Known vulnerabilities in U.motion Builder

Software CPE: cpe:2.3:a:schneider_electric:umotion_builder:*:*:*:*:*:*:*:*
Total vulnerabilities: 28
Public exploits: 4
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting U.motion Builder U.motion Builder is affected by 28 known vulnerabilities: 5 high, 1 medium, 22 low Critical High Medium Low

Vulnerabilities (28)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU35886 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2018-7841
CWE-89 High
Available
Exploited
- 22.05.2019 SB2019052225
#VU13330 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2018-7785
CWE-78 High
No
No
1.3.4 13.06.2018 SB2018061310
#VU13329 - Stack-based buffer overflow
CVE-2018-7784
CWE-121 High
No
No
1.3.4 12.06.2018 SB2018061310
#VU13331 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-7786
CWE-79 Low
No
No
1.3.4 12.06.2018 SB2018061310
#VU13332 - Exposure of sensitive information to an unauthorized actor
CVE-2018-7787
CWE-200 Low
No
No
1.3.4 12.06.2018 SB2018061310
#VU11664 - Improper input validation
CVE-2018-7777
CWE-20 High
Available
No
- 10.04.2018 SB2018041010
#VU11663 - Exposure of sensitive information to an unauthorized actor
CVE-2018-7776
CWE-200 Low
No
No
- 10.04.2018 SB2018041010
#VU11662 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-7775
CWE-22 Low
No
No
- 10.04.2018 SB2018041010
#VU11661 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-7771
CWE-22 Low
No
No
- 10.04.2018 SB2018041010
#VU11660 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-7770
CWE-22 Low
No
No
- 10.04.2018 SB2018041010
#VU11659 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2018-7774
CWE-89 Low
No
No
- 10.04.2018 SB2018041010
#VU11658 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2018-7773
CWE-89 Low
No
No
- 10.04.2018 SB2018041010
#VU11657 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2018-7772
CWE-89 Low
No
No
- 10.04.2018 SB2018041010
#VU11656 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2018-7769
CWE-89 Low
No
No
- 10.04.2018 SB2018041010
#VU11655 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2018-7768
CWE-89 Low
No
No
- 10.04.2018 SB2018041010
#VU11654 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2018-7767
CWE-89 Low
No
No
- 10.04.2018 SB2018041010
#VU11653 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2018-7766
CWE-89 Low
No
No
- 10.04.2018 SB2018041010
#VU11652 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2018-7765
CWE-89 Low
Available
No
- 10.04.2018 SB2018041010
#VU11645 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-7764
CWE-22 Low
No
No
- 10.04.2018 SB2018041010
#VU6676 - Untrusted Search Path
CVE-2017-7494
CWE-426 Medium
Available
Exploited
- 24.05.2017 SB2017052410
SB2017052413
SB2017052414
and 20 more


Showing elements 1 - 20 out of 28