VendorsJuniperjunos_spaceall versions
Vulnerabilities

Juniper Junos Space

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

79CVEs
CVE-2025-59983
Junos Space: Template Definition page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.003
CVE-2025-59999
Junos Space: API Access Profiles page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59989
Junos Space: Device Discovery page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-60002
Junos Space: Template Definitions page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59994
Junos Space: Quick Template page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59995
Junos Space: Template creation through Definition is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59996
Junos Space: Configuration View page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59997
Junos Space: Fields in the CLI Configlets are vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59998
Junos Space: Archive Logs screen is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-60000
Junos Space: Generate Report page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-60001
Junos Space: Create Quick Template page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-60009
Junos Space: CLI Configlet page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59985
Junos Space: Purging Policy field is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59992
Junos Space: Secure Console page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59991
Junos Space: Device Management pages are vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59990
Junos Space: Template creation pages are vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59988
Junos Space: Generate Report page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59987
Junos Space: The arbitrary device search field is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59986
Junos Space: Input fields in Model Devices are vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59984
Junos Space: Global Search is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59993
Junos Space: Space Node Setting fields are vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2026-21904
Junos Space: ilpFilter field on nLegacy.jsp is vulnerable to reflected cross-site script injection
Published 2026-04-09 · Analyzed
6.1EPSS 0.002
CVE-2017-2309
On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is enabled for the Junos Space cluster, some restricted web services are accessible over the network. This represents an information leak risk.
Published 2017-05-30 · Modified
5.9EPSS 0.008
CVE-2014-0460
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via vectors related to JNDI.
Published 2014-04-16 · Modified
5.8EPSS 0.044
CVE-2015-0501
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Compiling.
Published 2015-04-16 · Modified
5.7EPSS 0.099
CVE-2018-0011
Junos Space: Reflected XSS vulnerability in Junos Space management interface
Published 2018-01-10 · Modified
5.4EPSS 0.008
CVE-2017-2311
On Juniper Networks Junos Space versions prior to 16.1R1, an unauthenticated remote attacker with network access to Junos space device can easily create a denial of service condition.
Published 2017-05-30 · Modified
5.3EPSS 0.013
CVE-2017-2310
A firewall bypass vulnerability in the host based firewall of Juniper Networks Junos Space versions prior to 16.1R1 may permit certain crafted packets, representing a network integrity risk.
Published 2017-05-30 · Modified
5.3EPSS 0.012
CVE-2013-3497
Juniper Junos Space before 12.3P2.8, as used on the JA1500 appliance and in other contexts, includes a cleartext password in a configuration tab, which makes it easier for physically proximate attackers to obtain the password by reading the workstation screen.
Published 2013-05-08 · Modified
4.7EPSS 0.003
CVE-2014-6494
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6496.
Published 2014-10-15 · Modified
4.3EPSS 0.048
CVE-2015-2620
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.23 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges.
Published 2015-07-16 · Modified
4.3EPSS 0.047
CVE-2014-6559
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality via vectors related to C API SSL CERTIFICATE HANDLING.
Published 2014-10-15 · Modified
4.3EPSS 0.046
CVE-2014-6496
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6494.
Published 2014-10-15 · Modified
4.3EPSS 0.043
CVE-2014-6495
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect availability via vectors related to SERVER:SSL:yaSSL.
Published 2014-10-15 · Modified
4.3EPSS 0.030
CVE-2014-6478
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect integrity via vectors related to SERVER:SSL:yaSSL.
Published 2014-10-15 · Modified
4.3EPSS 0.026
CVE-2013-5095
Cross-site scripting (XSS) vulnerability in the web-based interface in Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka PR 884469.
Published 2013-08-16 · Modified
4.3EPSS 0.014
CVE-2014-0453
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Security.
Published 2014-04-16 · Modified
4.0EPSS 0.049
CVE-2013-5097
Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly restrict access to the list of user accounts and their MD5 password hashes, which makes it easier for remote authenticated users to obtain sensitive information via a dictionary attack, aka PR 879462.
Published 2013-08-16 · Modified
4.0EPSS 0.013
CVE-2013-5096
Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly implement role-based access control, which allows remote authenticated users to modify the configuration by leveraging the read-only privilege, aka PR 863804.
Published 2013-08-16 · Modified
4.0EPSS 0.011
← Prev2 / 2