7.1

CVSS4.0

CVE-2026-21903 - Junos OS: Subscribing to telemetry sensors at scale causes all FPCs to crash

A Stack-based Buffer Overflow vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a network-based attacker, authenticated with low privileges to cause a Denial-of-Service (DoS). Subscribing to telemetry sensors at scale causes all FPC connections to drop, resu…

📅 Published: Jan. 15, 2026, 8:18 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:40 p.m.

7.1

CVSS4.0

CVE-2026-0203 - Junos OS: Receipt of a specifically malformed ICMP packet causes an FPC restart

An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS allows an unauthenticated, network-adjacent attacker sending a specifically malformed ICMP packet to cause an FPC to crash and restart, resulting in a Denial of Service (DoS). When an I…

📅 Published: Jan. 15, 2026, 8:17 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:39 p.m.

6.9

CVSS4.0

CVE-2025-60011 - Junos OS and Junos OS Evolved: Optional transitive BGP attribute is modified before propagation to …

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an availability impact for downstream devices. When an affected device receives a …

📅 Published: Jan. 15, 2026, 8:16 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:39 p.m.

6.8

CVSS4.0

CVE-2025-60007 - Junos OS: A specifically crafted 'show chassis' command causes chassisd to crash

A NULL Pointer Dereference vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS on MX, SRX and EX Series allows a local attacker with low privileges to cause a Denial-of-Service (DoS). When a user executes the 'show chassis' command with specifically crafted options, chassi…

📅 Published: Jan. 15, 2026, 8:16 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:39 p.m.

8.7

CVSS4.0

CVE-2025-60003 - Junos OS and Junos OS Evolved: BGP update with a set of specific attributes causes rpd crash

A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When an affected device receives a BGP update with a set of specific optional transitive att…

📅 Published: Jan. 15, 2026, 8:15 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:39 p.m.

6.8

CVSS4.0

CVE-2025-59961 - Junos OS and Junos OS Evolved: Unix socket used to control the jdhcpd process is world-writable

An Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged user to write to the Unix socket used to manage the jdhcpd process, resulting in complete control over the reso…

📅 Published: Jan. 15, 2026, 8:14 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:39 p.m.

6.3

CVSS4.0

CVE-2025-59960 - Junos OS and Junos OS Evolved: DHCP Option 82 messages from clients being passed unmodified to the …

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a DHCP client in one subnet to exhaust the address pools of other subnets, leading to a Denial of Service (DoS) on the downstream DHCP …

📅 Published: Jan. 15, 2026, 8:14 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:39 p.m.

6.8

CVSS4.0

CVE-2025-59959 - Junos OS and Junos OS Evolved: Executing a specific show command leads to an rpd crash

An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial-of-Service (DoS). When the command 'show route < ( receive-protocol | advertising-proto…

📅 Published: Jan. 15, 2026, 8:13 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:38 p.m.

5.1

CVSS4.0

CVE-2025-52987 - Paragon Automation: A clickjacking vulnerability in the web server configuration has been addressed

A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the application's failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerability allows an attacker to trick users into interacting wit…

📅 Published: Jan. 15, 2026, 8:10 p.m. 🔄 Last Modified: Jan. 16, 2026, 5:15 p.m.

5.3

CVSS4.0

CVE-2025-15265 - Svelte 5.46.0 - Hydratable Key Script-Breakout XSS (SSR)

An SSR XSS exists in async hydration when attacker‑controlled keys are passed to hydratable. The key is embedded inside a <script> block without HTML‑safe escaping, allowing </script> to terminate the script and inject arbitrary JavaScript. This enables remote script execution in users' browsers, w…

📅 Published: Jan. 15, 2026, 7:59 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:04 p.m.
Total resulsts: 329553
Page 164 of 32,956
« previous page » next page
Filters