Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
976 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.52% | — | Juniper Junos OS Evolved | 13/1/2023 | 17/6/2026 | A Use After Free vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). In a Non Stop Routing (NSR) scenario, an unexpected kernel restart might be observed if "bgp auto-discovery" is enabled and if there is a BGP neighbor… | |
| Modificada | Alta (7.5) | 0.62% | — | Juniper JunosJuniper Junos OS Evolved | 13/1/2023 | 17/6/2026 | An Improper Validation of Array Index vulnerability in the Advanced Forwarding Toolkit Manager daemon (aftmand) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On the PTX10008 and PTX10016 platforms running Junos OS or Junos OS… | |
| Modificada | Alta (7.5) | 0.62% | — | Juniper Junos OS Evolved | 13/1/2023 | 17/6/2026 | An Uncontrolled Resource Consumption vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS). When a specific SNMP GET operation or a specific CLI command is executed this… | |
| Modificada | Alta (7.5) | 0.64% | — | Juniper Junos | 13/1/2023 | 17/6/2026 | When sFlow is enabled and it monitors a packet forwarded via ECMP, a buffer management vulnerability in the dcpfe process of Juniper Networks Junos OS on QFX10K Series systems allows an attacker to cause the Packet Forwarding Engine (PFE) to crash and restart by sending specific genuine packets to the device,… | |
| Modificada | Media (5.5) | 0.17% | — | Juniper JunosJuniper Junos OS Evolved | 13/1/2023 | 17/6/2026 | An Access of Uninitialized Pointer vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). When an MPLS ping is performed on BGP LSPs, the RPD might crash. Repeated execution of… | |
| Modificada | Media (6.1) | 0.18% | — | Juniper Junos OS Evolved | 13/1/2023 | 17/6/2026 | An Allocation of Resources Without Limits or Throttling weakness in the memory management of the Packet Forwarding Engine (PFE) on Juniper Networks Junos OS Evolved PTX10003 Series devices allows an adjacently located attacker who has established certain preconditions and knowledge of the environment to send certain… | |
| Modificada | Alta (7.5) | 0.56% | — | Juniper Junos | 13/1/2023 | 17/6/2026 | An Uncontrolled Resource Consumption vulnerability in TCP processing on the Routing Engine (RE) of Juniper Networks Junos OS allows an unauthenticated network-based attacker to send crafted TCP packets destined to the device, resulting in an MBUF leak that ultimately leads to a Denial of Service (DoS). The system does… | |
| Modificada | Media (6.5) | 0.30% | — | Juniper Junos | 13/1/2023 | 17/6/2026 | A Missing Release of Memory after Effective Lifetime vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). In an MPLS scenario specific packets destined to an Integrated Routing and Bridging (irb) interface of the device will cause a… | |
| Modificada | Alta (7.5) | 0.62% | — | Juniper Junos | 13/1/2023 | 17/6/2026 | An Improper Handling of Unexpected Data Type vulnerability in the handling of SIP calls in Juniper Networks Junos OS on SRX Series and MX Series platforms allows an attacker to cause a memory leak leading to Denial of Services (DoS). This issue occurs on all MX Series platforms with MS-MPC or MS-MIC card and all SRX… | |
| Modificada | Alta (7.5) | 0.62% | — | Juniper JunosJuniper Junos OS Evolved | 13/1/2023 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in BGP route processing of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to cause Routing Protocol Daemon (RPD) crash by sending a BGP route with invalid next-hop resulting in a Denial of Service (DoS). Continued receipt and… | |
| Modificada | Alta (7.5) | 0.62% | — | Juniper Junos | 13/1/2023 | 17/6/2026 | A vulnerability in class-of-service (CoS) queue management in Juniper Networks Junos OS on the ACX2K Series devices allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). Specific packets are being incorrectly routed to a queue used for other high-priority traffic such as BGP, PIM, ICMP,… | |
| Modificada | Alta (7.5) | 0.68% | — | Juniper JunosJuniper Junos OS Evolved | 22/12/2022 | 17/6/2026 | An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). If a BGP update message is received over an established BGP session, and that message contains a… | |
| Modificada | Alta (7.8) | 0.16% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | On cSRX Series devices software permission issues in the container filesystem and stored files combined with storing passwords in a recoverable format in Juniper Networks Junos OS allows a local, low-privileged attacker to elevate their permissions to take control of any instance of a cSRX software deployment. This… | |
