5.1

CVSS4.0

CVE-2025-59985 - Junos Space: Purging Policy field is vulnerable to reflected cross-site script injection

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in a field on the Purging Policy page that, when visited by another user, enables the attacker to execute commands with the …

📅 Published: Oct. 9, 2025, 4:08 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:16 p.m.

5.1

CVSS4.0

CVE-2025-59984 - Junos Space: Global Search is vulnerable to reflected cross-site script injection

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in Global Search that, when visited by another user, enables the attacker to execute commands with the target's permissions,…

📅 Published: Oct. 9, 2025, 4:08 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:16 p.m.

5.1

CVSS4.0

CVE-2025-59983 - Junos Space: Template Definition page is vulnerable to reflected cross-site script injection

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Template Definition page, when visited by another user, enables the attacker to execute commands with the target's p…

📅 Published: Oct. 9, 2025, 4:07 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:15 p.m.

5.1

CVSS4.0

CVE-2025-59982 - Junos Space: Dashboard Search field is vulnerable to reflected cross-site script injection

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the dashboard search field that, when visited by another user, enables the attacker to execute commands with the target's…

📅 Published: Oct. 9, 2025, 4:06 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:15 p.m.

5.1

CVSS4.0

CVE-2025-59981 - Junos Space: Device Template Definition page is vulnerable to reflected cross-site script injection

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Device Template Definition page that, when visited by another user, enables the attacker to execute commands with the…

📅 Published: Oct. 9, 2025, 4:06 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:15 p.m.

6.9

CVSS4.0

CVE-2025-59980 - Junos OS: When a user with the name ftp or anonymous is configured unauthenticated filesystem acces…

An Authentication Bypass by Primary Weakness in the FTP server of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to get limited read-write access to files on the device. When the FTP server is enabled and a user named "ftp" or "anonymous" is configured, that user can l…

📅 Published: Oct. 9, 2025, 4:05 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:15 p.m.

9.4

CVSS4.0

CVE-2025-59978 - Junos Space: Stored cross-site scripting vulnerability in web application

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the target's administra…

📅 Published: Oct. 9, 2025, 4:02 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:15 p.m.

7.1

CVSS4.0

CVE-2025-59976 - Junos Space: Arbitrary file download vulnerability in web interface

An arbitrary file download vulnerability in the web interface of Juniper Networks Junos Space allows a network-based authenticated attacker using a crafted GET method to access any file on the file system. Using specially crafted GET methods, an attacker can gain access to files beyond the file pat…

📅 Published: Oct. 9, 2025, 3:59 p.m. 🔄 Last Modified: Oct. 9, 2025, 7:49 p.m.

8.7

CVSS4.0

CVE-2025-59975 - Junos Space: Flooding device with inbound API calls leads to WebUI and CLI management access DoS

An Uncontrolled Resource Consumption vulnerability in the HTTP daemon (httpd) of Juniper Networks Junos Space allows an unauthenticated network-based attacker flooding the device with inbound API calls to consume all resources on the system, leading to a Denial of Service (DoS). After continuously…

📅 Published: Oct. 9, 2025, 3:58 p.m. 🔄 Last Modified: Oct. 9, 2025, 7:49 p.m.

9.3

CVSS4.0

CVE-2025-59974 - Junos Space Security Director: Persistent Cross-Site Scripting (XSS) vulnerability

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Junos Space Security Director allows an attacker to inject malicious scripts into the application, which are then stored and executed in the context of other users' browsers when they access aff…

📅 Published: Oct. 9, 2025, 3:57 p.m. 🔄 Last Modified: Oct. 9, 2025, 7:49 p.m.
Total resulsts: 313539
Page 8 of 31,354
« previous page » next page
Filters