Search
Search Results (13 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-64896 | 1 Johnson Controls | 1 T2000 | 2026-08-27 | N/A |
| Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects T2000: before 31.6. | ||||
| CVE-2026-34491 | 2 Johnson Controls, Johnsoncontrols | 3 Metasys 14, Metasys 15, Metasys | 2026-08-25 | N/A |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls Metasys 14 and Johnson Controls Metasys 15 allows Cross Site Scripting. This issue affects Metasys 14: before 14.1.5; Metasys 15: before 15.0.1. | ||||
| CVE-2026-21661 | 2 Johnson Controls, Johnsoncontrols | 2 Ac2000, Ac2000 | 2026-08-24 | N/A |
| An Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Configuration File Search Paths. This issue affects AC2000: from 10.6 before release 10, from 11.0 before release 9, from 12 before release 3. | ||||
| CVE-2026-27875 | 2 Johnson Controls, Johnsoncontrols | 2 Simplex Incident Manager Autocall Fire Administrator, Simplex Incident Manager / Autocall Fire Administrator | 2026-08-21 | N/A |
| Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data. This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05. | ||||
| CVE-2026-64887 | 2 Johnson Controls, Johnsoncontrols | 2 Airwall, Airwall | 2026-08-17 | N/A |
| Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack. This issue affects Airwall: before 4.1. | ||||
| CVE-2026-34492 | 2 Johnson Controls, Johnsoncontrols | 2 Airwall, Airwall | 2026-08-17 | N/A |
| External control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipulation. This issue affects Airwall: before 4.1. | ||||
| CVE-2026-27871 | 1 Johnson Controls | 1 Tl280 | 2026-08-14 | N/A |
| Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Johnson Controls TL280 allows Cryptanalytic Attack. This issue affects TL280: before 5.63. | ||||
| CVE-2026-21655 | 3 Johnson Control, Johnson Controls, Johnsoncontrols | 4 Victor, Ccure 9000, Victor Application Server and 1 more | 2026-08-06 | N/A |
| Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1. | ||||
| CVE-2026-34490 | 2 Johnson Controls, Johnsoncontrols | 3 Xaap Application, Xaap, Xaap Application | 2026-08-02 | 5.5 Medium |
| Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53. | ||||
| CVE-2026-21662 | 2 Johnson Controls, Johnsoncontrols | 3 Fm Systems Employee, Fm Systems Employee, Fms Employee | 2026-08-02 | 9.8 Critical |
| Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1. | ||||
| CVE-2026-34495 | 2 Johnson Controls, Johnsoncontrols | 3 Fm Systems Employee, Fm Systems Employee, Fms Employee | 2026-08-02 | 5.4 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: before 2025.3.1. | ||||
| CVE-2026-34497 | 2 Johnson Controls, Johnsoncontrols | 3 Fm Systems Employee, Fm Systems Employee, Fms Employee | 2026-08-02 | 5.4 Medium |
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1. | ||||
| CVE-2026-34496 | 2 Johnson Controls, Johnsoncontrols | 2 Victor Web, Victor Web | 2026-07-24 | N/A |
| Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1. | ||||
Page 1 of 1.