cbcvebase.

Juniper Junos Space vulnerabilities

78 known vulnerabilities affecting juniper/junos_space.

Total CVEs
78
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH15MEDIUM53

Vulnerabilities

Page 3 of 4
CVE-2016-4931P4MEDIUMCVSS 6.5≤ 15.22017-03-20
CVE-2016-4931 [MEDIUM] CWE-611 CVE-2016-4931: XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service. XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service.
nvd
CVE-2025-59983P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-59983 [MEDIUM] CWE-79 CVE-2025-59983: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Template Definition page, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This issue affe
nvd
CVE-2025-59981P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-59981 [MEDIUM] CWE-79 CVE-2025-59981: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Device Template Definition page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.Thi
nvd
CVE-2025-59982P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-59982 [MEDIUM] CWE-79 CVE-2025-59982: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the dashboard search field that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This issue a
nvd
CVE-2025-59989P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-59989 [MEDIUM] CWE-79 CVE-2025-59989: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Device Discovery page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue a
nvd
CVE-2026-21904P4MEDIUMCVSS 6.1v1.0v1.1+64 more2026-04-09
CVE-2026-21904 [MEDIUM] CWE-79 CVE-2026-21904: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the list filter field that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue aff
nvd
CVE-2025-59996P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-59996 [MEDIUM] CWE-79 CVE-2025-59996: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Configuration View page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue
nvd
CVE-2025-59995P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-59995 [MEDIUM] CWE-79 CVE-2025-59995: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Quick Template page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue aff
nvd
CVE-2025-59997P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-59997 [MEDIUM] CWE-79 CVE-2025-59997: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the CLI Configlets pages that, when visited by another user, enable the attacker to execute commands with the target's permissions, including an administrator. This issue aff
nvd
CVE-2025-60000P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-60000 [MEDIUM] CWE-79 CVE-2025-60000: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Generate Report page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue af
nvd
CVE-2025-60002P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-60002 [MEDIUM] CWE-79 CVE-2025-60002: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Template Definitions page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This iss
nvd
CVE-2025-59998P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-59998 [MEDIUM] CWE-79 CVE-2025-59998: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Archive Log screen that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue affe
nvd
CVE-2025-59994P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-59994 [MEDIUM] CWE-79 CVE-2025-59994: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Quick Template page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue aff
nvd
CVE-2025-59992P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-59992 [MEDIUM] CWE-79 CVE-2025-59992: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Secure Console page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue aff
nvd
CVE-2025-59993P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-59993 [MEDIUM] CWE-79 CVE-2025-59993: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Space Node Setting fields that, when visited by another user, enable the attacker to execute commands with the target's permissions, including an administrator. This issu
nvd
CVE-2025-59985P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-59985 [MEDIUM] CWE-79 CVE-2025-59985: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in a field on the Purging Policy page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This
nvd
CVE-2025-60001P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-60001 [MEDIUM] CWE-79 CVE-2025-60001: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Generate Report page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue af
nvd
CVE-2025-60009P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-60009 [MEDIUM] CWE-79 CVE-2025-60009: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the CLI Configlet page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue a
nvd
CVE-2025-59990P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-59990 [MEDIUM] CWE-79 CVE-2025-59990: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the template creation pages that, when visited by another user, enable the attacker to execute commands with the target's permissions, including an administrator. This issue
nvd
CVE-2025-59988P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-59988 [MEDIUM] CWE-79 CVE-2025-59988: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Generate Report page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue af
nvd
Juniper Junos Space vulnerabilities | cvebase