| Modificada | Media (6.5) | 0.31% | — | Juniper JunosJuniper Junos OS Evolved | 18/10/2022 | 17/6/2026 | An Improper Control of a Resource Through its Lifetime vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS and Junos OS Evolved allows unauthenticated adjacent attacker to cause a Denial of Service (DoS). In an EVPN-MPLS scenario, if MAC is learned locally on an access interface but later a… | |
| Modificada | Media (6.5) | 0.46% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | An Improper Control of a Resource Through its Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). When there is a continuous mac move a memory corruption causes one or more FPCs to crash… | |
| Modificada | Alta (7.3) | 0.19% | — | Juniper Junos OS Evolved | 18/10/2022 | 17/6/2026 | An Incorrect Permission Assignment vulnerability in shell processing of Juniper Networks Junos OS Evolved allows a low-privileged local user to modify the contents of a configuration file which could cause another user to execute arbitrary commands within the context of the follow-on user's session. If the follow-on… | |
| Modificada | Alta (7.5) | 0.62% | — | Juniper Junos OS Evolved | 18/10/2022 | 17/6/2026 | An Improper Input Validation vulnerability in ingress TCP segment processing of Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker to send a crafted TCP segment to the device, triggering a kernel panic, leading to a Denial of Service (DoS) condition. Continued receipt and processing of… | |
| Modificada | Alta (8.8) | 0.69% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | A PHP Local File Inclusion (LFI) vulnerability in the J-Web component of Juniper Networks Junos OS may allow a low-privileged authenticated attacker to execute an untrusted PHP file. By chaining this vulnerability with other unspecified vulnerabilities, and by circumventing existing attack requirements, successful… | |
| Modificada | Media (4.3) | 0.68% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | A Path Traversal vulnerability in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to upload arbitrary files to the device by bypassing validation checks built into Junos OS. The attacker should not be able to execute the file due to validation checks built into Junos OS. Successful… | |
| Modificada | Media (5.3) | 0.54% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | An XPath Injection vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker sending a crafted POST to reach the XPath channel, which may allow chaining to other unspecified vulnerabilities, leading to a partial loss of confidentiality. This issue affects Juniper Networks… | |
| Modificada | Media (4.3) | 0.48% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | An XPath Injection vulnerability due to Improper Input Validation in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to add an XPath command to the XPath stream, which may allow chaining to other unspecified vulnerabilities, leading to a partial loss of confidentiality. This issue… | |
| Modificada | Media (6.1) | 2.8% | 💥 Exploit | Juniper Junos | 18/10/2022 | 17/6/2026 | A Cross-site Scripting (XSS) vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker to run malicious scripts reflected off of J-Web to the victim's browser in the context of their session within J-Web. This issue affects Juniper Networks Junos OS all versions prior to… | |
| Modificada | Crítica (9.8) | 1.2% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data without proper authorization. Utilizing a crafted POST request, deserialization may occur which could lead to unauthorized local file access or the ability to execute… | |
| Modificada | Media (5.5) | 0.20% | — | Juniper JunosJuniper Junos OS Evolved | 18/10/2022 | 17/6/2026 | An Allocation of Resources Without Limits or Throttling and a Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated low privileged attacker to cause a Denial of Sevice (DoS). In a… | |
| Modificada | Alta (8.8) | 0.18% | — | Juniper Junos OS Evolved | 18/10/2022 | 17/6/2026 | An Execution with Unnecessary Privileges vulnerability in Management Daemon (mgd) of Juniper Networks Junos OS Evolved allows a locally authenticated attacker with low privileges to escalate their privileges on the device and potentially remote systems. This vulnerability allows a locally authenticated attacker with… |