Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3076▲ 446 respecto a la semana anterior
Críticas / altas1457▲ 26 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1118 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.4) | 0.67% | — | Juniper JunosJuniper Junos OS Evolved | 9/4/2026 | 17/6/2026 | An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI commands to inject arbitrary shell commands as root, leading to a complete compromise of the system. Certain 'set system' commands, when… | |
| Analizada | Alta (8.7) | 0.46% | — | Juniper Junos | 9/4/2026 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker sending a specific, malformed ICMPv6 packet to cause the srxpfe process to crash and restart. Continued receipt and processing of these packets will repeatedly… | |
| Analizada | Alta (8.5) | 0.17% | — | Juniper Junos OS Evolved | 9/4/2026 | 22/7/2026 | A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to FPCs installed in the device. A local user with low privileges can gain direct… | |
| Analizada | Media (6.8) | 0.13% | — | Juniper Junos | 9/4/2026 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1500, SRX4100, SRX4200 and SRX4600 allows a local attacker with low privileges to cause a complete Denial of Service (DoS). When a specific 'show chassis' CLI command is… | |
| Analizada | Media (6.8) | 0.13% | — | Juniper Junos | 9/4/2026 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local attacker with low privileges to cause a complete Denial of Service (DoS). When a specific 'show chassis' CLI command is executed,… | |
| Analizada | Media (6.3) | 0.14% | — | Juniper Junos | 9/4/2026 | 17/6/2026 | A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific commands which will lead to a complete compromise of managed devices. Any user logged in, without requiring specific privileges, can issue 'request csds'… | |
| Analizada | Crítica (9.3) | 0.48% | — | Juniper Virtual Lightweight Collector | 9/4/2026 | 8/7/2026 | A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device. vLWC software images ship with an initial password for a high privileged account. A change of this password… | |
| Analizada | Alta (7.1) | 0.42% | — | Juniper Junos OS Evolved | 9/4/2026 | 17/6/2026 | A Function Call With Incorrect Argument Type vulnerability in the sensor interface of Juniper Networks Junos OS Evolved on PTX Series allows a network-based, authenticated attacker with low privileges to cause a complete Denial of Service (DoS). If colored SRTE policy tunnels are provisioned via PCEP, and gRPC is used… | |
| Analizada | Alta (8.7) | 0.55% | — | Juniper Junos | 9/4/2026 | 17/6/2026 | A Missing Release of Memory after Effective Lifetime vulnerability in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS on MX Series, allows an adjacent, unauthenticated attacker to cause a memory leak, that will eventually cause a complete Denial-of-Service (DoS). In a DHCPv6 over PPPoE, or DHCPv6 over VLAN with… | |
| Analizada | Alta (7.1) | 0.27% | — | Juniper Junos | 9/4/2026 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX and QFX Series devices allow an unauthenticated, adjacent attacker to cause a complete Denial of Service (DoS). On EX4k, and QFX5k platforms configured as… | |
| Analizada | Alta (7.1) | 0.28% | — | Juniper JunosJuniper Junos OS Evolved | 9/4/2026 | 17/6/2026 | A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a memory leak ultimately leading to a Denial of Service (DoS). In an EVPN-MPLS scenario, routes… | |
| Analizada | Alta (8.3) | 0.18% | — | Juniper Junos | 9/4/2026 | 17/6/2026 | An Improper Following of a Certificate's Chain of Trust vulnerability in J-Web of Juniper Networks Junos OS on SRX Series allows a PITM to intercept the communication of the device and get access to confidential information and potentially modify it. When an SRX device is provisioned to connect to Security Director… | |
| Analizada | Alta (8.7) | 0.46% | — | Juniper Junos | 9/4/2026 | 17/6/2026 | An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a complete Denial-of-Service (DoS). If an affected device receives a specifically… | |
| Analizada | Media (6.8) | 0.13% | — | Juniper JunosJuniper Junos OS Evolved | 9/4/2026 | 17/6/2026 | A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a local user with low privileges to read sensitive information. A local user with low privileges can execute the CLI command 'show mgd' with specific arguments which will expose sensitive information. This issue… | |
| Analizada | Alta (7.1) | 0.32% | — | Juniper Junos | 9/4/2026 | 17/6/2026 | A Missing Release of Memory after Effective Lifetime vulnerability in the BroadBand Edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). If the authentication packet-type option is configured and a… | |
| Analizada | Media (6.9) | 0.29% | — | Juniper Junos | 9/4/2026 | 8/7/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the configured firewall filter and access the control-plane of the device. On MX platforms with MPC10, MPC11,… | |
| Analizada | Media (6.9) | 0.31% | — | Juniper Junos | 9/4/2026 | 17/6/2026 | An Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series and QFX Series device allows an unauthenticated, network-based attacker to cause an integrity impact to downstream networks. When the same family inet or inet6 filter is… | |
| Analizada | Crítica (9.1) | 0.39% | — | Juniper CTP Operating System | 9/4/2026 | 13/7/2026 | A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device. The password management menu enables the administrator to set… | |
| Analizada | Alta (7.1) | 0.23% | — | Juniper JunosJuniper Junos OS Evolved | 9/4/2026 | 17/6/2026 | An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker with low privileges to cause a complete Denial-of-Service (DoS) of the management plane. When NETCONF sessions are quickly established and disconnected, a locking… | |
| Analizada | Alta (7) | 0.13% | — | Juniper Junos | 9/4/2026 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in the CLI of Juniper Networks Junos OS allows a local, authenticated attacker with low privileges to escalate their privileges to root which will lead to a complete compromise of the system. When after a user has performed a specific 'file link ...' CLI… | |
| Analizada | Alta (8.4) | 2.2% | — | Juniper Virtual Lightweight Collector | 9/4/2026 | 8/7/2026 | A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged attacker to escalate their privileges to root. The CLI menu accepts input without carefully validating it, which allows for shell command… | |
| Analizada | Media (5.1) | 0.21% | — | Juniper Junos Space | 9/4/2026 | 8/7/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the list filter field that, when visited by another user, enables the attacker to execute commands with the target's permissions, including… | |
| Analizada | Alta (7.1) | 0.18% | — | Juniper Junos OS Evolved | 9/4/2026 | 7/10/2026 | Una vulnerabilidad de copia de búfer sin verificar el tamaño de la entrada ('desbordamiento de búfer clásico') en el kit de herramientas de reenvío avanzado (evo-aftmand/evo-pfemand) de Juniper Networks Junos OS Evolved en las series PTX o QFX5000 permite a un atacante adyacente no autenticado causar una denegación de… | |
| Analizada | Alta (7) | 0.30% | — | Juniper Apstra | 9/4/2026 | 7/10/2026 | Una vulnerabilidad de intercambio de claves sin autenticación de entidad en la implementación SSH de Juniper Networks Apstra permite a un atacante no autenticado, MitM, suplantar dispositivos gestionados. Debido a una validación insuficiente de la clave de host SSH, un atacante puede realizar un ataque MitM en las… | |
| Analizada | Alta (8.4) | 0.14% | — | Juniper Junos | 8/4/2026 | 26/8/2026 | Una vulnerabilidad de autenticación faltante para función crítica en el procesamiento de comandos de Juniper Networks Junos OS permite a un atacante local privilegiado obtener acceso a las tarjetas de línea que ejecutan Junos OS Evolved como root. |