<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T17:35:36.732544+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2018-avi-172</id>
    <title>certfr-2018-avi-172 — De multiples vulnérabilités ont été découvertes dans SCADA les produits
Schneider Electric. Elles permettent à un attaq…</title>
    <updated>2026-10-04T17:35:36.737531+00:00</updated>
    <content>certfr-2018-avi-172</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2018-avi-172"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-07819</id>
    <title>cnvd-2018-07819</title>
    <updated>2026-10-04T17:35:36.737571+00:00</updated>
    <content>cnvd-2018-07819</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-07819"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-175951</id>
    <title>EUVD-2026-175951</title>
    <updated>2026-10-04T17:35:36.737587+00:00</updated>
    <content>EUVD-2026-175951</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-175951"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-7772</id>
    <title>fkie_cve-2018-7772</title>
    <updated>2026-10-04T17:35:36.737600+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The vulnerability exists within processing of applets which are exposed on the web service in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query to determine whether a user is logged in is subject to SQL injection on the loginSeed parameter, which can be embedded in the HTTP cookie of the request.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-7772"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-crm2-6crx-pv5r</id>
    <title>GHSA-crm2-6crx-pv5r</title>
    <updated>2026-10-04T17:35:36.737632+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The vulnerability exists within processing of applets which are exposed on the web service in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query to determine whether a user is logged in is subject to SQL injection on the loginSeed parameter, which can be embedded in the HTTP cookie of the request.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-crm2-6crx-pv5r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-7772</id>
    <title>gsd-2018-7772</title>
    <updated>2026-10-04T17:35:36.737649+00:00</updated>
    <content>gsd-2018-7772</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-7772"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-17-180-02</id>
    <title>ICSA-17-180-02 — Schneider Electric U.motion Builder (Update A)</title>
    <updated>2026-10-04T17:35:36.737659+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Unauthenticated users can use calls to various paths in order to perform arbitrary SQL statements against the underlying database.CVE-2017-7973 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The vulnerability exists within processing of track_import_export.php. The underlying SQLite database query is subject to SQL injection on the object_id input parameter.CVE-2018-7765 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). The vulnerability exists within processing of track_getdata.php. The underlying SQLite database query is subject to SQL injection on the id input parameter.CVE-2018-7766 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L). The vulnerability exists within processing of editobject.php. The underlying SQLite database query is subject to SQL injection on the type input parameter.CVE-2018-7767 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L). The vulnerability exists within processing of loadtemplate.php. The underlying SQLite database query is subject to SQL injection on the tpl input parameter.CVE-2018-7768 has been assigned to this vulnerability. A CVSS v3…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-17-180-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2018-095-01</id>
    <title>SEVD-2018-095-01 — Security Notification - U.motion Builder software</title>
    <updated>2026-10-04T17:35:36.737714+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of an exploit that targets Schneider Electric’s U.motion Builder 
software. It is imperative customers cease using U.motion Builder software and remove it from 
their systems immediately.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2018-095-01"/>
  </entry>
</feed>
