrolled Resource Consumption vulnerability in the HTTP daemon (httpd) of Juniper Networks Junos Space allows an unauthenticated network-based attacker flooding the device with inbound API calls to consume all… |
| CVE-2025-60001 | Media (5.1) | 0.22% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Generate Report page that, when… |
| CVE-2025-59990 | Media (5.1) | 0.22% | — | 9 oct 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the template creation pages that, when… |
| CVE-2024-39563 | Media (6.9) | 1.3% | — | 11 oct 2024 | A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on the Junos Space Appliance,… |
| CVE-2021-0220 | Media (6.8) | 1.2% | — | 15 ene 2021 | The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for… |