Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
985 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.69% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | A PHP Local File Inclusion (LFI) vulnerability in the J-Web component of Juniper Networks Junos OS may allow a low-privileged authenticated attacker to execute an untrusted PHP file. By chaining this vulnerability with other unspecified vulnerabilities, and by circumventing existing attack requirements, successful… | |
| Modificada | Media (4.3) | 0.68% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | A Path Traversal vulnerability in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to upload arbitrary files to the device by bypassing validation checks built into Junos OS. The attacker should not be able to execute the file due to validation checks built into Junos OS. Successful… | |
| Modificada | Media (5.3) | 0.54% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | An XPath Injection vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker sending a crafted POST to reach the XPath channel, which may allow chaining to other unspecified vulnerabilities, leading to a partial loss of confidentiality. This issue affects Juniper Networks… | |
| Modificada | Media (4.3) | 0.48% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | An XPath Injection vulnerability due to Improper Input Validation in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to add an XPath command to the XPath stream, which may allow chaining to other unspecified vulnerabilities, leading to a partial loss of confidentiality. This issue… | |
| Modificada | Media (6.1) | 2.8% | 💥 Exploit | Juniper Junos | 18/10/2022 | 17/6/2026 | A Cross-site Scripting (XSS) vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker to run malicious scripts reflected off of J-Web to the victim's browser in the context of their session within J-Web. This issue affects Juniper Networks Junos OS all versions prior to… | |
| Modificada | Crítica (9.8) | 1.2% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data without proper authorization. Utilizing a crafted POST request, deserialization may occur which could lead to unauthorized local file access or the ability to execute… | |
| Modificada | Media (5.5) | 0.20% | — | Juniper JunosJuniper Junos OS Evolved | 18/10/2022 | 17/6/2026 | An Allocation of Resources Without Limits or Throttling and a Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated low privileged attacker to cause a Denial of Sevice (DoS). In a… | |
| Modificada | Alta (8.8) | 0.18% | — | Juniper Junos OS Evolved | 18/10/2022 | 17/6/2026 | An Execution with Unnecessary Privileges vulnerability in Management Daemon (mgd) of Juniper Networks Junos OS Evolved allows a locally authenticated attacker with low privileges to escalate their privileges on the device and potentially remote systems. This vulnerability allows a locally authenticated attacker with… | |
| Modificada | Media (6.5) | 0.29% | — | Juniper JunosJuniper Junos OS Evolved | 18/10/2022 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). When an incoming RESV message corresponding to a protected LSP is malformed it… | |
| Modificada | Media (6.5) | 0.44% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | An Improper Authentication vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause an impact on confidentiality or integrity. A vulnerability in the processing of TCP-AO will allow a BGP or LDP peer not configured with authentication to establish a session… | |
| Modificada | Alta (7.5) | 0.67% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | An Access of Uninitialized Pointer vulnerability in SIP Application Layer Gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When specific valid SIP packets are received the PFE will crash and restart. This issue… | |
| Modificada | Alta (7.5) | 0.64% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based, attacker to cause Denial of Service (DoS). A PFE crash will happen when a GPRS Tunnel Protocol (GTP) packet is received with a… | |
| Modificada | Media (5.5) | 0.18% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | An Improper Preservation of Consistency Between Independent Representations of Shared State vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). If the device is very busy for example while… | |
| Modificada | Media (5.5) | 0.18% | — | Juniper JunosJuniper Junos OS Evolved | 18/10/2022 | 17/6/2026 | An Unchecked Return Value to NULL Pointer Dereference vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). In Segment Routing (SR) to Label Distribution Protocol (LDP)… | |
| Modificada | Alta (7.5) | 0.67% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On SRX Series If Unified Threat Management (UTM) Enhanced Content Filtering (CF) is enabled and specific transit… | |
| Modificada | Alta (7.5) | 0.67% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | An Unchecked Return Value to NULL Pointer Dereference vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On SRX Series if Unified Threat Management (UTM) Enhanced Content Filtering (CF) and AntiVirus (AV)… | |
| Modificada | Media (6.5) | 0.32% | — | Juniper JunosJuniper Junos OS Evolved | 18/10/2022 | 17/6/2026 | An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause DoS (Denial of Service). If another router generates more than one specific valid OSPFv3 LSA then rpd will crash while processing these… | |
| Modificada | Alta (7.5) | 0.67% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | An Improper Validation of Specified Type of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS allows an attacker to cause an RPD memory leak leading to a Denial of Service (DoS). This memory leak only occurs when the attacker's packets are destined to any configured IPv6 address on… | |
| Modificada | Media (5.3) | 0.61% | — | Juniper Junos OS Evolved | 18/10/2022 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX7000 Series allows an unauthenticated network-based attacker to cause a partial Denial of Service (DoS). On receipt of specific IPv6 transit traffic, Junos OS Evolved… | |
| Modificada | Media (6.5) | 0.32% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | In VxLAN scenarios on EX4300-MP, EX4600, QFX5000 Series devices an Uncontrolled Memory Allocation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated adjacently located attacker sending specific packets to cause a Denial of Service (DoS) condition by crashing one… | |
| Modificada | Media (5.9) | 0.48% | — | Juniper JunosJuniper Junos OS Evolved | 18/10/2022 | 17/6/2026 | A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated attacker with an established BGP session to cause a Denial of Service (DoS). In a BGP multipath scenario, when one of the contributing… | |
| Modificada | Media (6.5) | 0.31% | — | Juniper JunosJuniper Junos OS Evolved | 18/10/2022 | 17/6/2026 | An Improper Check or Handling of Exceptional Conditions vulnerability in the processing of a malformed OSPF TLV in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause the periodic packet management daemon (PPMD) process to go into an infinite loop, which in turn can… | |
| Modificada | Alta (7.5) | 0.82% | — | Juniper Junos | 18/10/2022 | 17/6/2026 | On QFX10000 Series devices using Juniper Networks Junos OS when configured as transit IP/MPLS penultimate hop popping (PHP) nodes with link aggregation group (LAG) interfaces, an Improper Validation of Specified Index, Position, or Offset in Input weakness allows an attacker sending certain IP packets to cause… | |
| Modificada | Media (5.9) | 0.48% | — | Juniper JunosJuniper Junos OS Evolved | 18/10/2022 | 17/6/2026 | A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS, Junos OS Evolved allows a network-based unauthenticated attacker to cause a Denial of Service (DoS). When a BGP flow route with redirect IP extended community is received, and the… | |
| Modificada | Media (5.9) | 0.61% | — | Juniper JunosJuniper Junos OS Evolved | 18/10/2022 | 17/6/2026 | Due to the Improper Handling of an Unexpected Data Type in the processing of EVPN routes on Juniper Networks Junos OS and Junos OS Evolved, an attacker in direct control of a BGP client connected to a route reflector, or via a machine in the middle (MITM) attack, can send a specific EVPN route contained within a BGP… |