5.1

CVSS4.0

CVE-2025-59987 - Junos Space: The arbitrary device search field is vulnerable to reflected cross-site script injecti…

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the arbitrary device search field that, when visited by another user, enables the attacker to execute commands with the t…

📅 Published: Oct. 9, 2025, 4:09 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:16 p.m.

5.1

CVSS4.0

CVE-2025-59986 - Junos Space: Input fields in Model Devices are vulnerable to reflected cross-site script injection

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the input fields in Model Devices that, when visited by another user, enables the attacker to execute commands with the t…

📅 Published: Oct. 9, 2025, 4:09 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:16 p.m.

5.1

CVSS4.0

CVE-2025-59985 - Junos Space: Purging Policy field is vulnerable to reflected cross-site script injection

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in a field on the Purging Policy page that, when visited by another user, enables the attacker to execute commands with the …

📅 Published: Oct. 9, 2025, 4:08 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:16 p.m.

5.1

CVSS4.0

CVE-2025-59984 - Junos Space: Global Search is vulnerable to reflected cross-site script injection

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in Global Search that, when visited by another user, enables the attacker to execute commands with the target's permissions,…

📅 Published: Oct. 9, 2025, 4:08 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:16 p.m.

5.1

CVSS4.0

CVE-2025-59983 - Junos Space: Template Definition page is vulnerable to reflected cross-site script injection

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Template Definition page, when visited by another user, enables the attacker to execute commands with the target's p…

📅 Published: Oct. 9, 2025, 4:07 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:15 p.m.

5.1

CVSS4.0

CVE-2025-59982 - Junos Space: Dashboard Search field is vulnerable to reflected cross-site script injection

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the dashboard search field that, when visited by another user, enables the attacker to execute commands with the target's…

📅 Published: Oct. 9, 2025, 4:06 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:15 p.m.

5.1

CVSS4.0

CVE-2025-59981 - Junos Space: Device Template Definition page is vulnerable to reflected cross-site script injection

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Device Template Definition page that, when visited by another user, enables the attacker to execute commands with the…

📅 Published: Oct. 9, 2025, 4:06 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:15 p.m.

6.9

CVSS4.0

CVE-2025-59980 - Junos OS: When a user with the name ftp or anonymous is configured unauthenticated filesystem acces…

An Authentication Bypass by Primary Weakness in the FTP server of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to get limited read-write access to files on the device. When the FTP server is enabled and a user named "ftp" or "anonymous" is configured, that user can l…

📅 Published: Oct. 9, 2025, 4:05 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:15 p.m.

9.4

CVSS4.0

CVE-2025-59978 - Junos Space: Stored cross-site scripting vulnerability in web application

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the target's administra…

📅 Published: Oct. 9, 2025, 4:02 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:15 p.m.

7.1

CVSS4.0

CVE-2025-59976 - Junos Space: Arbitrary file download vulnerability in web interface

An arbitrary file download vulnerability in the web interface of Juniper Networks Junos Space allows a network-based authenticated attacker using a crafted GET method to access any file on the file system. Using specially crafted GET methods, an attacker can gain access to files beyond the file pat…

📅 Published: Oct. 9, 2025, 3:59 p.m. 🔄 Last Modified: Oct. 9, 2025, 7:49 p.m.
Total resulsts: 313541
Page 8 of 31,355
« previous page » next page
Filters