Junos
Vendor:
First CVE: Aug 18, 2004 · Active for 21 years
790
Total CVEs
More Total CVEs than 100% of tracked products
43.9
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.9%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Junos over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 18, 2004
21 years ago
Most Recent CVE
Jul 9, 2026
16 days ago
CVE Severity & Scoring
Junos790 CVEs
50%
45%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local101 (12.8%)
Network444 (56.2%)
Unknown67 (8.5%)
Physical8 (1.0%)
Adjacent Network170 (21.5%)
Attack Complexity
Low644 (81.5%)
High79 (10.0%)
Unknown67 (8.5%)
User Interaction
None693 (87.7%)
Unknown67 (8.5%)
Required30 (3.8%)
Privileges Required
Low125 (15.8%)
High14 (1.8%)
None584 (73.9%)
Unknown67 (8.5%)
Top CVEs
Signals from CVEs in this product scope (790 CVEs).
790 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36845CRITICAL A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series
and SRX Series
allows an unauthenticated, network-based attacker to remote | Aug 17, 2023 | 9.8 | 98 | YES | YES |
CVE-2023-36844MEDIUM A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, importan | Aug 17, 2023 | 5.3 | 95 | YES | YES |
CVE-2023-36846MEDIUM A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to | Aug 17, 2023 | 5.3 | 93 | YES | NO |
CVE-2023-36847MEDIUM A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to | Aug 17, 2023 | 5.3 | 91 | YES | NO |
CVE-2019-11358MEDIUM jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob | Apr 20, 2019 | 6.1 | 78 | NO | YES |
CVE-2004-0230MEDIUM TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by | Aug 18, 2004 | 5.0 | 74 | NO | YES |
CVE-2020-1631CRITICAL A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning | May 4, 2020 | 9.8 | 72 | YES | NO |
CVE-2020-10188CRITICAL utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the net | Mar 6, 2020 | 9.8 | 68 | NO | NO |
CVE-2023-36851MEDIUM A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to | Sep 27, 2023 | 5.3 | 57 | YES | NO |
CVE-2025-21590MEDIUM An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of t | Mar 12, 2025 | 4.4 | 56 | YES | NO |
Exploit Exposure
Signals from CVEs in this product scope (790 CVEs).
CISA KEV
7 CVEs
0.9% of CVEs· 96th percentile
Metasploit
1 CVE
0.1% of CVEs· 96th percentile
Nuclei
3 CVEs
0.4% of CVEs· 96th percentile
ExploitDB
7 CVEs
0.9% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (790 CVEs).
Media Mentions
Signals from CVEs in this product scope (790 CVEs).
Top CNAs Publishing CVEs For Junos
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.6 | 5 | 5.9 | 2.0% | 0 | 0 |
| 9.5 | 5 | 5.9 | 2.0% | 0 | 0 |
| 9.4 | 5 | 5.9 | 2.0% | 0 | 0 |
| 9.2 | 5 | 5.9 | 2.0% | 0 | 0 |
| 9.1 | 5 | 5.9 | 2.0% | 0 | 0 |
| 9.0 | 5 | 5.2 | 1.9% | 0 | 1 |
| 8.5 | 3 | 3.8 | 1.3% | 0 | 3 |
| 8.4 | 5 | 5.9 | 2.4% | 0 | 0 |
| 8.3 | 5 | 5.9 | 2.4% | 0 | 0 |
| 8.2 | 5 | 5.9 | 2.4% | 0 | 0 |
| 8.1 | 5 | 5.9 | 2.4% | 0 | 0 |
| 8.0 | 6 | 5.7 | 2.7% | 0 | 0 |
| 7.9 | 1 | 5.0 | 4.2% | 0 | 0 |
| 7.8 | 1 | 5.0 | 4.2% | 0 | 0 |
| 7.7 | 1 | 5.0 | 4.2% | 0 | 0 |
| 7.6 | 6 | 5.7 | 2.7% | 0 | 0 |
| 7.5 | 6 | 5.7 | 2.7% | 0 | 0 |
| 7.4 | 6 | 5.7 | 2.7% | 0 | 0 |
| 7.3 | 6 | 5.7 | 2.7% | 0 | 0 |
| 7.2 | 5 | 5.3 | 2.5% | 0 | 0 |