The Juniper Project maintains a narrowly scoped vulnerability footprint centered on its Juniper product, where the durable signal reflects resource-exhaustion and recursion-depth weaknesses typical of parsing and algorithm-processing logic. Treat this as a compact vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Juniper Project over time
Signals from CVEs in this vendor scope (1111 CVEs).
1,111 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36845CRITICAL A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series
and SRX Series
allows an unauthenticated, network-based attacker to remote | Aug 17, 2023 | 9.8 | 98 | YES | YES |
CVE-2023-36844MEDIUM A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, importan | Aug 17, 2023 | 5.3 | 95 | YES | YES |
CVE-2022-42889CRITICAL Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where | Oct 13, 2022 | 9.8 | 95 | NO | YES |
CVE-2015-7755CRITICAL Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6 | Dec 19, 2015 | 9.8 | 94 | YES | YES |
CVE-2023-36846MEDIUM A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to | Aug 17, 2023 | 5.3 | 93 | YES | NO |
CVE-2023-36847MEDIUM A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to | Aug 17, 2023 | 5.3 | 91 | YES | NO |
CVE-2009-1185HIGH udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space. | Apr 17, 2009 | 7.2 | 84 | NO | YES |
CVE-2019-11358MEDIUM jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob | Apr 20, 2019 | 6.1 | 78 | NO | YES |
CVE-2008-0960HIGH SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC | Jun 10, 2008 | 10.0 | 77 | NO | YES |
CVE-2004-0230MEDIUM TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by | Aug 18, 2004 | 5.0 | 74 | NO | YES |
Signals from CVEs in this vendor scope (1111 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Juniper Project.
Media articles that mention a CVE ID that affects a product developed by Juniper Project — matched by CVE ID, not by vendor name.