CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-61740HIGH | Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG Origin Validation ErrorAuthentication issue that does not verify the source of a packet which could allow an attacker to create a denial-of-service condition or modify the configuration of the device. CWE-346Dec 22, 2025 | CVSS7.2v4.0 | EPSS0.123% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-26379HIGH | Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG use of Cryptographically Weak Pseudo-Random Number GeneratorUse of a weak pseudo-random number generator, which may allow an attacker to read or inject encrypted PowerG packets. CWE-338Dec 22, 2025 | CVSS7.2v4.0 | EPSS0.166% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-61739HIGH | Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG reusing a nonce, key pair in encryptionDue to Nonce reuse, attackers can perform reply attack or decrypt captured packets. CWE-323Dec 22, 2025 | CVSS7.2v4.0 | EPSS0.166% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |