Junos

Vendor:

First CVE: Aug 18, 2004 · Active for 21 years

790
Total CVEs
More Total CVEs than 100% of tracked products
43.9
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.9%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Junos over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 18, 2004
21 years ago
Most Recent CVE
Jul 9, 2026
16 days ago

CVE Severity & Scoring

Junos790 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local101 (12.8%)
Network444 (56.2%)
Unknown67 (8.5%)
Physical8 (1.0%)
Adjacent Network170 (21.5%)
Attack Complexity
Low644 (81.5%)
High79 (10.0%)
Unknown67 (8.5%)
User Interaction
None693 (87.7%)
Unknown67 (8.5%)
Required30 (3.8%)
Privileges Required
Low125 (15.8%)
High14 (1.8%)
None584 (73.9%)
Unknown67 (8.5%)

Top CVEs

Signals from CVEs in this product scope (790 CVEs).

790 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remote
Aug 17, 20239.898YESYES
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, importan
Aug 17, 20235.395YESYES
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to
Aug 17, 20235.393YESNO
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to
Aug 17, 20235.391YESNO
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob
Apr 20, 20196.178NOYES
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by
Aug 18, 20045.074NOYES
A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning
May 4, 20209.872YESNO
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the net
Mar 6, 20209.868NONO
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to
Sep 27, 20235.357YESNO
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of t
Mar 12, 20254.456YESNO

Exploit Exposure

Signals from CVEs in this product scope (790 CVEs).

CISA KEV
7 CVEs
0.9% of CVEs· 96th percentile
Metasploit
1 CVE
0.1% of CVEs· 96th percentile
Nuclei
3 CVEs
0.4% of CVEs· 96th percentile
ExploitDB
7 CVEs
0.9% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (790 CVEs).

Media Mentions

Signals from CVEs in this product scope (790 CVEs).

Top CNAs Publishing CVEs For Junos

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.655.92.0%00
9.555.92.0%00
9.455.92.0%00
9.255.92.0%00
9.155.92.0%00
9.055.21.9%01
8.533.81.3%03
8.455.92.4%00
8.355.92.4%00
8.255.92.4%00
8.155.92.4%00
8.065.72.7%00
7.915.04.2%00
7.815.04.2%00
7.715.04.2%00
7.665.72.7%00
7.565.72.7%00
7.465.72.7%00
7.365.72.7%00
7.255.32.5%00