Vulnerability index

Browse CVEs

70 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

C Cure 9000 Firmware MEDIUM 5.3
CVE-2021-36201

Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.

Fix: after 2.90
Fix from $1,600 2022-10-11
Metasys Extended Application And Data Server MEDIUM 6.5
CVE-2022-21936

On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when usin…

Mitigation only
Fix from $1,600 2022-10-07
Istar Ultra Firmware CRITICAL 9.8
CVE-2022-21941

All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to…

Fix: 6.8.9.cu01+
Fix from $2,300 2022-08-31
Metasys Application And Data Server MEDIUM 5.3
CVE-2021-36200

Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions …

Fix: 10.1.6 / 11.0.2+
Fix from $1,600 2022-07-22
Metasys Application And Data Server MEDIUM 5.4
CVE-2022-21938

Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 c…

Fix: 10.1.5+
Fix from $1,600 2022-06-15
Metasys Application And Data Server HIGH 7.5
CVE-2022-21935

A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password cha…

Fix: 10.1.5+
Fix from $1,950 2022-06-15
Metasys Application And Data Server MEDIUM 5.4
CVE-2022-21937

Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 c…

Fix: 10.1.5+
Fix from $1,600 2022-06-15
Metasys Application And Data Server HIGH 8.8
CVE-2022-21934

Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server …

Fix: 10.1.5 / 11.0.2+
Fix from $1,950 2022-05-06
Metasys Application And Data Server HIGH 8.8
CVE-2021-36207

Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an authenticated user to elev…

Fix: 10.1.5 / 11.0.2+
Fix from $1,950 2022-04-29
Metasys System Configuration Tool CRITICAL 9.1
CVE-2021-36203

The affected product may allow an attacker to identify and forge requests to internal systems by way of a specially crafted request.

Fix: 14.2.2+
Fix from $2,300 2022-04-22
Metasys Application And Data Server CRITICAL 9.8
CVE-2021-36205

Under certain circumstances the session token is not cleared on logout.

Fix: 10.1.5 / 11.0.2+
Fix from $2,300 2022-04-15
Easyio Cpt Graphics MEDIUM 5.3
CVE-2022-26643

An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.

No fix yet
Fix from $1,600 2022-04-13
Metasys Application And Data Server HIGH 8.8
CVE-2021-36202

Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the …

Fix: 10.1.5 / 11.0.2+
Fix from $1,950 2022-04-07
Videoedge MEDIUM 5.3
CVE-2021-36199

Running a vulnerability scanner against VideoEdge NVRs can cause some functionality to stop.

Fix: after 5.7.1
Fix from $1,600 2022-01-14
Kantech Entrapass HIGH 7.5
CVE-2021-36198

Successful exploitation of this vulnerability could allow an unauthorized user to access sensitive data.

Fix: 8.40+
Fix from $1,950 2021-12-06
Exacqvision Web Service CRITICAL 9.8
CVE-2021-27664

Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.

Fix: after 20.06.11.0
Fix from $2,300 2021-10-11
Exacqvision Server HIGH 7.5
CVE-2021-27665

An unauthenticated remote user could exploit a potential integer overflow condition in the exacqVision Server with a specially crafted script and cau…

Fix: after 21.06.11.0
Fix from $1,950 2021-10-11
Kantech Kt 1 Door Controller Firmware HIGH 8.1
CVE-2021-27662

The KT-1 door controller is susceptible to replay or man-in-the-middle attacks where an attacker can record and replay TCP packets. This issue affect…

Fix: after 3.01
Fix from $1,950 2021-09-15
Ac2000 Firmware CRITICAL 9.8
CVE-2021-27663

A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequat…

Fix: after 10.5
Fix from $2,300 2021-08-30
C Cure 9000 Firmware HIGH 8.8
CVE-2021-27660

An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.

Fix: 2.80+
Fix from $1,950 2021-07-01
F4 Snc Firmware HIGH 8.8
CVE-2021-27661

Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user an uninte…

Mitigation only
Fix from $1,950 2021-07-01
Exacqvision Web Service MEDIUM 6.1
CVE-2021-27659

exacqVision Web Service 21.03 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output tha…

Fix: after 21.03
Fix from $1,600 2021-06-24
Exacqvision Enterprise Manager MEDIUM 5.4
CVE-2021-27658

exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in out…

Fix: after 20.12
Fix from $1,600 2021-06-24
Metasys HIGH 8.8
CVE-2021-27657

Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allow…

Fix: after 11.0
Fix from $1,950 2021-06-04
Exacqvision Web Service HIGH 7.5
CVE-2021-27656

A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exa…

Fix: after 20.12.2.0
Fix from $1,950 2021-03-18
Metasys Reporting Engine HIGH 7.5
CVE-2020-9050

Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenticated attacker to access and …

Mitigation only
Fix from $1,950 2021-02-19
C Cure Web MEDIUM 5.3
CVE-2020-9049

A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated atta…

Fix: after 5.6
Fix from $1,600 2020-11-19
Victor Web Client HIGH 8.1
CVE-2020-9048

A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated…

Fix: after 5.4.1
Fix from $1,950 2020-10-08
Exacqvision Enterprise Manager HIGH 7.2
CVE-2020-9047EPSS 8%

A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service ve…

Fix: after 20.06.4.0
Fix from $1,950 2020-06-26
Kantech Entrapass HIGH 7.8
CVE-2020-9046

A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level pri…

Fix: after 8.22
Fix from $1,950 2020-05-26