Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.1
CVE-2020-9044
XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII serve…
Metasys Application And Data Server
after 13.2
CRITICAL 9.8
CVE-2019-7589
A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code …
Entrapass
8.10+
CRITICAL 9.1
CVE-2019-7593
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site …
Metasys System
9.0+
CRITICAL 9.1
CVE-2019-7594
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Ma…
Metasys System
9.0+
HIGH 7.8
CVE-2019-7590
ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path. If an authenticated user is abl…
Exacqvision Server
Patch available
MEDIUM 6.5
CVE-2018-10624
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error…
Bcpro
3.0.2+
HIGH 10.0
CVE-2014-5428
Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Serve…
Metsys
Mitigation only
MEDIUM 5.0
CVE-2014-5427
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Cont…
Metsys
Mitigation only
MEDIUM 5.0
CVE-2012-4026
The Johnson Controls Pegasys P2000 server with software before 3.11 allows remote attackers to trigger false alerts via crafted packets to TCP port 4…
Pegasys P2000 Server Software
after 3.10
HIGH 7.5
CVE-2012-2607
The Johnson Controls CK721-A controller with firmware before SSM4388_03.1.0.14_BB allows remote attackers to perform arbitrary actions via crafted pa…
Network Controller
after 03.1.0.14