Mx2010
Vendor:
First CVE: Jan 16, 2015 · Active for 11 years
90
Total CVEs
More Total CVEs than 99% of tracked products
8.2
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mx2010 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 16, 2015
11 years ago
Most Recent CVE
Jul 9, 2026
15 days ago
CVE Severity & Scoring
Mx201090 CVEs
53%
46%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local9 (10.0%)
Network55 (61.1%)
Unknown2 (2.2%)
Physical0 (0.0%)
Adjacent Network24 (26.7%)
Attack Complexity
Low81 (90.0%)
High7 (7.8%)
Unknown2 (2.2%)
User Interaction
None88 (97.8%)
Unknown2 (2.2%)
Required0 (0.0%)
Privileges Required
Low11 (12.2%)
High0 (0.0%)
None77 (85.6%)
Unknown2 (2.2%)
Top CVEs
Signals from CVEs in this product scope (90 CVEs).
90 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-9708MEDIUM Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demons | Mar 31, 2015 | 5.0 | 42 | NO | NO |
CVE-2019-0007CRITICAL The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well as clients connecting through the device susceptible to a family of attacks which r | Jan 15, 2019 | 10.0 | 32 | NO | NO |
CVE-2026-33785HIGH A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific commands which | Apr 9, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-57019MEDIUM An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjac | Jul 9, 2026 | 6.5 | 29 | NO | NO |
CVE-2021-0251HIGH A NULL Pointer Dereference vulnerability in the Captive Portal Content Delivery (CPCD) services daemon (cpcd) of Juniper Networks Junos OS on MX Series with MS-PIC, MS-SPC3, MS-MIC | Apr 22, 2021 | 8.6 | 27 | NO | NO |
CVE-2026-57054MEDIUM A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacke | Jul 9, 2026 | 5.8 | 26 | NO | NO |
CVE-2026-33778HIGH An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an | Apr 9, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-21918HIGH A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX and MX Series allows an unauthenticated, network-based attacker to cause a Den | Jan 15, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-21905HIGH A Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series with MX-S | Jan 15, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-57025MEDIUM A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to | Jul 9, 2026 | 5.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (90 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (90 CVEs).
Media Mentions
Signals from CVEs in this product scope (90 CVEs).
Top CNAs Publishing CVEs For Mx2010
Top CWEs
Versions
No cataloged versions.