漏洞列表 350655
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2026-0203
Junos OS: Receipt of a specifically malformed ICMP packet causes an FPC restart
HIGH 7.1 2026-01-15
Juniper Networks Junos OS
CVE NVD
CVE-2025-60011
Junos OS and Junos OS Evolved: Optional transitive BGP attribute is modified before propagation to peers causing sessions to flap
MEDIUM 6.9 2026-01-15
Juniper Networks Junos OS Juniper Networks Junos OS Evolved
CVE NVD
CVE-2025-60007
Junos OS: A specifically crafted 'show chassis' command causes chassisd to crash
MEDIUM 6.8 2026-01-15
Juniper Networks Junos OS
CVE NVD
CVE-2025-60003
Junos OS and Junos OS Evolved: BGP update with a set of specific attributes causes rpd crash
HIGH 8.7 2026-01-15
Juniper Networks Junos OS Juniper Networks Junos OS Evolved
CVE NVD
CVE-2025-59961
Junos OS and Junos OS Evolved: Unix socket used to control the jdhcpd process is world-writable
MEDIUM 6.8 2026-01-15
Juniper Networks Junos OS Juniper Networks Junos OS Evolved
CVE NVD
CVE-2025-59960
Junos OS and Junos OS Evolved: DHCP Option 82 messages from clients being passed unmodified to the DHCP server
MEDIUM 6.3 2026-01-15
Juniper Networks Junos OS Juniper Networks Junos OS Evolved
CVE NVD
CVE-2025-59959
Junos OS and Junos OS Evolved: Executing a specific show command leads to an rpd crash
MEDIUM 6.8 2026-01-15
Juniper Networks Junos OS Juniper Networks Junos OS Evolved
CVE NVD
CVE-2025-52987
Paragon Automation: A clickjacking vulnerability in the web server configuration has been addressed
MEDIUM 5.1 2026-01-15
Juniper Networks Paragon Automation (Pathfinder, Planner, Insights)
CVE NVD
CVE-2025-15265
Svelte 5.46.0 - Hydratable Key Script-Breakout XSS (SSR)
MEDIUM 5.3 2026-01-15
Svelte Svelte
CVE NVD
CVE-2026-23746
Entrust Instant Financial Issuance (IFI) SmartCardController Service .NET Remoting RCE
CRITICAL 9.3 2026-01-15
Entrust Corporation Instant Financial Issuance (IF)
CVE NVD
CVE-2026-23622
CSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeover
HIGH 7.4 2026-01-15
alextselegidis easyappointments
CVE NVD
CVE-2026-23527
Request Smuggling (TE.TE) in h3 v1
HIGH 8.9 2026-01-15
h3js h3
CVE NVD
CVE-2026-23520
Arcane has a Command Injection in Arcane Updater Lifecycle Labels Enables RCE
CRITICAL 9.1 2026-01-15
getarcaneapp arcane
CVE NVD
CVE-2026-23766
Istio through 1.28.2 allows iptables rule injection for changing firewall behavior via the traffic.s...
MEDIUM 4.1 2026-01-15
Istio Istio
CVE NVD
CVE-2026-23519
RustCrypto cmov: thumbv6m-none-eabi compiler emits non-constant time assembly when using cmovnz
HIGH 8.9 2026-01-15
RustCrypto utils
CVE NVD
CVE-2026-23511
ZITADEL has a user enumeration vulnerability in Login UIs
MEDIUM 5.3 2026-01-15
zitadel zitadel zitadel zitadel
CVE NVD
CVE-2026-22775
devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse
HIGH 7.5 2026-01-15
sveltejs devalue
CVE NVD
CVE-2026-22774
devalue vulnerable to denial of service due to memory exhaustion in devalue.parse
HIGH 7.5 2026-01-15
sveltejs devalue
CVE NVD
CVE-2026-0227
PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal
MEDIUM 6.6 2026-01-15
Palo Alto Networks Cloud NGFW Palo Alto Networks PAN-OS +1个
CVE NVD
CVE-2026-22249
Docmost affected by an Arbitrary File Write via Zip Import Feature (ZipSlip)
HIGH 7.1 2026-01-15
docmost docmost
CVE NVD