Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08

Vendors · jtekt

jtekt

· 2 Critical

Total CVEs

27

Critical

2

Products

132

Search All CVEs →

27

Products (132)

screen creator advance 29 CVEsplus cpu tcc-67404 CVEspc10b tcc-1021 firmware4 CVEsgc-a244 CVEskostac plc4 CVEspc10p tcc-6372 firmware4 CVEspc10p tcc-63724 CVEspc10p-dp tcc-6726 firmware4 CVEspc10p-dp tcc-67264 CVEspc10p-dp-io tcc-6752 firmware4 CVEspc10p-dp-io tcc-67524 CVEspc10ge tcc-6464 firmware4 CVEspc10ge tcc-64644 CVEspc10g-cpu tcc-6353 firmware4 CVEspc10g-cpu tcc-63534 CVEspc10b tcc-10214 CVEspc10b-p tcc-6373 firmware4 CVEspc10b-p tcc-63734 CVEsplus cpu tcc-6740 firmware4 CVEsgc-a22w-cw4 CVEsgc-a22w-cw firmware4 CVEsgc-a24-m4 CVEsgc-a24-m firmware4 CVEsgc-a24 firmware4 CVEsgc-a24w-c\(w\)4 CVEsgc-a24w-c\(w\) firmware4 CVEsgc-a254 CVEsgc-a25 firmware4 CVEsgc-a264 CVEsgc-a26-j24 CVEsgc-a26-j2 firmware4 CVEsgc-a26 firmware4 CVEsgc-a26w-c\(w\)4 CVEsgc-a26w-c\(w\) firmware4 CVEsgc-a27-c4 CVEsgc-a27-c firmware4 CVEsgc-a28-c4 CVEsgc-a28-c firmware4 CVEspc10pe tcc-11013 CVEskostac plc programming software3 CVEspc10pe-1616p tcc-1102 firmware3 CVEspc10pe-1616p tcc-11023 CVEspc10pe tcc-1101 firmware3 CVEsnano 10gx tuc-11573 CVEsnano 10gx tuc-1157 firmware3 CVEsnano cpu tuc-69413 CVEspc10e tcc-47373 CVEsnano cpu tuc-6941 firmware3 CVEspc10e tcc-4737 firmware3 CVEspc3jx tcc-69012 CVEs2port-efr thu-64042 CVEs2port-efr thu-6404 firmware2 CVEsfl\/et-t-v2h thu-62892 CVEsfl\/et-t-v2h thu-6289 firmware2 CVEsonsinview22 CVEspc10b-e\/c tcu-65212 CVEspc10b-e\/c tcu-6521 firmware2 CVEspc10el tcc-47472 CVEspc10el tcc-4747 firmware2 CVEspc3jx-d tcc-69022 CVEspc3jx-d tcc-6902 firmware2 CVEspc3jx tcc-6901 firmware2 CVEspcdl tkc-66882 CVEspcdl tkc-6688 firmware2 CVEsplus 2p-efr tcu-69292 CVEsplus 2p-efr tcu-6929 firmware2 CVEsplus bus-ex tcu-69002 CVEsplus bus-ex tcu-6900 firmware2 CVEsplus efr2 tcu-68592 CVEsplus efr2 tcu-6859 firmware2 CVEsplus efr tcu-67432 CVEsplus efr tcu-6743 firmware2 CVEsplus ex2 tcu-68582 CVEsplus ex2 tcu-6858 firmware2 CVEsplus ex tcu-67412 CVEsplus ex tcu-6741 firmware2 CVEsnano safety rs00ip tuu-10861 CVEspc10p1 CVEspc10p-dp1 CVEspc10p-dp-io1 CVEspc10p-dp-io firmware1 CVEsnano cpu firmware1 CVEsnano cpu1 CVEspc10p-dp firmware1 CVEsnano 2et tuu-6949 firmware1 CVEsnano 2et tuu-69491 CVEspc10p firmware1 CVEsnano 2et firmware1 CVEsnano 2et1 CVEspc10pe1 CVEsnano 10gx firmware1 CVEsnano 10gx1 CVEspc10pe-16\/16p1 CVEspc10pe-16\/16p firmware1 CVEspc10pe firmware1 CVEsfl\/et-t-v2h firmware1 CVEsfl\/et-t-v2h1 CVEsplus efr1 CVEsplus efr21 CVEs2port-efr1 CVEsplus efr2 firmware1 CVEsplus ex21 CVEsplus ex2 firmware1 CVEsplus 2p-efr1 CVEsplus 2p-efr firmware1 CVEsplus efr firmware1 CVEsplus ex firmware1 CVEsplus bus-ex1 CVEsplus bus-ex firmware1 CVEs2port-efr firmware1 CVEsplus ex1 CVEsplus cpu1 CVEsplus cpu firmware1 CVEspc10b-p firmware1 CVEspc10b firmware1 CVEspc10b-p1 CVEspc10b1 CVEspc10e1 CVEspc10e firmware1 CVEspc10e tcc-46371 CVEspc10e tcc-4637 firmware1 CVEsnano safety tuc-1085 firmware1 CVEsnano safety tuc-10851 CVEsef10 tcu-6982 firmware1 CVEsef10 tcu-69821 CVEspc10g-cpu1 CVEspc10g-cpu firmware1 CVEsnano safety rs01ip tuu-1087 firmware1 CVEsnano safety rs01ip tuu-10871 CVEspc10ge1 CVEspc10ge firmware1 CVEsnano safety rs00ip tuu-1086 firmware1 CVEs

Recent Vulnerabilities

View all 27
CVE-2024-47136HIGH 7.8

Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier may cause a denial-of-service (DoS) condition, arbitrary code execution, and/or information disclosure because the issues exist in parsing of KPP project files.

