Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
985 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 83% | ⚠ Explotación activa | Juniper Junos | 17/8/2023 | 17/6/2026 | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication an attacker is able to… | |
| Analizada | Media (5.3) | 93% | ⚠ Explotación activa💥 PoC | Juniper Junos | 17/8/2023 | 17/6/2026 | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication an attacker is able to upload arbitrary… | |
| Analizada | Crítica (9.8) | 95% | ⚠ Explotación activa💥 Exploit | Juniper Junos | 17/8/2023 | 17/6/2026 | A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attacker is able to modify the PHP execution environment allowing the… | |
| Analizada | Media (5.3) | 90% | ⚠ Explotación activa💥 Exploit | Juniper Junos | 17/8/2023 | 17/6/2026 | A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables leading to partial loss of… | |
| Modificada | Media (6.5) | 0.30% | — | Juniper Junos | 14/7/2023 | 17/6/2026 | An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Connectivity Fault Management(CFM) module of Juniper Networks Junos OS on MX Series(except MPC10, MPC11 and LC9600) allows an adjacent attacker on the local broadcast domain to cause a Denial of Service(DoS). Upon receiving a… | |
| Modificada | Media (6.5) | 0.30% | — | Juniper JunosJuniper Junos OS Evolved | 14/7/2023 | 17/6/2026 | An Improper Check or Handling of Exceptional Conditions vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). When a malformed LLDP packet is received, l2cpd will crash and restart.… | |
| Modificada | Media (6.5) | 0.30% | — | Juniper Junos | 14/7/2023 | 17/6/2026 | An Improper Handling of Undefined Values vulnerability in the periodic packet management daemon (PPMD) of Juniper Networks Junos OS on MX Series(except MPC10, MPC11 and LC9600) allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). When a malformed CFM packet is received, it leads to an FPC… | |
| Modificada | Media (5.5) | 0.19% | — | Juniper JunosJuniper Junos OS Evolved | 14/7/2023 | 17/6/2026 | A Reachable Assertion vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a locally-based, low-privileged attacker to cause a Denial of Service (DoS). On all Junos OS and Junos OS Evolved, when a specific L2VPN command is run, RPD will crash and restart. Continued… | |
| Modificada | Media (4.7) | 0.16% | — | Juniper JunosJuniper Junos OS Evolved | 14/7/2023 | 17/6/2026 | A Use of an Uninitialized Resource vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial of Service (DoS). On all Junos OS and Junos OS Evolved platforms, in a Multicast only Fast Reroute (MoFRR)… | |
| Modificada | Alta (7.5) | 0.64% | — | Juniper Junos | 14/7/2023 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on QFX10000 Series allows a network based attacker to cause a Denial of Service (DoS). If a specific valid IP packet is received and that packet needs to be routed over a VXLAN… | |
| Modificada | Media (6.5) | 0.30% | — | Juniper Junos | 14/7/2023 | 17/6/2026 | An Incomplete Internal State Distinction vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX 4600 and SRX 5000 Series allows an adjacent attacker to cause a Denial of Service (DoS). If an SRX is configured in L2 transparent mode the receipt of a specific genuine packet can cause a… | |
| Modificada | Media (5.5) | 0.18% | — | Juniper Junos | 14/7/2023 | 17/6/2026 | An Out-of-bounds Read vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a local, authenticated attacker with low privileges, to cause a Denial of Service (DoS). If a low privileged user executes a specific CLI command, flowd which is responsible for traffic… | |
| Modificada | Media (6.5) | 0.32% | — | Juniper Junos OS Evolved | 14/7/2023 | 17/6/2026 | A Use After Free vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS Evolved on PTX10001-36MR, and PTX10004, PTX10008, PTX10016 with LC1201/1202 allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). The process 'aftman-bt' will crash after multiple flaps on a… | |
