|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 12, 2026, 12:01 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 258631 | 7.5 | 危険 | Heartlogic | - | HL-SiteManager における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2010-1331 | 2010-04-2 15:02 | 2010-04-2 | Show | GitHub Exploit DB Packet Storm |
| 258632 | 9.3 | 危険 | Mozilla Foundation | - | Mozilla Firefox の Web Open Fonts Format デコーダ における整数オーバーフローの脆弱性 |
CWE-noinfo
情報不足 |
CVE-2010-1028 | 2010-04-2 14:05 | 2010-03-19 | Show | GitHub Exploit DB Packet Storm |
| 258633 | 5 | 警告 | 富士通 アクセラテクノロジ |
- | Accela BizSearch のローカル収集におけるアクセス権限に関する脆弱性 |
CWE-200
情報漏えい |
- | 2010-04-2 14:05 | 2010-03-10 | Show | GitHub Exploit DB Packet Storm |
| 258634 | 1.9 | 注意 | サイバートラスト株式会社 Linux レッドハット |
- | Linux kernel における SCSI ホストの属性に任意の変更を加えられる脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2009-3556 | 2010-04-2 14:02 | 2010-01-19 | Show | GitHub Exploit DB Packet Storm |
| 258635 | 10 | 危険 | サイバートラスト株式会社 Linux レッドハット |
- | Linux kernel の e1000e ドライバにおけるイーサネットフレームの処理に関する脆弱性 |
CWE-noinfo
情報不足 |
CVE-2009-4538 | 2010-04-2 14:02 | 2010-01-12 | Show | GitHub Exploit DB Packet Storm |
| 258636 | 6.6 | 警告 | サイバートラスト株式会社 Linux レッドハット |
- | Linux kernel の poll_mode_io ファイルにおけるドライバの I/O モードを変更される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2009-3939 | 2010-04-2 14:00 | 2009-11-16 | Show | GitHub Exploit DB Packet Storm |
| 258637 | 6.6 | 警告 | サイバートラスト株式会社 Linux レッドハット |
- | Linux kernel におけるドライバの動作およびログレベルを変更される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2009-3889 | 2010-04-2 14:00 | 2009-11-16 | Show | GitHub Exploit DB Packet Storm |
| 258638 | 7.8 | 危険 | サイバートラスト株式会社 Linux レッドハット |
- | Linux kernel の hfs サブシステムにおけるスタックベースのバッファオーバーフローの脆弱性 |
CWE-119
バッファエラー |
CVE-2009-4020 | 2010-04-2 13:59 | 2009-12-4 | Show | GitHub Exploit DB Packet Storm |
| 258639 | 4.7 | 警告 | サイバートラスト株式会社 Linux レッドハット |
- | Linux kernel の drivers/firewire/ohci.c におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2009-4138 | 2010-04-2 13:58 | 2009-12-16 | Show | GitHub Exploit DB Packet Storm |
| 258640 | 4.9 | 警告 | サイバートラスト株式会社 Linux レッドハット |
- | Linux kernel の fuse_direct_io 関数におけるサービス運用妨害 (DoS)の脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2009-4021 | 2010-04-2 13:58 | 2009-11-25 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 12, 2026, 4:20 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 198291 | 9.8 |
CRITICAL
Network |
ovarro |
twinsoft tbox_lt2-530_firmware tbox_lt2-532_firmware tbox_lt2-540_firmware tbox_ms-cpu32_firmware tbox_ms-cpu32-s2_firmware tbox_rm2_firmware tbox_tg2_firmware |
Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file. |
CWE-732
Incorrect Permission Assignment for Critical Resource |
CVE-2021-22648 | 2024-11-21 14:50 | 2022-07-29 | Show | GitHub Exploit DB Packet Storm |
| 198292 | 9.8 |
CRITICAL
Network |
ovarro |
twinsoft tbox_lt2-530_firmware tbox_lt2-532_firmware tbox_lt2-540_firmware tbox_ms-cpu32_firmware tbox_ms-cpu32-s2_firmware tbox_rm2_firmware tbox_tg2_firmware |
The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code execution. |
