Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
976 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.50% | — | Juniper JunosJuniper Junos OS Evolved | 13/10/2023 | 17/6/2026 | An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the management daemon (mgd) process of Juniper Networks Junos OS and Junos OS Evolved allows a network-based authenticated low-privileged attacker, by executing a specific command via NETCONF, to cause a CPU Denial of Service… | |
| Modificada | Media (5.3) | 0.32% | — | Juniper Junos | 13/10/2023 | 17/6/2026 | An Improper Input Validation vulnerability in the VxLAN packet forwarding engine (PFE) of Juniper Networks Junos OS on QFX5000 Series, EX4600 Series devices allows an unauthenticated, adjacent attacker, sending two or more genuine packets in the same VxLAN topology to possibly cause a DMA memory leak to occur under… | |
| Modificada | Alta (8.8) | 0.58% | — | Juniper JunosJuniper Junos OS Evolved | 13/10/2023 | 17/6/2026 | An Unchecked Return Value vulnerability in the user interfaces to the Juniper Networks Junos OS and Junos OS Evolved, the CLI, the XML API, the XML Management Protocol, the NETCONF Management Protocol, the gNMI interfaces, and the J-Web User Interfaces causes unintended effects such as demotion or elevation of… | |
| Modificada | Alta (7.5) | 0.53% | — | Juniper Junos | 13/10/2023 | 17/6/2026 | An Improperly Implemented Security Check for Standard vulnerability in storm control of Juniper Networks Junos OS QFX5k devices allows packets to be punted to ARP queue causing a l2 loop resulting in a DDOS violations and DDOS syslog. This issue is triggered when Storm control is enabled and ICMPv6 packets are present… | |
| Modificada | Media (5.5) | 0.16% | — | Juniper JunosJuniper Junos OS Evolved | 13/10/2023 | 17/6/2026 | A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos OS allows a low privileged attacker to execute a specific CLI commands leading to Denial of Service. Repeated actions by the attacker will create a sustained Denial of Service (DoS) condition. This issue affects Juniper Networks:… | |
| Modificada | Media (5.5) | 0.16% | — | Juniper JunosJuniper Junos OS Evolved | 13/10/2023 | 17/6/2026 | A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos and Junos EVO allows a low privileged attacker to execute a specific CLI commands leading to Denial of Service. Repeated actions by the attacker will create a sustained Denial of Service (DoS) condition. This issue affects Juniper… | |
| Modificada | Media (5.5) | 0.16% | — | Juniper JunosJuniper Junos OS Evolved | 13/10/2023 | 17/6/2026 | A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos OS allows a low privileged attacker to execute a specific CLI commands leading to Denial of Service. Repeated actions by the attacker will create a sustained Denial of Service (DoS) condition. This issue affects Juniper Networks:… | |
| Modificada | Alta (7.5) | 0.52% | — | Juniper JunosJuniper Junos OS Evolved | 12/10/2023 | 17/6/2026 | A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows to send specific genuine PIM packets to the device resulting in rpd to crash causing a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained… | |
| Modificada | Alta (7.5) | 0.55% | — | Juniper Junos | 12/10/2023 | 17/6/2026 | An Improper Handling of Inconsistent Special Elements vulnerability in the Junos Services Framework (jsf) module of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause a crash in the Packet Forwarding Engine (pfe) and thereby resulting in a Denial of Service (DoS). Upon receiving… | |
| Modificada | Alta (7.5) | 0.52% | — | Juniper Junos | 12/10/2023 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite loop, resulting in a Denial of Service (DoS). An attacker who sends malformed TCP traffic via an… | |
| Modificada | Media (6.5) | 0.27% | — | Juniper JunosJuniper Junos OS Evolved | 12/10/2023 | 17/6/2026 | An Improper Validation of Specified Quantity in Input vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker who sends specific LLDP packets to cause a Denial of Service(DoS). This issue occurs when specific LLDP… | |
