CVE-2025-59984
- EPSS 0.05%
- Veröffentlicht 09.10.2025 16:08:22
- Zuletzt bearbeitet 23.01.2026 20:00:05
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in Global Search that, when visited by another user, enables the attacker t...
CVE-2025-59983
- EPSS 0.05%
- Veröffentlicht 09.10.2025 16:07:25
- Zuletzt bearbeitet 23.01.2026 20:00:08
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Template Definition page, when visited by another user, enables the...
CVE-2025-59982
- EPSS 0.05%
- Veröffentlicht 09.10.2025 16:06:53
- Zuletzt bearbeitet 23.01.2026 19:44:34
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the dashboard search field that, when visited by another user, enables t...
CVE-2025-59981
- EPSS 0.05%
- Veröffentlicht 09.10.2025 16:06:13
- Zuletzt bearbeitet 23.01.2026 19:44:49
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Device Template Definition page that, when visited by another user, ...
CVE-2025-59978
- EPSS 0.08%
- Veröffentlicht 09.10.2025 16:02:59
- Zuletzt bearbeitet 23.01.2026 19:44:53
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker...
CVE-2025-59976
- EPSS 0.05%
- Veröffentlicht 09.10.2025 15:59:07
- Zuletzt bearbeitet 23.01.2026 19:45:09
An arbitrary file download vulnerability in the web interface of Juniper Networks Junos Space allows a network-based authenticated attacker using a crafted GET method to access any file on the file system. Using specially crafted GET methods, an atta...
CVE-2025-59975
- EPSS 0.06%
- Veröffentlicht 09.10.2025 15:58:33
- Zuletzt bearbeitet 23.01.2026 18:37:40
An Uncontrolled Resource Consumption vulnerability in the HTTP daemon (httpd) of Juniper Networks Junos Space allows an unauthenticated network-based attacker flooding the device with inbound API calls to consume all resources on the system, leading ...
CVE-2024-39563
- EPSS 0.56%
- Veröffentlicht 11.10.2024 16:15:07
- Zuletzt bearbeitet 23.01.2026 20:02:07
A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on the Junos Space Appliance, leading to remote command execut...
CVE-2021-0220
- EPSS 0.28%
- Veröffentlicht 15.01.2021 18:15:15
- Zuletzt bearbeitet 21.11.2024 05:42:14
The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for example via XSS) or access cac...
CVE-2019-0017
- EPSS 0.23%
- Veröffentlicht 15.01.2019 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:16:03
The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which may allow uploading of malicious images or scripts, or other content types. Affected releases are Juniper Networks Junos Space versi...