|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 19, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 259751 | 9.3 | 危険 | マイクロソフト | - | Microsoft Project における任意のコードを実行される脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2009-0102 | 2010-01-22 10:26 | 2009-12-8 | Show | GitHub Exploit DB Packet Storm |
| 259752 | 9.3 | 危険 | マイクロソフト | - | Microsoft Internet Explorer におけるメモリ破損の脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-3673 | 2010-01-22 10:26 | 2009-12-8 | Show | GitHub Exploit DB Packet Storm |
| 259753 | 9.3 | 危険 | マイクロソフト | - | Microsoft Internet Explorer におけるメモリ破損の脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2009-3671 | 2010-01-22 10:26 | 2009-12-8 | Show | GitHub Exploit DB Packet Storm |
| 259754 | 10 | 危険 | マイクロソフト | - | Microsoft Windows のインターネット認証サービスにおけるネットワークリソースにアクセスされる脆弱性 |
CWE-255 CWE-94 |
CVE-2009-3677 | 2010-01-22 10:24 | 2009-12-8 | Show | GitHub Exploit DB Packet Storm |
| 259755 | 10 | 危険 | マイクロソフト | - | Microsoft Windows のインターネット認証サービスにおける任意のコードを実行される脆弱性 |
CWE-287
不適切な認証 |
CVE-2009-2505 | 2010-01-22 10:24 | 2009-12-8 | Show | GitHub Exploit DB Packet Storm |
| 259756 | 6.9 | 警告 | acpid | - | acpid の umask におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2009-4235 | 2010-01-21 11:44 | 2009-12-7 | Show | GitHub Exploit DB Packet Storm |
| 259757 | 6.9 | 警告 | サイバートラスト株式会社 レッドハット acpid |
- | acpid のレッドハットパッチにおける権限を取得される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2009-4033 | 2010-01-21 11:43 | 2009-12-7 | Show | GitHub Exploit DB Packet Storm |
| 259758 | 10 | 危険 | アドビシステムズ | - | Adobe Illustrator における任意のコードを実行される脆弱性 |
CWE-119
バッファエラー |
CVE-2009-3952 | 2010-01-21 11:43 | 2010-01-7 | Show | GitHub Exploit DB Packet Storm |
| 259759 | 9.3 | 危険 | アドビシステムズ | - | Adobe Illustrator における Encapsulated PostScript ファイルの処理に関する任意のコードを実行される脆弱性 |
CWE-119
バッファエラー |
CVE-2009-4195 | 2010-01-21 11:43 | 2009-12-4 | Show | GitHub Exploit DB Packet Storm |
| 259760 | 4.4 | 警告 | サイバートラスト株式会社 Linux レッドハット |
- | Linux Kernel の exit_notify 関数における任意のシグナルをプロセスに送信可能な脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2009-1337 | 2010-01-21 11:23 | 2009-04-22 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 19, 2026, 4:01 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 199251 | 9.8 |
CRITICAL
Network |
ovarro |
twinsoft tbox_lt2-530_firmware tbox_lt2-532_firmware tbox_lt2-540_firmware tbox_ms-cpu32_firmware tbox_ms-cpu32-s2_firmware tbox_rm2_firmware tbox_tg2_firmware |
An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWinSoft, which could lead to code execution. |
CWE-22
Path Traversal |
CVE-2021-22650 | 2024-11-21 14:50 | 2022-07-29 | Show | GitHub Exploit DB Packet Storm |
| 199252 | 9.8 |
CRITICAL
Network |
ovarro |
twinsoft tbox_lt2-530_firmware tbox_lt2-532_firmware tbox_lt2-540_firmware tbox_ms-cpu32_firmware tbox_ms-cpu32-s2_firmware tbox_rm2_firmware tbox_tg2_firmware |
Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file. |
CWE-732
Incorrect Permission Assignment for Critical Resource |
CVE-2021-22648 | 2024-11-21 14:50 | 2022-07-29 | Show | GitHub Exploit DB Packet Storm |
| 199253 | 9.8 |
CRITICAL
Network |
ovarro |
twinsoft tbox_lt2-530_firmware tbox_lt2-532_firmware tbox_lt2-540_firmware tbox_ms-cpu32_firmware tbox_ms-cpu32-s2_firmware tbox_rm2_firmware tbox_tg2_firmware |
The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code execution. |
NVD-CWE-noinfo
|
CVE-2021-22646 | 2024-11-21 14:50 | 2022-07-29 | Show | GitHub Exploit DB Packet Storm |
| 199254 | 9.8 |
CRITICAL
Network |
ovarro |
twinsoft tbox_lt2-530_firmware tbox_lt2-532_firmware tbox_lt2-540_firmware tbox_ms-cpu32_firmware tbox_ms-cpu32-s2_firmware tbox_rm2_firmware tbox_tg2_firmware |
Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key. |
CWE-798
Use of Hard-coded Credentials |
CVE-2021-22644 | 2024-11-21 14:50 | 2022-07-29 | Show | GitHub Exploit DB Packet Storm |
| 199255 | 7.5 |
HIGH
Network |
ovarro |
twinsoft tbox_lt2-530_firmware tbox_lt2-532_firmware tbox_lt2-540_firmware tbox_ms-cpu32_firmware tbox_ms-cpu32-s2_firmware tbox_rm2_firmware tbox_tg2_firmware |
An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system. |
CWE-400
Uncontrolled Resource Consumption |
CVE-2021-22642 | 2024-11-21 14:50 | 2022-07-29 | Show | GitHub Exploit DB Packet Storm |
| 199256 | 9.8 |
CRITICAL
Network |
ovarro |
twinsoft tbox_lt2-530_firmware tbox_lt2-532_firmware tbox_lt2-540_firmware tbox_ms-cpu32_firmware tbox_ms-cpu32-s2_firmware tbox_rm2_firmware tbox_tg2_firmware |
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks. |
CWE-294 CWE-307 Authentication Bypass by Capture-replay mproper Restriction of Excessive Authentication Attempts |
CVE-2021-22640 | 2024-11-21 14:50 | 2022-07-29 | Show | GitHub Exploit DB Packet Storm |
| 199257 | 6.1 |
MEDIUM
Network |
microfocus | access_manager | A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability. This affects NetIQ Access Manager 4.5 and 5.0 |
CWE-79
Cross-site Scripting |
CVE-2021-22531 | 2024-11-21 14:50 | 2022-05-13 | Show | GitHub Exploit DB Packet Storm |
| 199258 | 9.8 |
CRITICAL
Network |
nxp | mqx | NXP MQX Versions 5.1 and prior are vulnerable to integer overflow in mem_alloc, _lwmem_alloc and _partition functions. This unverified memory assignment can lead to arbitrary memory allocation, resul… | - | CVE-2021-22680 | 2024-11-21 14:50 | 2022-05-4 | Show | GitHub Exploit DB Packet Storm |
| 199259 | 7.3 |
HIGH
Network |
oauth_client_library_for_java | The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sure that the token's payload comes from valid provider, not from someone else. An… |
CWE-347
Improper Verification of Cryptographic Signature |
CVE-2021-22573 | 2024-11-21 14:50 | 2022-05-4 | Show | GitHub Exploit DB Packet Storm | |
| 199260 | 7.8 |
HIGH
Local |
fuchsia | The Security Team discovered an integer overflow bug that allows an attacker with code execution to issue memory cache invalidation operations on pages that they don’t own, allowing them to control k… |
CWE-190
Integer Overflow or Wraparound |
CVE-2021-22556 | 2024-11-21 14:50 | 2022-05-4 | Show | GitHub Exploit DB Packet Storm |