9.3

CVSS4.0

CVE-2011-10041 - Uploadify <= 1.0 Unauthenticated Arbitrary File Upload

Uploadify WordPress plugin versions up to and including 1.0 contain an arbitrary file upload vulnerability in process_upload.php due to missing file type validation. An unauthenticated remote attacker can upload arbitrary files to the affected WordPress site, which may allow remote code execution b…

📅 Published: Jan. 15, 2026, 9:44 p.m. 🔄 Last Modified: Jan. 20, 2026, 4:16 p.m.

6.9

CVSS4.0

CVE-2026-1002 - Eclipse Vert.x Web static handler file access denial

The Vert.x Web static handler component cache can be manipulated to deny the access to static files served by the handler using specifically crafted request URI. The issue comes from an improper implementation of the C. rule of section 5.2.4 of RFC3986 and is fixed in Vert.x Core component (used …

📅 Published: Jan. 15, 2026, 8:50 p.m. 🔄 Last Modified: Jan. 16, 2026, 3:55 p.m.

7.1

CVSS4.0

CVE-2026-21921 - Junos OS and Junos OS Evolved: When telemetry collectors are frequently subscribing and unsubscribi…

A Use After Free vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker authenticated with low privileges to cause a Denial-of-Service (DoS). When telemetry collectors are frequently subscribing and unsubscribing to sensors …

📅 Published: Jan. 15, 2026, 8:28 p.m. 🔄 Last Modified: Jan. 23, 2026, 6:52 p.m.

8.7

CVSS4.0

CVE-2026-21920 - Junos OS: SRX Series: If a specific request is processed by the DNS subsystem flowd will crash

An Unchecked Return Value vulnerability in the DNS module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX Series device configured for DNS processing, receives a specifically formatted DNS request flowd w…

📅 Published: Jan. 15, 2026, 8:28 p.m. 🔄 Last Modified: Jan. 23, 2026, 6:51 p.m.

8.7

CVSS4.0

CVE-2026-21918 - Junos OS: SRX and MX Series: When TCP packets occur in a specific sequence flowd crashes

A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX and MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On all SRX and MX Series platforms, when during TCP session establishment a specific sequence of …

📅 Published: Jan. 15, 2026, 8:27 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:41 p.m.

8.7

CVSS4.0

CVE-2026-21917 - Junos OS: SRX Series: Specifically malformed SSL packet causes FPC crash

An Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX device configured for UTM Web-Filtering receives a specifica…

📅 Published: Jan. 15, 2026, 8:27 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:41 p.m.

8.7

CVSS4.0

CVE-2026-21914 - Junos OS: SRX Series: A specifically malformed GTP message will cause an FPC crash

An Improper Locking vulnerability in the GTP plugin of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (Dos). If an SRX Series device receives a specifically malformed GPRS Tunnelling Protocol (GTP) Modify Bearer Request messag…

📅 Published: Jan. 15, 2026, 8:25 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:41 p.m.

8.7

CVSS4.0

CVE-2026-21913 - Junos OS: EX4000: A high volume of traffic destined to the device leads to a crash and restart

An Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Juniper Networks Junos OS on EX4000 models allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On EX4000 models with 48 ports (EX4000-48T, EX4000-48P, EX4000-48MP) a high…

📅 Published: Jan. 15, 2026, 8:25 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:40 p.m.

6.8

CVSS4.0

CVE-2026-21912 - Junos OS: MX10k Series: 'show system firmware' CLI command may lead to LC480 or LC2101 line card re…

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the method to collect FPC Ethernet firmware statistics of Juniper Networks Junos OS on MX10k Series allows a local, low-privileged attacker executing the 'show system firmware' CLI command to cause an LC480 or LC2101 line card to …

📅 Published: Jan. 15, 2026, 8:24 p.m. 🔄 Last Modified: Jan. 16, 2026, 3:55 p.m.

7.1

CVSS4.0

CVE-2026-21911 - Junos OS Evolved: Flapping management interface causes MAC learning on label-switched interfaces to…

An Incorrect Calculation vulnerability in the Layer 2 Control Protocol Daemon (l2cpd) of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker flapping the management interface to cause the learning of new MACs over label-switched interfaces (LSI) to stop while g…

📅 Published: Jan. 15, 2026, 8:23 p.m. 🔄 Last Modified: Jan. 23, 2026, 4:59 p.m.
Total resulsts: 329549
Page 162 of 32,955
« previous page » next page
Filters