CVE-2024-47135HIGH 7.8

Stack-based buffer overflow vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier may cause a denial-of-service (DoS) condition, arbitrary code execution, and/or information disclosure because the issues exist in parsing of KPP project files.

CVE-2023-49713HIGH 7.5

Denial-of-service (DoS) vulnerability exists in NetBIOS service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

CVE-2023-49143HIGH 7.5

Denial-of-service (DoS) vulnerability exists in rfe service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

CVE-2023-49140HIGH 7.5

Denial-of-service (DoS) vulnerability exists in commplex-link service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

CVE-2023-41963HIGH 7.5

Denial-of-service (DoS) vulnerability exists in FTP service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

CVE-2023-42507HIGH 7.8

Stack-based buffer overflow vulnerability exists in OnSinView2 versions 2.0.1 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user open a specially crafted OnSinView2 project file.

CVE-2023-42506HIGH 7.8

Improper restriction of operations within the bounds of a memory buffer issue exists in OnSinView2 versions 2.0.1 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user open a specially crafted OnSinView2 project file.

CVE-2023-41375HIGH 7.8

Use after free vulnerability exists in Kostac PLC Programming Software Version 1.6.11.0. Arbitrary code may be executed by having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier because the issue exists in parsing of KPP project files. The vendor states that Kostac PLC Programming Software Version 1.6.10.0 or later implements the function which prevents a project file alteration. Therefore, to mitigate the impact of these vulnerabilities, a project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier needs to be saved again using Kostac PLC Programming Software Version 1.6.10.0 or later.

CVE-2023-41374HIGH 7.8

Double free issue exists in Kostac PLC Programming Software Version 1.6.11.0 and earlier. Arbitrary code may be executed by having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier because the issue exists in parsing of KPP project files. The vendor states that Kostac PLC Programming Software Version 1.6.10.0 or later implements the function which prevents a project file alteration. Therefore, to mitigate the impact of these vulnerabilities, a project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier needs to be saved again using Kostac PLC Programming Software Version 1.6.10.0 or later.

CVE-2023-25755HIGH 7.8

Screen Creator Advance 2 Ver.0.1.1.4 Build01A and earlier is vulnerable to improper restriction of operations within the bounds of a memory buffer (CWE-119) due to improper check of its data size when processing a project file. If a user of Screen Creator Advance 2 opens a specially crafted project file, information may be disclosed and/or arbitrary code may be executed.

CVE-2022-27648HIGH 7.8

This vulnerability allows remote attackers to execute arbitrary code on affected installations of KOYO Screen Creator 0.1.1.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SCA2 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14868.

CVE-2023-22424HIGH 7.8

Use-after-free vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.9.0 and earlier. With the abnormal value given as the maximum number of columns for the PLC program, the process accesses the freed memory. As a result, opening a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

CVE-2023-22421HIGH 7.8

Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.9.0 and earlier. The insufficient buffer size for the PLC program instructions leads to out-of-bounds read. As a result, opening a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

CVE-2023-22419HIGH 7.8

Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.9.0 and earlier. When processing a comment block in stage information, the end of data cannot be verified and out-of-bounds read occurs. As a result, opening a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

CVE-2023-22360HIGH 7.8

Use-after free vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process even when an error was detected. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

CVE-2023-22353HIGH 7.8

Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing control management information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

CVE-2023-22350HIGH 7.8

Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing parts management information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

CVE-2023-22349HIGH 7.8

Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing screen management information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

CVE-2023-22347HIGH 7.8

Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing file structure information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

CVE-2023-22346HIGH 7.8

Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing template information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

CVE-2023-22345HIGH 7.8

Out-of-bound write vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process when out of specification errors are detected. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

CVE-2022-29958CRITICAL 9.8

JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protocol for engineering purposes, including downloading projects and control logic to the PLC. Control logic is downloaded to the PLC on a block-by-block basis with a given memory address and a blob of machine code. The logic that is downloaded to the PLC is not cryptographically authenticated, allowing an attacker to execute arbitrary machine code on the PLC's CPU module in the context of the runtime. In the case of the PC10G-CPU, and likely for other CPU modules of the TOYOPUC family, a processor without MPU or MMU is used and this no memory protection or privilege-separation capabilities are available, giving an attacker full control over the CPU.

CVE-2022-29951CRITICAL 9.1

JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on ports 1024-65534 on either TCP or UDP) for a wide variety of engineering purposes such as starting and stopping the PLC, downloading and uploading projects, and changing configuration settings. This protocol does not have any authentication features, allowing any attacker capable of communicating with the port in question to invoke (a subset of) desired functionality.

CVE-2021-33011MEDIUM 4.3

All versions of the afffected TOYOPUC-PC10 Series,TOYOPUC-Plus Series,TOYOPUC-PC3J/PC2J Series, TOYOPUC-Nano Series products may not be able to properly process an ICMP flood, which may allow an attacker to deny Ethernet communications between affected devices.