VYPR

Junos Space

by Juniper Networks

CVEs (80)

  • CVE-2025-59990MedOct 9, 2025
    risk 0.40cvss 6.1epss 0.00

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the template creation pages that, when visited by another user, enable the attacker to execute…

  • CVE-2025-59989MedOct 9, 2025
    risk 0.40cvss 6.1epss 0.00

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Device Discovery page that, when visited by another user, enables the attacker to execute…

  • CVE-2025-59988MedOct 9, 2025
    risk 0.40cvss 6.1epss 0.00

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Generate Report page that, when visited by another user, enables the attacker to execute commands…

  • CVE-2025-59987MedOct 9, 2025
    risk 0.40cvss 6.1epss 0.00

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the arbitrary device search field that, when visited by another user, enables the attacker to…

  • CVE-2025-59986MedOct 9, 2025
    risk 0.40cvss 6.1epss 0.00

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the input fields in Model Devices that, when visited by another user, enables the attacker to…

  • CVE-2025-59985MedOct 9, 2025
    risk 0.40cvss 6.1epss 0.00

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in a field on the Purging Policy page that, when visited by another user, enables the attacker to…

  • CVE-2025-59984MedOct 9, 2025
    risk 0.40cvss 6.1epss 0.00

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in Global Search that, when visited by another user, enables the attacker to execute commands with the…

  • CVE-2025-59983MedOct 9, 2025
    risk 0.40cvss 6.1epss 0.00

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Template Definition page, when visited by another user, enables the attacker to execute…

  • CVE-2025-59982MedOct 9, 2025
    risk 0.40cvss 6.1epss 0.00

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the dashboard search field that, when visited by another user, enables the attacker to execute…

  • CVE-2025-59981MedOct 9, 2025
    risk 0.40cvss 6.1epss 0.00

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Device Template Definition page that, when visited by another user, enables the attacker to…

  • CVE-2017-2307MedMay 30, 2017
    risk 0.40cvss 6.1epss 0.01

    A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks Junos Space versions prior to 16.1R1 may allow remote attackers to steal sensitive information or perform certain administrative actions on Junos Space.

  • CVE-2016-4930MedMar 20, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in Junos Space before 15.2R2 allows remote attackers to steal sensitive information or perform certain administrative actions.

  • CVE-2026-21907MedJan 15, 2026
    risk 0.38cvss 5.9epss 0.00

    A Use of a Broken or Risky Cryptographic Algorithm vulnerability in the TLS/SSL server of Juniper Networks Junos Space allows the use of static key ciphers (ssl-static-key-ciphers), reducing the confidentiality of on-path traffic communicated across the connection. These…

  • CVE-2017-2309MedMay 30, 2017
    risk 0.38cvss 5.9epss 0.01

    On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is enabled for the Junos Space cluster, some restricted web services are accessible over the network. This represents an information leak risk.

  • CVE-2020-1652MedJul 17, 2020
    risk 0.36cvss 5.6epss 0.01

    OpenNMS is accessible via port 9443

  • CVE-2018-0011MedJan 10, 2018
    risk 0.35cvss 5.4epss 0.01

    A reflected cross site scripting (XSS) vulnerability in Junos Space may potentially allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a session, and to perform administrative actions on the Junos Space network management…

  • CVE-2017-2311MedMay 30, 2017
    risk 0.35cvss 5.3epss 0.01

    On Juniper Networks Junos Space versions prior to 16.1R1, an unauthenticated remote attacker with network access to Junos space device can easily create a denial of service condition.

  • CVE-2017-2310MedMay 30, 2017
    risk 0.35cvss 5.3epss 0.01

    A firewall bypass vulnerability in the host based firewall of Juniper Networks Junos Space versions prior to 16.1R1 may permit certain crafted packets, representing a network integrity risk.

  • CVE-2015-3209Jun 15, 2015
    risk 0.01cvss —epss 0.10

    Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.

  • CVE-2015-0501Apr 16, 2015
    risk 0.01cvss —epss 0.10

    Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Compiling.