Search Results (6 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-21655 3 Johnson Control, Johnson Controls, Johnsoncontrols 4 Victor, Ccure 9000, Victor Application Server and 1 more 2026-08-06 N/A
Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1.
CVE-2026-34490 2 Johnson Controls, Johnsoncontrols 3 Xaap Application, Xaap, Xaap Application 2026-08-02 5.5 Medium
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53.
CVE-2026-21662 2 Johnson Controls, Johnsoncontrols 3 Fm Systems Employee, Fm Systems Employee, Fms Employee 2026-08-02 9.8 Critical
Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1.
CVE-2026-34495 2 Johnson Controls, Johnsoncontrols 3 Fm Systems Employee, Fm Systems Employee, Fms Employee 2026-08-02 5.4 Medium
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: before 2025.3.1.
CVE-2026-34497 2 Johnson Controls, Johnsoncontrols 3 Fm Systems Employee, Fm Systems Employee, Fms Employee 2026-08-02 5.4 Medium
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1.
CVE-2026-34496 2 Johnson Controls, Johnsoncontrols 2 Victor Web, Victor Web 2026-07-24 N/A
Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1.