Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.3
CVE-2021-36201
Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.
C Cure 9000 Firmware
after 2.90
MEDIUM 6.5
CVE-2022-21936
On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when usin…
Metasys Extended Application And Data Server
Mitigation only
CRITICAL 9.8
CVE-2022-21941
All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to…
Istar Ultra Firmware
6.8.9.cu01+
MEDIUM 5.3
CVE-2021-36200
Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions …
Metasys Application And Data Server
10.1.6 / 11.0.2+
MEDIUM 5.4
CVE-2022-21938
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 c…
Metasys Application And Data Server
10.1.5+
HIGH 7.5
CVE-2022-21935
A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password cha…
Metasys Application And Data Server
10.1.5+
MEDIUM 5.4
CVE-2022-21937
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 c…
Metasys Application And Data Server
10.1.5+
HIGH 8.8
CVE-2022-21934
Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server …
Metasys Application And Data Server
10.1.5 / 11.0.2+
HIGH 8.8
CVE-2021-36207
Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an authenticated user to elev…
Metasys Application And Data Server
10.1.5 / 11.0.2+
CRITICAL 9.1
CVE-2021-36203
The affected product may allow an attacker to identify and forge requests to internal systems by way of a specially crafted request.
Metasys System Configuration Tool
14.2.2+
CRITICAL 9.8
CVE-2021-36205
Under certain circumstances the session token is not cleared on logout.
Metasys Application And Data Server
10.1.5 / 11.0.2+
MEDIUM 5.3
CVE-2022-26643
An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.
Easyio Cpt Graphics
No fix yet
HIGH 8.8
CVE-2021-36202
Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the …
Metasys Application And Data Server
10.1.5 / 11.0.2+
MEDIUM 5.3
CVE-2021-36199
Running a vulnerability scanner against VideoEdge NVRs can cause some functionality to stop.
Videoedge
after 5.7.1
HIGH 7.5
CVE-2021-36198
Successful exploitation of this vulnerability could allow an unauthorized user to access sensitive data.
Kantech Entrapass
8.40+
CRITICAL 9.8
CVE-2021-27664
Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.
Exacqvision Web Service
after 20.06.11.0
HIGH 7.5
CVE-2021-27665
An unauthenticated remote user could exploit a potential integer overflow condition in the exacqVision Server with a specially crafted script and cau…
Exacqvision Server
after 21.06.11.0
HIGH 8.1
CVE-2021-27662
The KT-1 door controller is susceptible to replay or man-in-the-middle attacks where an attacker can record and replay TCP packets. This issue affect…
Kantech Kt 1 Door Controller Firmware
after 3.01
CRITICAL 9.8
CVE-2021-27663
A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequat…
Ac2000 Firmware
after 10.5
HIGH 8.8
CVE-2021-27660
An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.
C Cure 9000 Firmware
2.80+
HIGH 8.8
CVE-2021-27661
Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user an uninte…
F4 Snc Firmware
Mitigation only
MEDIUM 6.1
CVE-2021-27659
exacqVision Web Service 21.03 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output tha…
Exacqvision Web Service
after 21.03
MEDIUM 5.4
CVE-2021-27658
exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in out…
Exacqvision Enterprise Manager
after 20.12
HIGH 8.8
CVE-2021-27657
Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allow…
Metasys
after 11.0
HIGH 7.5
CVE-2021-27656
A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exa…
Exacqvision Web Service
after 20.12.2.0
HIGH 7.5
CVE-2020-9050
Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenticated attacker to access and …
Metasys Reporting Engine
Mitigation only
MEDIUM 5.3
CVE-2020-9049
A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated atta…
C Cure Web
after 5.6
HIGH 8.1
CVE-2020-9048
A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated…
Victor Web Client
after 5.4.1
HIGH 7.2
CVE-2020-9047EPSS 8%
A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service ve…
Exacqvision Enterprise Manager
after 20.06.4.0
HIGH 7.8
CVE-2020-9046
A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level pri…
Kantech Entrapass
after 8.22