Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2015-7755 | Juniper | ScreenOS | Juniper ScreenOS Improper Authentication Vulnerability Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device. | 9.8 CISA | 2025-10-02 | 2025-10-23 | Unknown |
| CVE-2025-21590 | Juniper | Junos OS | Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker with high privileges to inject arbitrary code. | 4.4 CNA | 2025-03-13 | 2025-04-03 | Unknown |
| CVE-2023-36851 | Juniper | Junos OS | Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. | 5.3 CNA | 2023-11-13 | 2023-11-17 | Unknown |
| CVE-2023-36847 | Juniper | Junos OS | Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. | 5.3 CNA | 2023-11-13 | 2023-11-17 | Unknown |
| CVE-2023-36846 | Juniper | Junos OS | Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. | 5.3 CNA | 2023-11-13 | 2023-11-17 | Unknown |
| CVE-2023-36845 | Juniper | Junos OS | Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafted request, which sets the variable PHPRC, an attacker is able to modify the PHP execution environment allowing the injection und execution of code. | 9.8 CNA | 2023-11-13 | 2023-11-17 | Unknown |
| CVE-2023-36844 | Juniper | Junos OS | Juniper Junos OS EX Series PHP External Variable Modification Vulnerability Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables, leading to partial loss of integrity, which may allow chaining to other vulnerabilities. | 5.3 CNA | 2023-11-13 | 2023-11-17 | Unknown |
| CVE-2020-1631 | Juniper | Junos OS | Juniper Junos OS Path Traversal Vulnerability A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution. | 8.8 CNA | 2022-03-25 | 2022-04-15 | Unknown |