| Modificada | Alta (7.5) | 0.63% | — | Juniper Junos | 14/7/2023 | 17/6/2026 | An Improper Validation of Syntactic Correctness of Input vulnerability in Intrusion Detection and Prevention (IDP) of Juniper Networks SRX Series and MX Series allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Continued receipt of this specific packet will cause a sustained Denial of… | |
| Modificada | Alta (7.5) | 0.64% | — | Juniper Junos | 14/7/2023 | 17/6/2026 | An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series allows an unauthenticated network-based attacker to send specific packets to an Aggregated Multiservices (AMS) interface on the device, causing the packet forwarding engine (PFE) to crash,… | |
| Modificada | Alta (7.5) | 0.63% | — | Juniper Junos | 14/7/2023 | 17/6/2026 | An Improper Check or Handling of Exceptional Conditions vulnerability in the UTM (Unified Threat Management) Web-Filtering feature of Juniper Networks Junos OS on SRX Series causes a jbuf memory leak to occur when accessing certain websites, eventually leading to a Denial of Service (DoS) condition. Service… | |
| Modificada | Alta (7.5) | 0.65% | — | Juniper JunosJuniper Junos OS Evolved | 21/6/2023 | 17/6/2026 | An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When a BGP update message is received over an established BGP session, and that message contains a… | |
| Modificada | Media (4.3) | 0.16% | — | ABB Terra AC Wallbox Ul40 FirmwareABB Terra AC Wallbox 80A FirmwareABB Terra AC Wallbox Ul32a FirmwareABB Terra AC Wallbox JP Firmware+4 | 17/5/2023 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (CE) (Terra AC MID), ABB Terra AC wallbox (CE) Terra AC Juno CE, ABB Terra AC wallbox (CE) Terra AC PTB, ABB Terra AC wallbox (CE) Symbiosis, ABB Terra AC wallbox… | |
| Modificada | Alta (8.8) | 0.35% | — | ABB Terra AC Wallbox Ul40 FirmwareABB Terra AC Wallbox 80A FirmwareABB Terra AC Wallbox Ul32a FirmwareABB Terra AC Wallbox JP Firmware+4 | 17/5/2023 | 17/6/2026 | Improper Authentication vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (CE) (Terra AC MID), ABB Terra AC wallbox (CE) Terra AC Juno CE, ABB Terra AC wallbox (CE) Terra AC PTB, ABB Terra AC wallbox (CE) Symbiosis, ABB Terra AC wallbox (JP).This issue affects Terra… | |
| Modificada | Media (5.3) | 0.21% | — | Juniper Junos | 17/4/2023 | 17/6/2026 | A Use After Free vulnerability in the Layer 2 Address Learning Manager (l2alm) of Juniper Networks Junos OS on QFX Series allows an adjacent attacker to cause the Packet Forwarding Engine to crash and restart, leading to a Denial of Service (DoS). The PFE may crash when a lot of MAC learning and aging happens, but due… | |
| Modificada | Alta (8.8) | 1.5% | — | Juniper Junos OS Evolved | 17/4/2023 | 17/6/2026 | An OS Command Injection vulnerability in gRPC Network Operations Interface (gNOI) server module of Juniper Networks Junos OS Evolved allows an authenticated, low privileged, network based attacker to inject shell commands and execute code. This issue affects Juniper Networks Junos OS Evolved 21.4 version 21.4R1-EVO… | |
| Modificada | Alta (7.5) | 0.65% | — | Juniper JunosJuniper Junos OS Evolved | 17/4/2023 | 17/6/2026 | A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). In a BGP rib sharding scenario, when an attribute of an active BGP route is updated… | |
| Modificada | Media (6.5) | 0.30% | — | Juniper JunosJuniper Junos OS Evolved | 17/4/2023 | 17/6/2026 | An Improper Input Validation vulnerability in the kernel of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). If the receipt of router advertisements is enabled on an interface and a specifically malformed RA packet is received, memory… | |
| Modificada | Media (5.5) | 0.17% | — | Juniper JunosJuniper Junos OS Evolved | 17/4/2023 | 17/6/2026 | A Use After Free vulnerability in the routing protocol daemon of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause Denial of Service (DoS). In a rib sharding scenario the rpd process will crash shortly after specific CLI command is issued. This issue is… | |
| Modificada | Media (4.7) | 0.27% | — | Juniper Junos | 17/4/2023 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to bypass an integrity check. In a 6PE scenario and if an additional integrity check is configured, it will fail to drop specific malformed IPv6 packets, and then… |