CVE search

401,009 results
CVE-2026-64893HIGH- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issuEPSS 0.1%CVE-2026-64892MEDIUM- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations. This EPSS 0.2%CVE-2026-104356HIGHPictShare < 3.7.1 Predictable Delete Code via rand()EPSS 0.3%CVE-2026-34494HIGH- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue EPSS 0.2%CVE-2026-34493HIGH- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations. This issue affeEPSS 0.2%CVE-2026-71449CRITICAL: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue aEPSS 0.3%CVE-2026-71448MEDIUM: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affecEPSS 0.1%CVE-2026-71454MEDIUMImproper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63EPSS 0.2%CVE-2026-71453MEDIUM- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO EPSS 0.1%CVE-2026-104051HIGHPictShare < 3.7.1 Sensitive Information Disclosure via info APIEPSS 0.4%CVE-2026-71452HIGH- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.EPSS 0.7%CVE-2026-104002MEDIUMFail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)EPSS 0.3%CVE-2026-71451MEDIUM- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0EPSS 0.4%CVE-2026-27874MEDIUM: Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. TEPSS 0.1%CVE-2026-102370MEDIUMPhysical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71EPSS 0.2%CVE-2026-104020HIGHUncontrolled recursion in the Ion reader in Amazon Ion PythonEPSS 0.4%CVE-2026-96780HIGHfiglet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small widthEPSS 0.4%CVE-2026-104183MEDIUMstream-json: Prototype pollution: Assembler writes this.current[this.key] on plain objectsEPSS 0.2%CVE-2026-104182MEDIUMstream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunkEPSS 0.1%CVE-2026-104181MEDIUMFilament: Multi-factor authentication (app) management actions do not require password reauthenticationEPSS 0.3%