Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2026-34490
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherw…
Xaap
1.53+
MEDIUM 5.4
CVE-2026-34495
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Sto…
Fms Employee
after 2025.3.1
MEDIUM 5.4
CVE-2026-34497
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site…
Fms Employee
after 2025.3.1
CRITICAL 9.8
CVE-2026-21662
Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.
This issue affec…
Fms Employee
after 2025.3.1
CRITICAL 9.8
CVE-2026-21659
Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Q…
Frick Controls Quantum Hd Firmware
after 10.22
CRITICAL 9.8
CVE-2026-21660
Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD vers…
Frick Controls Quantum Hd Firmware
after 10.22
CRITICAL 9.8
CVE-2026-21654
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum H…
Frick Controls Quantum Hd Firmware
after 10.22
CRITICAL 9.8
CVE-2026-21656
Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insuffic…
Frick Controls Quantum Hd Firmware
after 10.22
CRITICAL 9.8
CVE-2026-21657
Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insuffic…
Frick Controls Quantum Hd Firmware
after 10.22
CRITICAL 9.8
CVE-2026-21658
Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls …
Frick Controls Quantum Hd Firmware
after 10.22
MEDIUM 5.7
CVE-2024-32931
Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.
Exacqvision Web Service
after 24.03
HIGH 8.1
CVE-2024-32862
Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains.
Exacqvision Web Service
after 24.03
HIGH 7.5
CVE-2024-32758
Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange
Exacqvision Client
24.06+
HIGH 7.3
CVE-2024-32865
Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices.
Exacqvision Server
24.06+
HIGH 8.1
CVE-2024-32864
Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)
Exacqvision Web Service
after 24.03
HIGH 8.8
CVE-2024-32863
Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF)
Exacqvision Web Service
after 24.03
CRITICAL 9.8
CVE-2024-0242
Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings.
Qolsys Iq Panel 4 Firmware
4.4.2+
MEDIUM 5.3
CVE-2023-0248
An attacker with physical access to the Kantech Gen1 ioSmart card reader with firmware version prior to 1.07.02 in certain circumstances can recover …
Iosmart Gen 1 Firmware
1.07.02+
HIGH 7.5
CVE-2023-4486
Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC e…
Nae55 Firmware
12.0.4+
CRITICAL 9.8
CVE-2023-4804
An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.
Quantum Hd Unity Compressor Firmware
11.11 / 11.12+
MEDIUM 5.5
CVE-2023-3749
A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.
Videoedge
6.1.1+
CRITICAL 9.8
CVE-2023-3548
An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.
Iq Wifi 6 Firmware
2.0.2+
CRITICAL 9.8
CVE-2023-3127
An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
Istar Ultra Firmware
6.9.2+
CRITICAL 9.8
CVE-2023-0954
A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentials after a long period of sus…
Illustra Pro Gen 4 Dome Firmware
No fix yet
HIGH 7.5
CVE-2023-2024
Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain c…
Openblue Enterprise Manager Data Collector
3.2.5.75+
MEDIUM 6.5
CVE-2023-2025
OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumst…
Openblue Enterprise Manager Data Collector
3.2.5.75+
MEDIUM 6.1
CVE-2022-21939
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 …
Metasys System Configuration Tool
14.2.3 / 15.0.3+
MEDIUM 6.1
CVE-2022-21940
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14…
Metasys System Configuration Tool
14.2.3 / 15.0.3+
HIGH 7.5
CVE-2021-36204
Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 an…
Metasys Application And Data Server
10.1.6 / 11.0.3+
MEDIUM 6.1
CVE-2021-36206
All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retri…
Cevas
1.01.46+