Vulnerability index

Browse CVEs

70 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xaap MEDIUM 5.5
CVE-2026-34490

Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherw…

Fix: 1.53+
Fix from $1,600 2026-07-31
Fms Employee MEDIUM 5.4
CVE-2026-34495

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Sto…

Fix: after 2025.3.1
Fix from $1,600 2026-07-31
Fms Employee MEDIUM 5.4
CVE-2026-34497

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site…

Fix: after 2025.3.1
Fix from $1,600 2026-07-31
Fms Employee CRITICAL 9.8
CVE-2026-21662

Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affec…

Fix: after 2025.3.1
Fix from $2,300 2026-07-31
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21659

Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Q…

Fix: after 10.22
Fix from $2,300 2026-02-27
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21660

Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD vers…

Fix: after 10.22
Fix from $2,300 2026-02-27
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21654

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum H…

Fix: after 10.22
Fix from $2,300 2026-02-27
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21656

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insuffic…

Fix: after 10.22
Fix from $2,300 2026-02-27
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21657

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insuffic…

Fix: after 10.22
Fix from $2,300 2026-02-27
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21658

Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls …

Fix: after 10.22
Fix from $2,300 2026-02-27
Exacqvision Web Service MEDIUM 5.7
CVE-2024-32931

Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.

Fix: after 24.03
Fix from $1,600 2024-08-01
Exacqvision Web Service HIGH 8.1
CVE-2024-32862

Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains.

Fix: after 24.03
Fix from $1,950 2024-08-01
Exacqvision Client HIGH 7.5
CVE-2024-32758

Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange

Fix: 24.06+
Fix from $1,950 2024-08-01
Exacqvision Server HIGH 7.3
CVE-2024-32865

Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices.

Fix: 24.06+
Fix from $1,950 2024-08-01
Exacqvision Web Service HIGH 8.1
CVE-2024-32864

Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)

Fix: after 24.03
Fix from $1,950 2024-08-01
Exacqvision Web Service HIGH 8.8
CVE-2024-32863

Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF)

Fix: after 24.03
Fix from $1,950 2024-08-01
Qolsys Iq Panel 4 Firmware CRITICAL 9.8
CVE-2024-0242

Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings.

Fix: 4.4.2+
Fix from $2,300 2024-02-08
Iosmart Gen 1 Firmware MEDIUM 5.3
CVE-2023-0248

An attacker with physical access to the Kantech Gen1 ioSmart card reader with firmware version prior to 1.07.02 in certain circumstances can recover …

Fix: 1.07.02+
Fix from $1,600 2023-12-14
Nae55 Firmware HIGH 7.5
CVE-2023-4486

Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC e…

Fix: 12.0.4+
Fix from $1,950 2023-12-07
Quantum Hd Unity Compressor Firmware CRITICAL 9.8
CVE-2023-4804

An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.

Fix: 11.11 / 11.12+
Fix from $2,300 2023-11-10
Videoedge MEDIUM 5.5
CVE-2023-3749

A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.

Fix: 6.1.1+
Fix from $1,600 2023-08-03
Iq Wifi 6 Firmware CRITICAL 9.8
CVE-2023-3548

An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.

Fix: 2.0.2+
Fix from $2,300 2023-07-25
Istar Ultra Firmware CRITICAL 9.8
CVE-2023-3127

An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.

Fix: 6.9.2+
Fix from $2,300 2023-07-11
Illustra Pro Gen 4 Dome Firmware CRITICAL 9.8
CVE-2023-0954

A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentials after a long period of sus…

No fix yet
Fix from $2,300 2023-06-08
Openblue Enterprise Manager Data Collector HIGH 7.5
CVE-2023-2024

Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain c…

Fix: 3.2.5.75+
Fix from $1,950 2023-05-18
Openblue Enterprise Manager Data Collector MEDIUM 6.5
CVE-2023-2025

OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumst…

Fix: 3.2.5.75+
Fix from $1,600 2023-05-18
Metasys System Configuration Tool MEDIUM 6.1
CVE-2022-21939

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 …

Fix: 14.2.3 / 15.0.3+
Fix from $1,600 2023-02-09
Metasys System Configuration Tool MEDIUM 6.1
CVE-2022-21940

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14…

Fix: 14.2.3 / 15.0.3+
Fix from $1,600 2023-02-09
Metasys Application And Data Server HIGH 7.5
CVE-2021-36204

Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 an…

Fix: 10.1.6 / 11.0.3+
Fix from $1,950 2023-01-13
Cevas MEDIUM 6.1
CVE-2021-36206

All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retri…

Fix: 1.01.46+
Fix from $1,600 2022-10-28