Juniper records
1,112 published records for vendor juniper.
Researcher profile
- Entered KEV
- 8 · 0.7%
- Weaponized
- 11 · 1%
- Pre-auth RCE
- 41
- With a fix record
- 33.5%
- Median publish → KEV
- 88 days
Recurring classes
- CWE-20 Improper Input Validation93
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')80
- CWE-754 Improper Check for Unusual or Exceptional Conditions68
- CWE-400 Uncontrolled Resource Consumption51
- CWE-401 Missing Release of Memory after Effective Lifetime39
- CWE-755 Improper Handling of Exceptional Conditions36
The weakness classes this vendor ships most often: where to look.
CWEAll records
1,112 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
98Now | CVE-2023-36845Weaponized | Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variablejuniper · junos · CWE-473 | Critical9.8 | KEV | 95.1% | Aug 17, 2023 |
87Now | CVE-2015-7755Weaponized | Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 beforejuniper · screenos · CWE-287 | Critical9.8 | KEV | 61.1% | Dec 19, 2015 |
79This week | CVE-2023-36846Weaponized | Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary filesjuniper · junos · CWE-306 | Medium5.3 | KEV | 93.5% | Aug 17, 2023 |
78This week | CVE-2023-36844Weaponized | Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variablesjuniper · junos · CWE-473 | Medium5.3 | KEV | 90.0% | Aug 17, 2023 |
76This week | CVE-2023-36847Weaponized | Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary filesjuniper · junos · CWE-306 | Medium5.3 | KEV | 83.5% | Aug 17, 2023 |
70This week | CVE-2020-1631Weaponized | Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) servicesjuniper · junos · CWE-22 | Critical9.8 | KEV | 4.8% | May 4, 2020 |
69This week | CVE-2022-42889Weaponized | Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaultsapache · commons text · CWE-94 | Critical9.8 | — | 99.9% | Oct 13, 2022 |
61This week | CVE-2020-10188No exploit | utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, becausnetkit telnet project · netkit telnet · CWE-120 | Critical9.8 | — | 74.3% | Mar 6, 2020 |
61This week | CVE-2008-0960Proof of concept | SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Jnet-snmp · net snmp · CWE-287 | Critical10.0 | — | 68.8% | Jun 10, 2008 |
57Plan | CVE-2025-21590Weaponized | Junos OS: An local attacker with shell access can execute arbitrary codejuniper · junos · CWE-653 | Medium6.7 | KEV | 1.7% | Mar 12, 2025 |
53Plan | CVE-2016-1286No exploit | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure anisc · bind | High8.6 | — | 62.1% | Mar 9, 2016 |
52Plan | CVE-2009-1185Weaponized | udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by senudev project · udev · CWE-346 | High7.2 | — | 80.4% | Apr 17, 2009 |
51Plan | CVE-2023-36851Weaponized | Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary filesjuniper · junos · CWE-306 | Medium5.3 | KEV | 1.1% | Sep 27, 2023 |
50Plan | CVE-2019-11358Proof of concept | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototypjquery · jquery · CWE-1321 | Medium6.1 | — | 87.2% | Apr 19, 2019 |
50Plan | CVE-2006-2086Weaponized | Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juniper NetScreen IVE dejuniper · junipersetup control | High7.5 | — | 67.3% | Apr 29, 2006 |
45Plan | CVE-2016-1285No exploit | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, isc · bind | Medium6.8 | — | 59.1% | Mar 9, 2016 |
44Plan | CVE-2004-0230Proof of concept | TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connectiojuniper · junos | Medium5.0 | — | 80.3% | Aug 18, 2004 |
44Plan | CVE-2024-21591No exploit | Junos OS: SRX Series and EX Series: Security Vulnerability in J-web allows a preAuth Remote Code Executionjuniper · junos · CWE-787 | Critical9.8 | — | 17.5% | Jan 11, 2024 |
42Plan | CVE-2026-21902Proof of concept | Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as rootjuniper · junos os evolved · CWE-732 | Critical9.3 | — | 18.0% | Feb 25, 2026 |
42Plan | CVE-2013-4685No exploit | Buffer overflow in flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7, 12.1 before 12.1R6, and 12.1X44 before 12.1X44-D15 on SRXjuniper · junos · CWE-119 | Critical10.0 | — | 7.6% | Jul 11, 2013 |
42Plan | CVE-2014-0429No exploit | Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote oracle · jrockit | Critical10.0 | — | 7.3% | Apr 15, 2014 |
