CVE search
401,009 resultsCVE-2026-64893HIGH- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack.
This issuEPSS 0.1%CVE-2026-64892MEDIUM- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations.
This EPSS 0.2%CVE-2026-104356HIGHPictShare < 3.7.1 Predictable Delete Code via rand()EPSS 0.3%CVE-2026-34494HIGH- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations.
This issue EPSS 0.2%CVE-2026-34493HIGH- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations.
This issue affeEPSS 0.2%CVE-2026-71449CRITICAL: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data.
This issue aEPSS 0.3%CVE-2026-71448MEDIUM: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse.
This issue affecEPSS 0.1%CVE-2026-71454MEDIUMImproper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63EPSS 0.2%CVE-2026-71453MEDIUM- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack.
This issue affects EasyIO EPSS 0.1%CVE-2026-104051HIGHPictShare < 3.7.1 Sensitive Information Disclosure via info APIEPSS 0.4%CVE-2026-71452HIGH- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection.
This issue affects EasyIO FS32: before 3.EPSS 0.7%CVE-2026-104002MEDIUMFail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)EPSS 0.3%CVE-2026-71451MEDIUM- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection.
This issue affects EasyIO FS32: before 3.0EPSS 0.4%CVE-2026-27874MEDIUM: Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials.
TEPSS 0.1%CVE-2026-102370MEDIUMPhysical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71EPSS 0.2%CVE-2026-104020HIGHUncontrolled recursion in the Ion reader in Amazon Ion PythonEPSS 0.4%CVE-2026-96780HIGHfiglet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small widthEPSS 0.4%CVE-2026-104183MEDIUMstream-json: Prototype pollution: Assembler writes this.current[this.key] on plain objectsEPSS 0.2%CVE-2026-104182MEDIUMstream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunkEPSS 0.1%CVE-2026-104181MEDIUMFilament: Multi-factor authentication (app) management actions do not require password reauthenticationEPSS 0.3%