| Modificada | Media (6.5) | 0.28% | — | Juniper Junos | 12/10/2023 | 17/6/2026 | A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). PTX3000, PTX5000, QFX10000, PTX1000, PTX10002, and PTX10004, PTX10008 and PTX10016 with LC110x FPCs do… | |
| Modificada | Media (5.4) | 0.17% | — | Juniper Junos OS Evolved | 11/10/2023 | 17/6/2026 | An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10001, PTX10004, PTX10008, and PTX10016 devices allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addresses not intended to reach the adjacent LAN to be forwarded to the downstream… | |
| Modificada | Media (5.4) | 0.18% | — | Juniper Junos OS Evolved | 11/10/2023 | 17/6/2026 | An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10003 Series allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addresses not intended to reach the adjacent LAN to be forwarded to the downstream network. Due to this issue, the router… | |
| Modificada | Media (5.3) | 0.33% | — | Juniper Junos | 11/10/2023 | 17/6/2026 | A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in telemetry processing of Juniper Networks Junos OS allows a network-based authenticated attacker to flood the system with multiple telemetry requests, causing the Junos Kernel Debugging Streaming Daemon (jkdsd) process to crash, leading to a Denial of… | |
| Modificada | Media (5.5) | 0.17% | — | Juniper Junos OS Evolved | 11/10/2023 | 17/6/2026 | An Exposure of Sensitive Information vulnerability in the 'file copy' command of Junos OS Evolved allows a local, authenticated attacker with shell access to view passwords supplied on the CLI command-line. These credentials can then be used to provide unauthorized access to the remote system. | |
| Modificada | Alta (7.5) | 0.54% | — | Juniper JunosJuniper Junos OS Evolved | 11/10/2023 | 17/6/2026 | An Improper Handling of Exceptional Conditions vulnerability in AS PATH processing of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a BGP update message with an AS PATH containing a large number of 4-byte ASes, leading to a Denial of Service (DoS). Continued receipt and processing of these… | |
| Analizada | Media (5.3) | 1.1% | ⚠ Explotación activa | Juniper Junos | 27/9/2023 | 17/6/2026 | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to… | |
| Modificada | Alta (7.5) | 18% | — | Juniper JunosJuniper Junos OS Evolved | 1/9/2023 | 17/6/2026 | An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When certain specific crafted BGP UPDATE messages are received over an established BGP session, one BGP… | |
| Analizada | Media (5.3) | 83% | ⚠ Explotación activa | Juniper Junos | 17/8/2023 | 17/6/2026 | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication an attacker is able to… | |
| Analizada | Media (5.3) | 93% | ⚠ Explotación activa💥 PoC | Juniper Junos | 17/8/2023 | 17/6/2026 | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication an attacker is able to upload arbitrary… | |
| Analizada | Crítica (9.8) | 95% | ⚠ Explotación activa💥 Exploit | Juniper Junos | 17/8/2023 | 17/6/2026 | A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attacker is able to modify the PHP execution environment allowing the… | |
| Analizada | Media (5.3) | 90% | ⚠ Explotación activa💥 Exploit | Juniper Junos | 17/8/2023 | 17/6/2026 | A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables leading to partial loss of… | |
| Modificada | Media (6.5) | 0.30% | — | Juniper Junos | 14/7/2023 | 17/6/2026 | An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Connectivity Fault Management(CFM) module of Juniper Networks Junos OS on MX Series(except MPC10, MPC11 and LC9600) allows an adjacent attacker on the local broadcast domain to cause a Denial of Service(DoS). Upon receiving a… | |
| Modificada | Media (6.5) | 0.30% | — | Juniper JunosJuniper Junos OS Evolved | 14/7/2023 | 17/6/2026 | An Improper Check or Handling of Exceptional Conditions vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). When a malformed LLDP packet is received, l2cpd will crash and restart.… |