Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6) | 0.19% | — | Juniper Junos OS Evolved | 9/7/2026 | 13/7/2026 | A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS). When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update… | |
| Analizada | Media (6.9) | 0.30% | — | Juniper Junos OS Evolved | 9/7/2026 | 13/7/2026 | An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion. Due to an incorrect initialization, a process which should only be able to communicate internally within the device,… | |
| Modificada | Media (6.8) | 0.14% | — | Juniper JunosJuniper Junos OS Evolved | 9/7/2026 | 16/7/2026 | A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' or… | |
| Analizada | Media (6.9) | 0.35% | — | Juniper Junos OS Evolved | 9/7/2026 | 13/7/2026 | An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device. Due to a wrong initialization, a process which should only be able… | |
| Analizada | Alta (7.1) | 0.28% | — | Juniper JunosJuniper Junos OS Evolved | 9/7/2026 | 13/7/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a specific BGP update over an established BGP session to cause a Denial-of-Service (DoS). Upon receipt of a… | |
| Analizada | Media (5.3) | 0.37% | — | Juniper JunosJuniper Junos OS Evolved | 9/7/2026 | 13/7/2026 | An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over time, continuous receipt of these queries will result in snmpd process memory exhaustion,… | |
| Analizada | Alta (8.2) | 0.40% | — | Juniper Junos OS Evolved | 9/7/2026 | 13/7/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating continuous routing updates, resulting in unilist ECMP routes, to crash the evo-aftmand… | |
| Analizada | Media (6.7) | 0.17% | — | Juniper JunosJuniper Junos OS Evolved | 9/7/2026 | 26/8/2026 | A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration parameter to create a Denial of Service (DoS). A local high-privileged user configuring or deactivating… | |
| Aplazada | Media (5.2) | 0.28% | — | EvolverAI | 4/5/2026 | 17/6/2026 | Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerability in the mailbox store module allows attackers to modify the behavior of all JavaScript objects by injecting malicious properties into Object.prototype. The vulnerability exists in the _applyUpdate()… | |
| Aplazada | Crítica (9.8) | 2.6% | — | EvolverAI | 4/5/2026 | 17/6/2026 | Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function allows attackers to execute arbitrary shell commands on the server. The function constructs a curl command using string concatenation and passes it to execSync() without… | |
| Aplazada | Alta (8.1) | 0.90% | — | EvolverAI | 4/5/2026 | 17/6/2026 | Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in the skill download (fetch) command allows attackers to write files to arbitrary locations on the filesystem. The --out= flag accepts user-provided paths without validation, enabling directory… | |
| Modificada | Alta (7.1) | 0.27% | — | Juniper JunosJuniper Junos OS Evolved | 9/4/2026 | 17/6/2026 | An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial of Service (DoS). An attacker repeatedly sending the packet… | |
| Analizada | Alta (8.5) | 0.17% | — | Juniper JunosJuniper Junos OS Evolved | 9/4/2026 | 17/6/2026 | An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the system. When a configuration that allows unsigned Python op scripts is present on the device, a… | |
| Modificada | Alta (8.4) | 0.67% | — | Juniper JunosJuniper Junos OS Evolved | 9/4/2026 | 17/6/2026 | An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI commands to inject arbitrary shell commands as root, leading to a complete compromise of the system. Certain 'set system' commands, when… | |
| Analizada | Alta (8.5) | 0.17% | — | Juniper Junos OS Evolved | 9/4/2026 | 22/7/2026 | A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to FPCs installed in the device. A local user with low privileges can gain direct… | |
| Analizada | Alta (7.1) | 0.42% | — | Juniper Junos OS Evolved | 9/4/2026 | 17/6/2026 | A Function Call With Incorrect Argument Type vulnerability in the sensor interface of Juniper Networks Junos OS Evolved on PTX Series allows a network-based, authenticated attacker with low privileges to cause a complete Denial of Service (DoS). If colored SRTE policy tunnels are provisioned via PCEP, and gRPC is used… | |
| Analizada | Alta (7.1) | 0.28% | — | Juniper JunosJuniper Junos OS Evolved | 9/4/2026 | 17/6/2026 | A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a memory leak ultimately leading to a Denial of Service (DoS). In an EVPN-MPLS scenario, routes… | |
| Analizada | Media (6.8) | 0.13% | — | Juniper JunosJuniper Junos OS Evolved | 9/4/2026 | 17/6/2026 | A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a local user with low privileges to read sensitive information. A local user with low privileges can execute the CLI command 'show mgd' with specific arguments which will expose sensitive information. This issue… | |
| Analizada | Alta (7.1) | 0.23% | — | Juniper JunosJuniper Junos OS Evolved | 9/4/2026 | 17/6/2026 | An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker with low privileges to cause a complete Denial-of-Service (DoS) of the management plane. When NETCONF sessions are quickly established and disconnected, a locking… | |
| Analizada | Alta (7.1) | 0.18% | — | Juniper Junos OS Evolved | 9/4/2026 | 30/9/2026 | A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forwarding toolkit (evo-aftmand/evo-pfemand) of Juniper Networks Junos OS Evolved on PTX Series or QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).An attacker sending… | |
| Analizada | Alta (8) | 0.27% | — | Cisco Evolved Programmable Network Manager | 1/4/2026 | 2/7/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access. This vulnerability is due to improper authorization checks on a REST API… | |
| Analizada | Crítica (9.3) | 18% | — | Juniper Junos OS Evolved | 25/2/2026 | 17/6/2026 | An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root. The On-Box Anomaly detection framework should only be reachable by other… | |
| Analizada | Media (6.1) | 0.22% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 4/2/2026 | 29/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in the HTTP… | |
| Analizada | Alta (7.1) | 0.38% | — | Juniper JunosJuniper Junos OS Evolved | 15/1/2026 | 17/6/2026 | A Use After Free vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker authenticated with low privileges to cause a Denial-of-Service (DoS). When telemetry collectors are frequently subscribing and unsubscribing to sensors continuously over a… | |
| Analizada | Alta (7.1) | 0.24% | — | Juniper Junos OS Evolved | 15/1/2026 | 17/6/2026 | An Incorrect Calculation vulnerability in the Layer 2 Control Protocol Daemon (l2cpd) of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker flapping the management interface to cause the learning of new MACs over label-switched interfaces (LSI) to stop while generating a flood of… |