VendorsJuniperjunosany version
Vulnerabilities

Juniper Junos any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

278CVEs
CVE-2016-1279
J-Web in Juniper Junos OS before 12.1X46-D45, 12.1X46-D50, 12.1X47 before 12.1X47-D35, 12.3 before 12.3R12, 12.3X48 before 12.3X48-D25, 13.3 before 13.3R10, 13.3R9 before 13.3R9-S1, 14.1 before 14.1R7, 14.1X53 before 14.1X53-D35, 14.2 before 14.2R6, 15.1 before 15.1A2 or 15.1F4, 15.1X49 before 15.1X49-D30, and 15.1R before 15.1R3 might allow remote attackers to obtain sensitive information and consequently gain administrative privileges via unspecified vectors.
Published 2016-09-09 · Modified
10.0EPSS 0.029
CVE-2020-1614
NFX250 Series: Hardcoded credentials in the vSRX VNF instance.
Published 2020-04-08 · Modified
10.0EPSS 0.014
CVE-2021-0248
NFX Series: Hard-coded credentials allow an attacker to take control of any instance through administrative interfaces.
Published 2021-04-22 · Modified
10.0EPSS 0.010
CVE-2023-36845
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
Published 2023-08-17 · Analyzed
9.8KEVEPSS 0.951
CVE-2024-21591
Junos OS: SRX Series and EX Series: Security Vulnerability in J-web allows a preAuth Remote Code Execution
Published 2024-01-12 · Analyzed
9.8EPSS 0.177
CVE-2019-0008
QFX5000 Series, EX4300, EX4600: A stack buffer overflow vulnerability in Packet Forwarding Engine manager (FXPC) process
Published 2019-04-10 · Modified
9.8EPSS 0.045
CVE-2018-0016
Junos OS: Kernel crash upon receipt of crafted CLNP datagrams
Published 2018-04-11 · Modified
9.8EPSS 0.041
CVE-2018-0044
NFX Series: Insecure sshd configuration in Juniper Device Manager (JDM) and host OS
Published 2018-10-10 · Modified
9.8EPSS 0.013
CVE-2022-22241
Junos OS: Vulnerability in J-Web may allow deserialization without authentication
Published 2022-10-18 · Modified
9.8EPSS 0.012
CVE-2019-0036
Junos OS: Firewall filter terms named "internal-1" and "internal-2" being ignored
Published 2019-04-10 · Modified
9.8EPSS 0.010
CVE-2023-28962
Junos OS: Unauthenticated access vulnerability in J-Web
Published 2023-04-17 · Modified
9.8EPSS 0.006
CVE-2013-6618
jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3, and 12.3 before 12.3R1 allows remote authenticated users to execute arbitrary commands via the rsargs parameter in an exec action.
Published 2013-11-05 · Modified
9.01 PoCEPSS 0.106
CVE-2021-31372
Junos OS: J-Web allows a locally authenticated attacker to escalate their privileges to root.
Published 2021-10-19 · Modified
9.0EPSS 0.012
CVE-2016-1264
Race condition in the Op command in Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D20, 12.3X50 before 12.3X50-D50, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D39, 13.2X52 before 13.2X52-D30, 13.3 before 13.3R7, 14.1 before 14.1R6, 14.1X53 before 14.1X53-D30, 14.2 before 14.2R4, 15.1 before 15.1F2 or 15.1R2, 15.1X49 before 15.1X49-D10 or 15.1X49-D20, and 16.1 before 16.1R1 allows remote authenticated users to gain privileges via the URL option.
Published 2016-04-15 · Modified
8.8EPSS 0.017
CVE-2024-21620
Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS
Published 2024-01-25 · Modified
8.8EPSS 0.009
CVE-2022-22246
Junos OS: PHP file inclusion vulnerability in J-Web
Published 2022-10-18 · Modified
8.8EPSS 0.007
CVE-2023-44182
Junos OS and Junos OS Evolved: An Unchecked Return Value in multiple users interfaces affects confidentiality and integrity of device operations
Published 2023-10-12 · Modified
8.8EPSS 0.006
CVE-2024-39565
Junos OS: J-Web: An unauthenticated, network-based attacker can perform XPATH injection attack against a device.
Published 2024-07-10 · Analyzed
8.8EPSS 0.005
CVE-2019-0070
Junos OS: NFX Series: An Improper Input Validation weakness allows a malicious local attacker to elevate their permissions.
