CVE-2025-21602 – Juniper Networks Junos OS and Junos OS Evolved BGP Routing Protocol Denial of Service
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sending a specific BGP update packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continuous receipt and processing of this packet will […]
CVE-2025-21599 – Juniper Networks Junos OS Evolved IPv6 Malformed Packet Memory Exhaustion Denial of Service
A Missing Release of Memory after Effective Lifetime vulnerability in the Juniper Tunnel Driver (jtd) of Juniper Networks Junos OS Evolved allows an unauthenticated network-based attacker to cause Denial of Service. Receipt of specifically malformed IPv6 packets, destined to the device, causes kernel memory to not be freed, resulting in memory exhaustion leading to a system […]
CVE-2025-21596 – Juniper Networks Junos OS SRX1500, SRX4100, SRX4200 Denial of Service (DoS) Command Injectionunga
An Improper Handling of Exceptional Conditions vulnerability in the command-line processing of Juniper Networks Junos OS on SRX1500, SRX4100, and SRX4200 devices allows a local, low-privileged authenticated attacker executing the ‘show chassis environment pem’ command to cause the chassis daemon (chassisd) to crash and restart, resulting in a temporary Denial of Service (DoS). However, repeated […]
CVE-2025-21593 – “Juniper Networks Junos OS and Junos OS Evolved SRv6 BGP UPDATE Packet Denial-of-Service Vulnerability”
An Improper Control of a Resource Through its Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial-of-Service (DoS). On devices with SRv6 (Segment Routing over IPv6) enabled, an attacker can send a malformed BGP UPDATE packet which will […]
CVE-2025-21592 – Juniper Networks Junos OS SRX Series Information Disclosure Vulnerability
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Juniper Networks Junos OS on SRX Series devices allows a local, low-privileged user with access to the Junos CLI to view the contents of sensitive files on the file system. Through the execution of either ‘show services advanced-anti-malware’ or ‘show […]
CVE-2025-21600 – “Juniper Networks Junos OS and Junos OS Evolved BGP Daemon OOB Read DoS”
An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, logically adjacent BGP peer sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create […]
CVE-2025-22826 – Adobe Wpecommerce Cross-site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-22826 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 09, 2025 Action […]
CVE-2025-22827 – Joomag Cross-site Scripting (XSS) Vulnerability
The following table lists the changes that have been made to the CVE-2025-22827 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 09, 2025 Action […]
CVE-2025-22824 – Lucia Intelisano Live Flight Radar Stored Cross-Site Scripting
The following table lists the changes that have been made to the CVE-2025-22824 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 09, 2025 Action […]
CVE-2025-22823 – “Genesis Style Shortcodes DOM-Based Cross-site Scripting”
The following table lists the changes that have been made to the CVE-2025-22823 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 09, 2025 Action […]