VendorsJuniperjunosany version
Vulnerabilities

Juniper Junos any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

278CVEs
CVE-2025-59962
Junos OS and Junos OS Evolved: With BGP sharding enabled, change in indirect next-hop can cause RPD crash
Published 2025-10-09 · Analyzed
6.0EPSS 0.002
CVE-2016-1262
Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.1X48 before 12.3X48-D20, and 15.1X49 before 15.1X49-D30 on SRX series devices, when the Real Time Streaming Protocol Application Layer Gateway (RTSP ALG) is enabled, allow remote attackers to cause a denial of service (flowd crash) via a crafted RTSP packet.
Published 2016-01-15 · Modified
5.9EPSS 0.015
CVE-2016-1273
Juniper Junos OS before 13.2X51-D40, 14.x before 14.1X53-D30, and 15.x before 15.1X53-D20 on QFX5100 and QFX10002 switches do not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic encryption and authentication protection mechanisms via unspecified vectors.
Published 2016-04-15 · Modified
5.9EPSS 0.007
CVE-2022-22220
Junos OS and Junos OS Evolved: Due to a race condition the rpd process can crash upon receipt of a BGP update message containing flow spec route
Published 2022-10-18 · Modified
5.9EPSS 0.005
CVE-2022-22208
Junos OS and Junos OS Evolved: An rpd crash can occur due to memory corruption caused by flapping BGP sessions
Published 2022-10-18 · Modified
5.9EPSS 0.005
CVE-2023-28961
Junos OS: ACX Series: IPv6 firewall filter is not installed in PFE when "from next-header ah" is used
Published 2023-04-17 · Modified
5.8EPSS 0.004
CVE-2023-36840
Junos OS and Junos OS Evolved: An rpd crash occurs when a specific L2VPN command is run
Published 2023-07-14 · Modified
5.5EPSS 0.002
CVE-2023-36838
Junos OS: SRX Series: A flowd core occurs when running a low privileged CLI command
Published 2023-07-14 · Modified
5.5EPSS 0.002
CVE-2022-22234
Junos OS: EX2300 and EX3400 Series: One of more SFPs might become unavailable when the system is very busy
Published 2022-10-18 · Modified
5.5EPSS 0.002
CVE-2023-22409
Junos OS: SRX Series, MX Series with SPC3: When an inconsistent NAT configuration exists and a specific CLI command is issued the SPC will reboot
Published 2023-01-12 · Modified
5.5EPSS 0.002
CVE-2024-21594
Junos OS: SRX 5000 Series: Repeated execution of a specific CLI command causes a flowd crash
Published 2024-01-12 · Modified
5.5EPSS 0.002
CVE-2023-44193
Junos OS: MX Series: An FPC crash is observed when CFM is enabled in a VPLS scenario and a specific LDP related command is run
Published 2023-10-12 · Modified
5.5EPSS 0.002
CVE-2023-44176
Junos OS : Stack overflow vulnerability in CLI command processing
Published 2023-10-12 · Modified
5.5EPSS 0.002
CVE-2023-44177
Junos OS and Junos OS Evolved: Stack overflow vulnerability in CLI command processing
Published 2023-10-12 · Modified
5.5EPSS 0.002
CVE-2023-44178
Junos OS : Stack overflow vulnerability in CLI command processing
Published 2023-10-12 · Modified
5.5EPSS 0.002
CVE-2023-44201
Junos OS and Junos OS Evolved: A local attacker can retrieve sensitive information and elevate privileges on the device to an authorized user.