Published 2019-10-09 · Modified
8.8EPSS 0.004
CVE-2024-39547
Junos OS and Junos OS Evolved: cRPD: Receipt of crafted TCP traffic can trigger high CPU utilization
Published 2024-10-11 · Analyzed
8.7EPSS 0.010
CVE-2024-30382
Junos OS and Junos OS Evolved: RPD crash when CoS-based forwarding (CBF) policy is configured
Published 2024-04-12 · Analyzed
8.7EPSS 0.007
CVE-2024-30392
Junos OS: MX Series with SPC3 and MS-MPC/-MIC: When URL filtering is enabled and a specific URL request is received a flowd crash occurs
Published 2024-04-12 · Analyzed
8.7EPSS 0.007
CVE-2024-30394
Junos OS and Junos OS Evolved: A specific EVPN type-5 route causes rpd crash
Published 2024-04-12 · Analyzed
8.7EPSS 0.007
CVE-2024-47499
Junos OS and Junos OS Evolved: In a BMP scenario receipt of a malformed AS PATH attribute can cause an RPD crash
Published 2024-10-11 · Analyzed
8.7EPSS 0.006
CVE-2024-30405
Junos OS: SRX 5000 Series with SPC2: Processing of specific crafted packets when ALG is enabled causes a transit traffic Denial of Service
Published 2024-04-12 · Analyzed
8.7EPSS 0.006
CVE-2024-47497
Junos OS: SRX Series, QFX Series, MX Series and EX Series: Receiving specific HTTPS traffic causes resource exhaustion
Published 2024-10-11 · Analyzed
8.7EPSS 0.006
CVE-2024-39552
Junos OS and Junos OS Evolved: Malformed BGP UPDATE causes RPD crash
Published 2024-07-11 · Analyzed
8.7EPSS 0.006
CVE-2026-21906
Junos OS: SRX Series: With GRE performance acceleration enabled, receipt of a specific ICMP packet causes the PFE to crash
Published 2026-01-15 · Analyzed
8.7EPSS 0.006
CVE-2024-30395
Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash
Published 2024-04-12 · Analyzed
8.7EPSS 0.005
CVE-2024-39555
Junos OS and Junos OS Evolved: Receipt of a specific malformed BGP update causes the session to reset
Published 2024-07-10 · Analyzed
8.7EPSS 0.005
CVE-2024-39545
Junos OS: SRX Series, MX Series with SPC3 and NFX350: When VPN tunnels parameters are not configured in specific way the iked process will crash
Published 2024-07-11 · Analyzed
8.7EPSS 0.005
CVE-2024-39529
Junos OS: SRX Series: If DNS traceoptions are configured in a DGA or tunnel detection scenario specific DNS traffic leads to a PFE crash
Published 2024-07-11 · Modified
8.7EPSS 0.005
CVE-2024-39549
Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to a memory leak
Published 2024-07-11 · Modified
8.7EPSS 0.005
CVE-2026-57026
Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash
Published 2026-07-09 · Analyzed
8.7EPSS 0.005
CVE-2024-39515
Junos OS and Junos OS Evolved: With BGP traceoptions enabled, receipt of specifically malformed BGP update causes RPD crash
Published 2024-10-09 · Analyzed
8.7EPSS 0.005
CVE-2025-52981
Junos OS: SRX Series: Sequence of specific PIM packets causes a flowd crash
Published 2025-07-11 · Analyzed
8.7EPSS 0.004
CVE-2025-52946
Junos OS and Junos OS Evolved: With traceoptions enabled, receipt of malformed AS PATH causes RPD crash
Published 2025-07-11 · Analyzed
8.7EPSS 0.004
CVE-2024-39525
Junos OS and Junos OS Evolved: When BGP traceoptions is enabled, receipt of specially crafted BGP packet causes RPD crash
Published 2024-10-09 · Analyzed
8.7EPSS 0.004
CVE-2024-39516
Junos OS and Junos OS Evolved: With certain BGP options enabled, receipt of specifically malformed BGP update causes RPD crash
Published 2024-10-09 · Analyzed
8.7EPSS 0.004
CVE-2024-39564
Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to RPD crash
Published 2025-02-05 · Analyzed
8.7EPSS 0.004
1 / 7Next →