NVD-CWE-noinfo
|
CVE-2021-22646 | 2024-11-21 14:50 | 2022-07-29 | Show | GitHub Exploit DB Packet Storm |
| 198293 | 9.8 |
CRITICAL
Network |
ovarro |
twinsoft tbox_lt2-530_firmware tbox_lt2-532_firmware tbox_lt2-540_firmware tbox_ms-cpu32_firmware tbox_ms-cpu32-s2_firmware tbox_rm2_firmware tbox_tg2_firmware |
Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key. |
CWE-798
Use of Hard-coded Credentials |
CVE-2021-22644 | 2024-11-21 14:50 | 2022-07-29 | Show | GitHub Exploit DB Packet Storm |
| 198294 | 7.5 |
HIGH
Network |
ovarro |
twinsoft tbox_lt2-530_firmware tbox_lt2-532_firmware tbox_lt2-540_firmware tbox_ms-cpu32_firmware tbox_ms-cpu32-s2_firmware tbox_rm2_firmware tbox_tg2_firmware |
An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system. |
CWE-400
Uncontrolled Resource Consumption |
CVE-2021-22642 | 2024-11-21 14:50 | 2022-07-29 | Show | GitHub Exploit DB Packet Storm |
| 198295 | 9.8 |
CRITICAL
Network |
ovarro |
twinsoft tbox_lt2-530_firmware tbox_lt2-532_firmware tbox_lt2-540_firmware tbox_ms-cpu32_firmware tbox_ms-cpu32-s2_firmware tbox_rm2_firmware tbox_tg2_firmware |
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks. |
CWE-294 CWE-307 Authentication Bypass by Capture-replay mproper Restriction of Excessive Authentication Attempts |
CVE-2021-22640 | 2024-11-21 14:50 | 2022-07-29 | Show | GitHub Exploit DB Packet Storm |
| 198296 | 6.1 |
MEDIUM
Network |
microfocus | access_manager | A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability. This affects NetIQ Access Manager 4.5 and 5.0 |
CWE-79
Cross-site Scripting |
CVE-2021-22531 | 2024-11-21 14:50 | 2022-05-13 | Show | GitHub Exploit DB Packet Storm |
| 198297 | 9.8 |
CRITICAL
Network |
nxp | mqx | NXP MQX Versions 5.1 and prior are vulnerable to integer overflow in mem_alloc, _lwmem_alloc and _partition functions. This unverified memory assignment can lead to arbitrary memory allocation, resul… | - | CVE-2021-22680 | 2024-11-21 14:50 | 2022-05-4 | Show | GitHub Exploit DB Packet Storm |
| 198298 | 7.3 |
HIGH
Network |
oauth_client_library_for_java | The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sure that the token's payload comes from valid provider, not from someone else. An… |
CWE-347
Improper Verification of Cryptographic Signature |
CVE-2021-22573 | 2024-11-21 14:50 | 2022-05-4 | Show | GitHub Exploit DB Packet Storm | |
| 198299 | 7.8 |
HIGH
Local |
fuchsia | The Security Team discovered an integer overflow bug that allows an attacker with code execution to issue memory cache invalidation operations on pages that they don’t own, allowing them to control k… |
CWE-190
Integer Overflow or Wraparound |
CVE-2021-22556 | 2024-11-21 14:50 | 2022-05-4 | Show | GitHub Exploit DB Packet Storm | |
| 198300 | 7.8 |
HIGH
Local |
schneider-electric |
ecostruxure_process_expert ecostruxure_control_expert remoteconnect |
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may resul… | - | CVE-2021-22797 | 2024-11-21 14:50 | 2022-04-14 | Show | GitHub Exploit DB Packet Storm |