Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Johnsoncontrols

16 known vulnerabilities

7
CRITICAL
3
MEDIUM

Top Products

frick controls quantum hd firmware 6 frick controls quantum hd 6 fms employee 3 xaap 1
10 CVEs
5.4
CVE-2026-34497

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Syste

5.4
CVE-2026-34495

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls F

5.5
CVE-2026-34490

Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attac

9.8
CVE-2026-21662

Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malic

9.8
CVE-2026-21660

A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in

9.8
CVE-2026-21659

Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in John

9.8
CVE-2026-21658

Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Joh

9.8
CVE-2026-21657

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD al

9.8
CVE-2026-21656

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD al

9.8
CVE-2026-21654

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Cont

Frequently Asked Questions

How many CVEs affect Johnsoncontrols?

Johnsoncontrols has 16 CVE records in our database, including 13 critical and 0 high severity vulnerabilities.

What are the most severe Johnsoncontrols vulnerabilities?

Johnsoncontrols has 13 critical severity (CVSS 9.0+) and 0 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Johnsoncontrols vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Johnsoncontrols products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Johnsoncontrols Vulnerabilities

CyberStrike scans your infrastructure for Johnsoncontrols vulnerabilities and provides real-time remediation guidance.

Get Started