Vulnerability index

Browse CVEs

70 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2026-34490 Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherw… Xaap 1.53+ Fix from $1,6002026-07-31 MEDIUM 5.4 CVE-2026-34495 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Sto… Fms Employee after 2025.3.1 Fix from $1,6002026-07-31 MEDIUM 5.4 CVE-2026-34497 Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site… Fms Employee after 2025.3.1 Fix from $1,6002026-07-31 CRITICAL 9.8 CVE-2026-21662 Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affec… Fms Employee after 2025.3.1 Fix from $2,3002026-07-31 CRITICAL 9.8 CVE-2026-21659 Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Q… Frick Controls Quantum Hd Firmware after 10.22 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-21660 Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD vers… Frick Controls Quantum Hd Firmware after 10.22 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-21654 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum H… Frick Controls Quantum Hd Firmware after 10.22 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-21656 Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insuffic… Frick Controls Quantum Hd Firmware after 10.22 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-21657 Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insuffic… Frick Controls Quantum Hd Firmware after 10.22 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-21658 Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls … Frick Controls Quantum Hd Firmware after 10.22 Fix from $2,3002026-02-27 MEDIUM 5.7 CVE-2024-32931 Under certain circumstances the exacqVision Web Service can expose authentication token details within communications. Exacqvision Web Service after 24.03 Fix from $1,6002024-08-01 HIGH 8.1 CVE-2024-32862 Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains. Exacqvision Web Service after 24.03 Fix from $1,9502024-08-01 HIGH 7.5 CVE-2024-32758 Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange Exacqvision Client 24.06+ Fix from $1,9502024-08-01 HIGH 7.3 CVE-2024-32865 Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices. Exacqvision Server 24.06+ Fix from $1,9502024-08-01 HIGH 8.1 CVE-2024-32864 Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS) Exacqvision Web Service after 24.03 Fix from $1,9502024-08-01 HIGH 8.8 CVE-2024-32863 Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF) Exacqvision Web Service after 24.03 Fix from $1,9502024-08-01 CRITICAL 9.8 CVE-2024-0242 Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings. Qolsys Iq Panel 4 Firmware 4.4.2+ Fix from $2,3002024-02-08 MEDIUM 5.3 CVE-2023-0248 An attacker with physical access to the Kantech Gen1 ioSmart card reader with firmware version prior to 1.07.02 in certain circumstances can recover … Iosmart Gen 1 Firmware 1.07.02+ Fix from $1,6002023-12-14 HIGH 7.5 CVE-2023-4486 Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC e… Nae55 Firmware 12.0.4+ Fix from $1,9502023-12-07 CRITICAL 9.8 CVE-2023-4804 An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed. Quantum Hd Unity Compressor Firmware 11.11 / 11.12+ Fix from $2,3002023-11-10 MEDIUM 5.5 CVE-2023-3749 A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation. Videoedge 6.1.1+ Fix from $1,6002023-08-03 CRITICAL 9.8 CVE-2023-3548 An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack. Iq Wifi 6 Firmware 2.0.2+ Fix from $2,3002023-07-25 CRITICAL 9.8 CVE-2023-3127 An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights. Istar Ultra Firmware 6.9.2+ Fix from $2,3002023-07-11 CRITICAL 9.8 CVE-2023-0954 A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentials after a long period of sus… Illustra Pro Gen 4 Dome Firmware No fix yet Fix from $2,3002023-06-08 HIGH 7.5 CVE-2023-2024 Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain c… Openblue Enterprise Manager Data Collector 3.2.5.75+ Fix from $1,9502023-05-18 MEDIUM 6.5 CVE-2023-2025 OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumst… Openblue Enterprise Manager Data Collector 3.2.5.75+ Fix from $1,6002023-05-18 MEDIUM 6.1 CVE-2022-21939 Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 … Metasys System Configuration Tool 14.2.3 / 15.0.3+ Fix from $1,6002023-02-09 MEDIUM 6.1 CVE-2022-21940 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14… Metasys System Configuration Tool 14.2.3 / 15.0.3+ Fix from $1,6002023-02-09 HIGH 7.5 CVE-2021-36204 Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 an… Metasys Application And Data Server 10.1.6 / 11.0.3+ Fix from $1,9502023-01-13 MEDIUM 6.1 CVE-2021-36206 All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retri… Cevas 1.01.46+ Fix from $1,6002022-10-28