Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
248 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.26% | — | Juniper JunosJuniper Junos OS Evolved | 15/1/2026 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a DHCP client in one subnet to exhaust the address pools of other subnets, leading to a Denial of Service (DoS) on the downstream DHCP server. By default,… | |
| Analizada | Media (6.8) | 0.15% | — | Juniper JunosJuniper Junos OS Evolved | 15/1/2026 | 17/6/2026 | An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial-of-Service (DoS). When the command 'show route < ( receive-protocol | advertising-protocol ) bgp > detail'… | |
| Analizada | Media (5.3) | 0.18% | — | Juniper JunosJuniper Junos OS Evolved | 9/10/2025 | 17/6/2026 | A password aging vulnerability in the RADIUS client of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker to access the device without enforcing the required password change. Affected devices allow logins by users for whom the RADIUS server has responded with a reject and… | |
| Analizada | Alta (8.7) | 0.42% | — | Juniper JunosJuniper Junos OS Evolved | 9/10/2025 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-Of-Service (DoS). When an affected system receives a specific BGP EVPN update message over an… | |
| Analizada | Alta (7.1) | 0.20% | — | Juniper Junos OS Evolved | 9/10/2025 | 17/6/2026 | A NULL Pointer Dereference vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved on ACX7024, ACX7024X, ACX7100-32C, ACX7100-48L, ACX7348, ACX7509 devices allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). Whenever specific valid multicast traffic is… | |
| Analizada | Media (6) | 0.18% | — | Juniper JunosJuniper Junos OS Evolved | 9/10/2025 | 17/6/2026 | An Access of Uninitialized Pointer vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved with BGP sharding configured allows an attacker triggering indirect next-hop updates, along with timing outside the attacker's control, to cause rpd to crash and restart, leading to a… | |
| Analizada | Media (6.9) | 0.28% | — | Juniper Junos OS Evolved | 9/10/2025 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to cause impact to confidentiality and availability. When an output firewall filter is configured with one or… | |
| Analizada | Alta (7.1) | 0.48% | — | Juniper Junos OS Evolved | 9/10/2025 | 17/6/2026 | An Uncontrolled Resource Consumption vulnerability in the Connectivity Fault Management (CFM) daemon and the Connectivity Fault Management Manager (cfmman) of Juniper Networks Junos OS Evolved on PTX10001-36MR, PTX10002-36QDD, PTX10004, PTX10008, PTX10016 allows an unauthenticated, adjacent attacker to cause a… | |
| Analizada | Media (4.8) | 0.99% | — | Juniper Junos OS Evolved | 9/10/2025 | 30/9/2026 | Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS Evolved could be used to elevate privileges and/or execute unauthorized commands. When an attacker executes crafted CLI commands, the options are… | |
| Analizada | Media (6.8) | 0.13% | — | Juniper JunosJuniper Junos OS Evolved | 11/7/2025 | 17/6/2026 | An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration. A user with limited configuration and commit permissions, using a specifically crafted annotate… | |
| Analizada | Alta (8.4) | 0.45% | — | Juniper JunosJuniper Junos OS Evolved | 11/7/2025 | 17/6/2026 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a high privileged, local attacker to escalated their privileges to root. When a user provides specifically crafted arguments to the 'request… | |
| Analizada | Media (6.8) | 0.12% | — | Juniper JunosJuniper Junos OS Evolved | 11/7/2025 | 17/6/2026 | A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low privileged user to cause an impact to the availability of the device. When RIB sharding is enabled and a user executes one of several routing… | |
| Analizada | Media (6.9) | 0.28% | — | Juniper Junos OS Evolved | 11/7/2025 | 17/6/2026 | A Use of Incorrect Operator vulnerability in the Routing Engine firewall of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to bypass security restrictions. When a firewall filter which is applied to the lo0 or re:mgmt interface references a prefix list with 'from prefix-list', and… | |
| Analizada | Alta (8.2) | 0.45% | — | Juniper JunosJuniper Junos OS Evolved | 11/7/2025 | 17/6/2026 | A NULL Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause impact to the availability of the device. When static route points to a reject next hop and a gNMI query is processed for that… | |
| Analizada | Alta (7.1) | 0.28% | — | Juniper JunosJuniper Junos OS Evolved | 11/7/2025 | 17/6/2026 | A Reachable Assertion vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When the device receives a specific BGP UPDATE packet, the rpd crashes and restarts. Continuous receipt of… | |
| Analizada | Media (6) | 0.23% | — | Juniper JunosJuniper Junos OS Evolved | 11/7/2025 | 17/6/2026 | A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS).On all Junos OS and Junos OS Evolved devices, when route validation is enabled, a rare condition during BGP initial… | |
| Analizada | Alta (7.1) | 0.29% | — | Juniper JunosJuniper Junos OS Evolved | 11/7/2025 | 17/6/2026 | An Incorrect Calculation of Buffer Size vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause a memory corruption that leads to a rpd crash. When the logical interface using a routing instance flaps continuously,… | |
| Analizada | Alta (8.5) | 0.16% | — | Juniper Junos OS Evolved | 11/7/2025 | 17/6/2026 | A Missing Authorization vulnerability in the internal virtual routing and forwarding (VRF) of Juniper Networks Junos OS Evolved allows a local, low-privileged user to gain root privileges, leading to a system compromise. Any low-privileged user with the capability to send packets over the internal VRF can execute… | |
| Analizada | Alta (7.1) | 0.30% | — | Juniper JunosJuniper Junos OS Evolved | 11/7/2025 | 17/6/2026 | An Expected Behavior Violation vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sending a valid BGP UPDATE packet to cause a BGP session reset, resulting in a Denial of Service (DoS). Continuous receipt and processing of… | |
| Analizada | Alta (7.1) | 0.30% | — | Juniper JunosJuniper Junos OS Evolved | 11/7/2025 | 17/6/2026 | An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a logically adjacent BGP peer sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS).… | |
| Analizada | Alta (8.7) | 0.48% | — | Juniper JunosJuniper Junos OS Evolved | 11/7/2025 | 17/6/2026 | A Use After Free vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an attacker sending a BGP update with a specifically malformed AS PATH to cause rpd to crash, resulting in a Denial of Service (DoS). Continuous receipt of the malformed AS PATH… | |
| Analizada | Media (6.8) | 0.15% | — | Juniper JunosJuniper Junos OS Evolved | 9/4/2025 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to cause a Denial-of-Service (DoS). When a specific "show bgp neighbor" CLI command is run, the rpd cpu utilization rises… | |
| Analizada | Media (6.8) | 0.17% | — | Juniper JunosJuniper Junos OS Evolved | 9/4/2025 | 17/6/2026 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged, authenticated attacker with access to the CLI to access sensitive information. Through the execution of a specific show mgd command, a… | |
| Analizada | Media (6) | 0.24% | — | Juniper JunosJuniper Junos OS Evolved | 9/4/2025 | 17/6/2026 | An Expired Pointer Dereference vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause Denial of Service (DoS).On all Junos OS and Junos OS Evolved platforms, when an MPLS Label-Switched Path (LSP) is configured with… | |
| Analizada | Media (6.8) | 0.16% | — | Juniper JunosJuniper Junos OS Evolved | 9/4/2025 | 17/6/2026 | An Improper Handling of Exceptional Conditions vulnerability in routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker executing a CLI command to cause a Denial of Service (DoS). When asregex-optimized is configured and a specific "show route as-path"… |