42Plan | CVE-2014-0456No exploit | Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality,oracle · jrockit | Critical10.0 | — | 6.6% | Apr 15, 2014 |
42Plan | CVE-2014-2421No exploit | Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to aoracle · jrockit | Critical10.0 | — | 6.6% | Apr 15, 2014 |
42Plan | CVE-2014-0457No exploit | Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remooracle · jrockit | Critical10.0 | — | 6.6% | Apr 15, 2014 |
41Plan | CVE-2018-0001No exploit | Junos: Unauthenticated Remote Code Execution through J-Web interfacejuniper · junos · CWE-416 | Critical9.8 | — | 6.3% | Jan 10, 2018 |
- CVE-2023-3684598Now
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
CriticalCVSS 9.8KEVWeaponizedEPSS 95%juniper · junosAug 17, 2023
- CVE-2015-775587Now
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before
CriticalCVSS 9.8KEVWeaponizedEPSS 61%juniper · screenosDec 19, 2015
- CVE-2023-3684679This week
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
MediumCVSS 5.3KEVWeaponizedEPSS 93%juniper · junosAug 17, 2023
- CVE-2023-3684478This week
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
MediumCVSS 5.3KEVWeaponizedEPSS 90%juniper · junosAug 17, 2023
- CVE-2023-3684776This week
Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
MediumCVSS 5.3KEVWeaponizedEPSS 83%juniper · junosAug 17, 2023
- CVE-2020-163170This week
Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services
CriticalCVSS 9.8KEVWeaponizedEPSS 5%juniper · junosMay 4, 2020
- CVE-2022-4288969This week
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
CriticalCVSS 9.8WeaponizedEPSS 100%apache · commons textOct 13, 2022
- CVE-2020-1018861This week
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, becaus
CriticalCVSS 9.8No exploitEPSS 74%netkit telnet project · netkit telnetMar 6, 2020
- CVE-2008-096061This week
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) J
CriticalCVSS 10.0Proof of conceptEPSS 69%net-snmp · net snmpJun 10, 2008
- CVE-2025-2159057Plan
Junos OS: An local attacker with shell access can execute arbitrary code
MediumCVSS 6.7KEVWeaponizedEPSS 2%juniper · junosMar 12, 2025
- CVE-2016-128653Plan
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure an
HighCVSS 8.6No exploitEPSS 62%isc · bindMar 9, 2016
- CVE-2009-118552Plan
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sen
HighCVSS 7.2WeaponizedEPSS 80%udev project · udevApr 17, 2009
- CVE-2023-3685151Plan
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files
MediumCVSS 5.3KEVWeaponizedEPSS 1%juniper · junosSep 27, 2023
- CVE-2019-1135850Plan
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp
MediumCVSS 6.1Proof of conceptEPSS 87%jquery · jqueryApr 19, 2019
- CVE-2006-208650Plan
Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juniper NetScreen IVE de
HighCVSS 7.5WeaponizedEPSS 67%juniper · junipersetup controlApr 29, 2006
- CVE-2016-128545Plan
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages,
MediumCVSS 6.8No exploitEPSS 59%isc · bindMar 9, 2016
- CVE-2004-023044Plan
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connectio
MediumCVSS 5.0Proof of conceptEPSS 80%juniper · junosAug 18, 2004
- CVE-2024-2159144Plan
Junos OS: SRX Series and EX Series: Security Vulnerability in J-web allows a preAuth Remote Code Execution
CriticalCVSS 9.8No exploitEPSS 18%juniper · junosJan 11, 2024
- CVE-2026-2190242Plan
Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root
CriticalCVSS 9.3Proof of conceptEPSS 18%juniper · junos os evolvedFeb 25, 2026
- CVE-2013-468542Plan
Buffer overflow in flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7, 12.1 before 12.1R6, and 12.1X44 before 12.1X44-D15 on SRX
CriticalCVSS 10.0No exploitEPSS 8%juniper · junosJul 11, 2013
- CVE-2014-042942Plan
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote
CriticalCVSS 10.0No exploitEPSS 7%oracle · jrockitApr 15, 2014
- CVE-2014-045642Plan
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality,
CriticalCVSS 10.0No exploitEPSS 7%oracle · jrockitApr 15, 2014
- CVE-2014-242142Plan
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to a
CriticalCVSS 10.0No exploitEPSS 7%oracle · jrockitApr 15, 2014
- CVE-2014-045742Plan
Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remo
CriticalCVSS 10.0No exploitEPSS 7%oracle · jrockitApr 15, 2014
- CVE-2018-000141Plan
Junos: Unauthenticated Remote Code Execution through J-Web interface
CriticalCVSS 9.8No exploitEPSS 6%juniper · junosJan 10, 2018