Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.87% | — | Juniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | A command injection vulnerability in command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be able to bypass configured access protections to execute arbitrary shell commands within the context of the current user. The vulnerability allows an attacker to bypass… | |
| Modificada | Alta (8.8) | 0.63% | — | Juniper JunosJuniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | An Out Of Bounds (OOB) access vulnerability in the handling of responses by a Juniper Agile License (JAL) Client in Juniper Networks Junos OS and Junos OS Evolved, configured in Network Mode (to use Juniper Agile License Manager) may allow an attacker to cause a partial Denial of Service (DoS), or lead to remote code… | |
| Modificada | Alta (7.5) | 1.2% | — | Juniper JunosJuniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | An Improper Handling of Exceptional Conditions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an attacker to inject a specific BGP update, causing the routing protocol daemon (RPD) to crash and restart, leading to a Denial of Service (DoS). Continued receipt and processing of the BGP update… | |
| Modificada | Alta (8.8) | 0.87% | — | Juniper JunosJuniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | An Improper Privilege Management vulnerability in the gRPC framework, used by the Juniper Extension Toolkit (JET) API on Juniper Networks Junos OS and Junos OS Evolved, allows a network-based, low-privileged authenticated attacker to perform operations as root, leading to complete compromise of the targeted system.… | |
| Modificada | Media (4.7) | 0.17% | — | Juniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | A Race Condition in the 'show chassis pic' command in Juniper Networks Junos OS Evolved may allow an attacker to crash the port interface concentrator daemon (picd) process on the FPC, if the command is executed coincident with other system events outside the attacker's control, leading to a Denial of Service (DoS)… | |
| Modificada | Media (6.5) | 0.73% | — | Juniper Junos OS Evolved | 19/10/2021 | 17/6/2026 | A vulnerability in the processing of TCP MD5 authentication in Juniper Networks Junos OS Evolved may allow a BGP or LDP session configured with MD5 authentication to succeed, even if the peer does not have TCP MD5 authentication enabled. This could lead to untrusted or unauthorized sessions being established,… | |
| Modificada | Alta (8.8) | 1.7% | — | Accesspressthemes Access Demo ImporterAccesspressthemes Accesspress-liteAccesspressthemes Accesspress-magAccesspressthemes Accesspress-parallax+39 | 11/10/2021 | 17/6/2026 | A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the… | |
| Modificada | Media (5.5) | 0.22% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 2/9/2021 | 17/6/2026 | A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, local attacker to access sensitive information stored on the underlying file system of an affected system. This vulnerability exists because sensitive information is not… | |
| Modificada | Media (6.5) | 1.1% | — | Cisco Evolved Programmable Network Manager | 4/8/2021 | 17/6/2026 | A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to access sensitive data on an affected system. This vulnerability exists because the application does not sufficiently protect sensitive data when responding to an API request. An… | |
| Modificada | Media (6.5) | 0.38% | — | Juniper Junos OS Evolved | 15/7/2021 | 17/6/2026 | An Uncontrolled Resource Consumption vulnerability in the ARP daemon (arpd) and Network Discovery Protocol (ndp) process of Juniper Networks Junos OS Evolved allows a malicious attacker on the local network to consume memory resources, ultimately resulting in a Denial of Service (DoS) condition. Link-layer functions… | |
| Modificada | Media (6.5) | 1.0% | — | Juniper JunosJuniper Junos OS Evolved | 15/7/2021 | 17/6/2026 | An Exposure of System Data vulnerability in Juniper Networks Junos OS and Junos OS Evolved, where a sensitive system-level resource is not being sufficiently protected, allows a network-based unauthenticated attacker to send specific traffic which partially reaches this resource. A high rate of specific traffic may… | |
| Modificada | Media (6.5) | 0.37% | — | Juniper JunosJuniper Junos OS Evolved | 15/7/2021 | 17/6/2026 | In a Segment Routing ISIS (SR-ISIS)/MPLS environment, on Juniper Networks Junos OS and Junos OS Evolved devices, configured with ISIS Flexible Algorithm for Segment Routing and sensor-based statistics, a flap of a ISIS link in the network, can lead to a routing process daemon (RPD) crash and restart, causing a Denial… | |
| Modificada | Alta (7.5) | 1.1% | — | Juniper Junos OS Evolved | 15/7/2021 | 17/6/2026 | A vulnerability in the handling of exceptional conditions in Juniper Networks Junos OS Evolved (EVO) allows an attacker to send specially crafted packets to the device, causing the Advanced Forwarding Toolkit manager (evo-aftmand-bt or evo-aftmand-zx) process to crash and restart, impacting all traffic going through… | |
