7.1

CVSS4.0

CVE-2026-33775 - Junos OS: MX Series: Mismatch between configured and received packet types causes memory leak in bb…

A Missing Release of Memory after Effective Lifetime vulnerability in the BroadBand Edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). If the authentication packet-type option is co…

📅 Published: April 9, 2026, 9:30 p.m. 🔄 Last Modified: April 9, 2026, 9:30 p.m.

5.3

CVSS3.1

CVE-2026-40151 - PraisonAI Affected by Unauthenticated Information Disclosure of Agent Instructions via /api/agents …

PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a GET /api/agents endpoint that returns agent names, roles, and the first 100 characters of agent system instructions to any unauthenticated caller. The AgentOS FastAPI application has no authenticati…

📅 Published: April 9, 2026, 9:29 p.m. 🔄 Last Modified: April 10, 2026, 5:10 p.m.

8.7

CVSS4.0

CVE-2026-33782 - Junos OS: MX Series: In specific DHCPv6 scenarios jdhcpd memory increases continuously with subscri…

A Missing Release of Memory after Effective Lifetime vulnerability in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS on MX Series, allows an adjacent, unauthenticated attacker to cause a memory leak, that will eventually cause a complete Denial-of-Service (DoS). In a DHCPv6 over PPPoE, or D…

📅 Published: April 9, 2026, 9:29 p.m. 🔄 Last Modified: April 9, 2026, 9:29 p.m.

7.1

CVSS4.0

CVE-2026-33780 - Junos OS and Junos OS Evolved: In an EVPN-MPLS scenario churn of ESI routes causes a memory leak in…

A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a memory leak ultimately leading to a Denial of Service (DoS). In an EVPN-MPLS…

📅 Published: April 9, 2026, 9:29 p.m. 🔄 Last Modified: April 9, 2026, 9:29 p.m.

6.9

CVSS4.0

CVE-2026-33773 - Junos OS: EX Series, QFX Series: If the same egress filter is configured on both an IRB and a physi…

An Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series and QFX Series device allows an unauthenticated, network-based attacker to cause an integrity impact to downstream networks. When the same family inet or i…

📅 Published: April 9, 2026, 9:28 p.m. 🔄 Last Modified: April 9, 2026, 9:28 p.m.

6.8

CVSS4.0

CVE-2026-33786 - Junos OS: SRX1600, SRX2300, SRX4300: When a specific show command is executed chassisd crashes

An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local attacker with low privileges to cause a complete Denial of Service (DoS). When a specific 'show chassis' CLI co…

📅 Published: April 9, 2026, 9:28 p.m. 🔄 Last Modified: April 9, 2026, 9:28 p.m.

7

CVSS4.0

CVE-2026-21916 - Junos OS: A low privileged user can escalate their privileges so that they can login as root

A UNIX Symbolic Link (Symlink) Following vulnerability in the CLI of Juniper Networks Junos OS allows a local, authenticated attacker with low privileges to escalate their privileges to root which will lead to a complete compromise of the system. When after a user has performed a specific 'file li…

📅 Published: April 9, 2026, 9:28 p.m. 🔄 Last Modified: April 9, 2026, 9:28 p.m.

7.4

CVSS3.1

CVE-2026-40153 - PraisonAIAgents Affected by Environment Variable Secret Exfiltration via os.path.expandvars() Bypas…

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in shell_tools.py calls os.path.expandvars() on every command argument at line 64, manually re-implementing shell-level environment variable expansion despite using shell=False (line 88) for security. This…

📅 Published: April 9, 2026, 9:27 p.m. 🔄 Last Modified: April 10, 2026, 9:28 a.m.

8.5

CVSS4.0

CVE-2026-33788 - Junos OS Evolved: Local, authenticated attacker can gain privileged access to FPCs

A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to FPCs installed in the device. A local user with low privilege…

📅 Published: April 9, 2026, 9:27 p.m. 🔄 Last Modified: April 9, 2026, 9:27 p.m.

6.3

CVSS4.0

CVE-2026-35646 - OpenClaw < 2026.3.25 - Pre-Authentication Rate-Limit Bypass in Webhook Token Validation

OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that allows attackers to brute-force weak webhook secrets. The vulnerability exists because invalid webhook tokens are rejected without throttling repeated authentication attempts, en…

📅 Published: April 9, 2026, 9:27 p.m. 🔄 Last Modified: April 10, 2026, 1:57 p.m.
Total resulsts: 343946
Page 32 of 34,395
« previous page » next page
Filters