CVE-2025-59985
- EPSS 0.04%
- Veröffentlicht 09.10.2025 16:08:57
- Zuletzt bearbeitet 23.01.2026 20:00:02
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in a field on the Purging Policy page that, when visited by another user, e...
CVE-2025-59984
- EPSS 0.04%
- Veröffentlicht 09.10.2025 16:08:22
- Zuletzt bearbeitet 23.01.2026 20:00:05
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in Global Search that, when visited by another user, enables the attacker t...
CVE-2025-59983
- EPSS 0.04%
- Veröffentlicht 09.10.2025 16:07:25
- Zuletzt bearbeitet 23.01.2026 20:00:08
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Template Definition page, when visited by another user, enables the...
CVE-2025-59982
- EPSS 0.04%
- Veröffentlicht 09.10.2025 16:06:53
- Zuletzt bearbeitet 23.01.2026 19:44:34
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the dashboard search field that, when visited by another user, enables t...
CVE-2025-59981
- EPSS 0.04%
- Veröffentlicht 09.10.2025 16:06:13
- Zuletzt bearbeitet 23.01.2026 19:44:49
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Device Template Definition page that, when visited by another user, ...
CVE-2025-59978
- EPSS 0.07%
- Veröffentlicht 09.10.2025 16:02:59
- Zuletzt bearbeitet 23.01.2026 19:44:53
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker...
CVE-2025-59976
- EPSS 0.05%
- Veröffentlicht 09.10.2025 15:59:07
- Zuletzt bearbeitet 23.01.2026 19:45:09
An arbitrary file download vulnerability in the web interface of Juniper Networks Junos Space allows a network-based authenticated attacker using a crafted GET method to access any file on the file system. Using specially crafted GET methods, an atta...
CVE-2025-59975
- EPSS 0.11%
- Veröffentlicht 09.10.2025 15:58:33
- Zuletzt bearbeitet 23.01.2026 18:37:40
An Uncontrolled Resource Consumption vulnerability in the HTTP daemon (httpd) of Juniper Networks Junos Space allows an unauthenticated network-based attacker flooding the device with inbound API calls to consume all resources on the system, leading ...
CVE-2024-39563
- EPSS 1.34%
- Veröffentlicht 11.10.2024 16:15:07
- Zuletzt bearbeitet 23.01.2026 20:02:07
A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on the Junos Space Appliance, leading to remote command execut...
CVE-2021-0220
- EPSS 0.28%
- Veröffentlicht 15.01.2021 18:15:15
- Zuletzt bearbeitet 21.11.2024 05:42:14
The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for example via XSS) or access cac...