<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 15:59:43 +0000</lastBuildDate>
    <item>
      <title>certfr-2018-avi-172 — De multiples vulnérabilités ont été découvertes dans SCADA les produits
Schneider Electric. Elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2018-avi-172</link>
      <description>certfr-2018-avi-172</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2018-avi-172</guid>
    </item>
    <item>
      <title>EUVD-2026-165624</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-165624</link>
      <description>EUVD-2026-165624</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-165624</guid>
    </item>
    <item>
      <title>fkie_cve-2018-7773</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-7773</link>
      <description>&lt;p&gt;The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the sessionid input parameter.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the sessionid input parameter.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-7773</guid>
    </item>
    <item>
      <title>GHSA-4296-vpvc-4596</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4296-vpvc-4596</link>
      <description>&lt;p&gt;The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the sessionid input parameter.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the sessionid input parameter.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4296-vpvc-4596</guid>
    </item>
    <item>
      <title>gsd-2018-7773</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-7773</link>
      <description>gsd-2018-7773</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-7773</guid>
    </item>
    <item>
      <title>ICSA-17-180-02 — Schneider Electric U.motion Builder (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-17-180-02</link>
      <description>&lt;p&gt;Unauthenticated users can use calls to various paths in order to perform arbitrary SQL statements against the underlying database.CVE-2017-7973 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The vulnerability exists within processing of track_import_export.php. The underlying SQLite database query is subject to SQL injection on the object_id input parameter.CVE-2018-7765 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). The vulnerability exists within processing of track_getdata.php. The underlying SQLite database query is subject to SQL injection on the id input parameter.CVE-2018-7766 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L). The vulnerability exists within processing of editobject.php. The underlying SQLite database query is subject to SQL injection on the type input parameter.CVE-2018-7767 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L). The vulnerability exists within processing of loadtemplate.php. The underlying SQLite database query is subject to SQL injection on the tpl input parameter.CVE-2018-7768 has been assigned to this vulnerability. A CVSS v3…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Unauthenticated users can use calls to various paths in order to perform arbitrary SQL statements against the underlying database.CVE-2017-7973 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The vulnerability exists within processing of track_import_export.php. The underlying SQLite database query is subject to SQL injection on the object_id input parameter.CVE-2018-7765 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). The vulnerability exists within processing of track_getdata.php. The underlying SQLite database query is subject to SQL injection on the id input parameter.CVE-2018-7766 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L). The vulnerability exists within processing of editobject.php. The underlying SQLite database query is subject to SQL injection on the type input parameter.CVE-2018-7767 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L). The vulnerability exists within processing of loadtemplate.php. The underlying SQLite database query is subject to SQL injection on the tpl input parameter.CVE-2018-7768 has been assigned to this vulnerability. A CVSS v3…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-17-180-02</guid>
    </item>
    <item>
      <title>SEVD-2018-095-01 — Security Notification - U.motion Builder software</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2018-095-01</link>
      <description>&lt;p&gt;Schneider Electric is aware of an exploit that targets Schneider Electric’s U.motion Builder &#13;
software. It is imperative customers cease using U.motion Builder software and remove it from &#13;
their systems immediately.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of an exploit that targets Schneider Electric’s U.motion Builder &#13;
software. It is imperative customers cease using U.motion Builder software and remove it from &#13;
their systems immediately.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2018-095-01</guid>
    </item>
  </channel>
</rss>