Published 2023-10-12 · Modified
5.5EPSS 0.001
CVE-2025-60010
Junos OS and Junos OS Evolved: Device allows login for user with expired password
Published 2025-10-09 · Analyzed
5.4EPSS 0.002
CVE-2023-36846
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
Published 2023-08-17 · Analyzed
5.3KEVEPSS 0.935
CVE-2023-36844
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
Published 2023-08-17 · Analyzed
5.3KEVEPSS 0.900
CVE-2023-36847
Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
Published 2023-08-17 · Analyzed
5.3KEVEPSS 0.835
CVE-2021-31369
Junos OS: MX Series: Traffic drops will be observed if MS-MPC/MS-PIC resources are consumed by certain traffic causing a partial DoS
Published 2021-10-19 · Modified
5.3EPSS 0.010
CVE-2021-31371
Junos OS: QFX5000 Series: Traffic from the network internal to the device (128.0.0.0) may be forwarded to egress interfaces.
Published 2021-10-19 · Modified
5.3EPSS 0.008
CVE-2022-22244
Junos OS: Unauthenticated XPath Injection vulnerability in J-Web
Published 2022-10-18 · Modified
5.3EPSS 0.005
CVE-2023-28963
Junos OS: User-controlled input vulnerability in J-Web
Published 2023-04-17 · Modified
5.3EPSS 0.005
CVE-2024-21610
Junos OS: If in a scaled CoS scenario information on CoS state is gathered mgd processes get stuck
Published 2024-04-12 · Modified
5.3EPSS 0.005
CVE-2026-33799
Junos OS and Junos OS Evolved: Receipt of a specific SNMPv3 request results in memory leak and eventual snmpd crash
Published 2026-07-09 · Analyzed
5.3EPSS 0.004
CVE-2023-44188
Junos OS: jkdsd crash due to multiple telemetry requests
Published 2023-10-11 · Modified
5.3EPSS 0.003
CVE-2024-21607
Junos OS: MX Series and EX9200 Series: If the "tcp-reset" option used in an IPv6 filter, matched packets are accepted instead of rejected
Published 2024-01-12 · Modified
5.3EPSS 0.003
CVE-2013-4689
J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1R before 12.1R6, 12.1X44 before 12.1X44-D15, 12.1x45 before 12.1X45-D10, 12.2 before 12.2R3, 12.3 before 12.3R2, and 13.1 before 13.1R3 allow remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism and hijack the authentication of administrators for requests that (1) create new administrator accounts or (2) have other unspecified impacts.
Published 2013-10-17 · Modified
5.1EPSS 0.010
CVE-2024-21615
Junos OS and Junos OS Evolved: A low-privileged user can access confidential information
Published 2024-04-12 · Analyzed
5.1EPSS 0.002
CVE-2004-0230
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.
Published 2004-05-05 · Analyzed
5.07 PoCEPSS 0.803
CVE-2004-0468
Memory leak in Juniper JUNOS Packet Forwarding Engine (PFE) allows remote attackers to cause a denial of service (memory exhaustion and device reboot) via certain IPv6 packets.
Published 2004-07-08 · Modified
5.0EPSS 0.032
CVE-2023-28979
Junos OS: In a 6PE scenario upon receipt of a specific IPv6 packet an integrity check fails
Published 2023-04-17 · Modified
4.7EPSS 0.003
CVE-2023-28975
Junos OS: The kernel will crash when certain USB devices are inserted
Published 2023-04-17 · Modified
4.6EPSS 0.003
CVE-2013-6015
Juniper Junos before 10.4S14, 11.4 before 11.4R5-S2, 12.1R before 12.1R3, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D15 on SRX Series services gateways, when a plugin using TCP proxy is configured, allows remote attackers to cause a denial of service (flow daemon crash) via an unspecified sequence of TCP packets.
Published 2013-10-17 · Modified
4.3EPSS 0.020
CVE-2022-22245
Junos OS: Path traversal vulnerability in J-Web
Published 2022-10-18 · Modified
4.3EPSS 0.007
CVE-2022-22243
Junos OS: XPath Injection vulnerability in J-Web
Published 2022-10-18 · Modified
4.3EPSS 0.005
CVE-2022-22216
Junos OS: PTX Series and QFX10000 Series: 'Etherleak' memory disclosure in Ethernet padding data
Published 2022-07-20 · Modified
4.3EPSS 0.003
← Prev7 / 7