| Modificada | Alta (8.8) | 2.1% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 22/5/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability is due to insufficient validation of user-supplied input to the… | |
| Modificada | Baja (3.4) | 0.21% | — | Cisco Evolved Programmable Network ManagerCisco Identity Services EngineCisco Prime Infrastructure | 22/5/2021 | 17/6/2026 | A vulnerability in the restricted shell of Cisco Evolved Programmable Network (EPN) Manager, Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to identify directories and write arbitrary files to the file system. This vulnerability is due to improper… | |
| Modificada | Media (5.3) | 1.0% | — | Juniper JunosJuniper Junos OS Evolved | 22/4/2021 | 17/6/2026 | An always-incorrect control flow implementation in the implicit filter terms of Juniper Networks Junos OS and Junos OS Evolved on ACX5800, EX9200 Series, MX10000 Series, MX240, MX480, MX960 devices with affected Trio line cards allows an attacker to exploit an interdependency in the PFE UCODE microcode of the Trio… | |
| Modificada | Alta (7.5) | 0.98% | — | Juniper JunosJuniper Junos OS Evolved | 22/4/2021 | 17/6/2026 | A vulnerability in the processing of traffic matching a firewall filter containing a syslog action in Juniper Networks Junos OS on MX Series with MPC10/MPC11 cards installed, PTX10003 and PTX10008 Series devices, will cause the line card to crash and restart, creating a Denial of Service (DoS). Continued receipt and… | |
| Modificada | Alta (7.4) | 0.38% | — | Juniper JunosJuniper Junos OS Evolved | 22/4/2021 | 17/6/2026 | Due to a vulnerability in DDoS protection in Juniper Networks Junos OS and Junos OS Evolved on QFX5K Series switches in a VXLAN configuration, instability might be experienced in the underlay network as a consequence of exceeding the default ddos-protection aggregate threshold. If an attacker on a client device on the… | |
| Modificada | Alta (7.5) | 1.0% | — | Juniper JunosJuniper Junos OS Evolved | 22/4/2021 | 17/6/2026 | In segment routing traffic engineering (SRTE) environments where the BGP Monitoring Protocol (BMP) feature is enable, a vulnerability in the Routing Protocol Daemon (RPD) process of Juniper Networks Junos OS allows an attacker to send a specific crafted BGP update message causing the RPD service to core, creating a… | |
| Modificada | Media (6.5) | 0.38% | — | Juniper Junos OS Evolved | 22/4/2021 | 17/6/2026 | In Juniper Networks Junos OS Evolved, receipt of a stream of specific genuine Layer 2 frames may cause the Advanced Forwarding Toolkit (AFT) manager process (Evo-aftmand), responsible for handling Route, Class-of-Service (CoS), Firewall operations within the packet forwarding engine (PFE) to crash and restart, leading… | |
| Modificada | Media (6.5) | 0.85% | — | Juniper JunosJuniper Junos OS Evolved | 22/4/2021 | 17/6/2026 | Due to an improper check for unusual or exceptional conditions in Juniper Networks Junos OS and Junos OS Evolved the Routing Protocol Daemon (RPD) service, upon receipt of a specific matching BGP packet meeting a specific term in the flowspec configuration, crashes and restarts causing a Denial of Service (DoS).… | |
| Modificada | Alta (7.5) | 0.88% | — | Juniper Junos OS Evolved | 22/4/2021 | 17/6/2026 | On Juniper Networks Junos OS Evolved devices, receipt of a specific IPv6 packet may cause an established IPv6 BGP session to terminate, creating a Denial of Service (DoS) condition. Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue does not affect… | |
| Modificada | Media (5.8) | 0.71% | — | Juniper Junos OS Evolved | 22/4/2021 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions in Juniper Networks Junos OS Evolved may cause the stateless firewall filter configuration which uses the action 'policer' in certain combinations with other options to not take effect. An administrator can use the following CLI command to see the failures with… | |
| Modificada | Crítica (10) | 1.3% | — | Juniper JunosJuniper Junos OS Evolved | 15/1/2021 | 17/6/2026 | An improper check for unusual or exceptional conditions in Juniper Networks Junos OS and Junos OS Evolved Routing Protocol Daemon (RPD) service allows an attacker to send a valid BGP FlowSpec message thereby causing an unexpected change in the route advertisements within the BGP FlowSpec domain leading to disruptions… | |
| Modificada | Media (6.5) | 0.44% | — | Juniper Junos OS Evolved | 15/1/2021 | 17/6/2026 | In Juniper Networks Junos OS Evolved an attacker sending certain valid BGP update packets may cause Junos OS Evolved to access an uninitialized pointer causing RPD to core leading to a Denial of Service (DoS). Continued receipt of these types of valid BGP update packets will cause an extended Denial of Service… |