NVD や CVE、ほか複数の脅威フィードを束ね、RCE など高リスクな事象を深く追える一覧です。CVSS と EPSS を組み合わせ、Exploit 参照や PoC の有無から悪用しやすさを追跡します。ベンダー修正や緩和策の文脈とあわせて優先度を決め、対応サイクルを短く保ちつつ重要資産を守る支援をします。
Assigner(CNA/発行元):[email protected] この条件を外す
| CVE | 説明 | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|
| CVE-2025-46743 | An authenticated user's token could be used by another source after the user had logged out prior to the token expiring. | 6.3 | 0.06% | 2025-05-12 | 2026-06-17 |
| CVE-2025-46741 | A suspended or recently logged-out user could continue to interact with Blueframe until the time-out period occurred. | 5.7 | 0.06% | 2025-05-12 | 2026-06-17 |
| CVE-2025-46737 | SEL-5037 Grid Configurator contains an overly permissive Cross Origin Resource Sharing (CORS) configuration for a data gateway service in the application. This gateway service includes an API which is not properly configured to reject requests from unexpected sources. | 7.4 | 0.08% | 2025-05-12 | 2026-06-17 |
| CVE-2025-48018 | An authenticated user can modify application state data. | 7.5 | 0.13% | 2025-05-20 | 2026-06-17 |
| CVE-2023-34391 | Insecure Inherited Permissions vulnerability in Schweitzer Engineering Laboratories SEL-5033 AcSELerator RTAC Software on Windows allows Leveraging/Manipulating Configuration File Search Paths. See Instruction Manual Appendix A [Cybersecurity] tag dated 20230522 for more details. This issue affects SEL-5033 AcSELerator RTAC Software: before 1.35.151.21000. | 7.4 | 0.13% | 2023-08-31 | 2026-06-17 |
| CVE-2025-46750 | SEL BIOS packages prior to 1.3.49152.117 or 2.6.49152.98 allow a local attacker to bypass password authentication and change password-protected BIOS settings by importing a BIOS settings file with no password set. | 4.4 | 0.15% | 2025-05-12 | 2026-06-17 |
| CVE-2025-46738 | An authenticated attacker can maliciously modify layout data files in the SEL-5033 installation directory to execute arbitrary code. | 6.6 | 0.15% | 2025-05-12 | 2026-06-17 |
| CVE-2023-31151 | An Improper Certificate Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote unauthenticated attacker to conduct a man-in-the-middle (MitM) attack. See SEL Service Bulletin dated 2022-11-15 for more details. | 4.7 | 0.15% | 2023-05-10 | 2026-06-17 |
| CVE-2025-46742 | Users who were required to change their password could still access system information before changing their password | 4.3 | 0.17% | 2025-05-12 | 2026-06-17 |
| CVE-2025-48016 | OpenFlow discovery protocol can exhaust resources because it is not rate limited | 4.3 | 0.18% | 2025-05-20 | 2026-06-17 |
| CVE-2025-46746 | An administrator could discover another account's credentials. | 5.8 | 0.19% | 2025-05-12 | 2026-06-17 |
| CVE-2025-48015 | Failed login response could be different depending on whether the username was local or central. | 3.7 | 0.20% | 2025-05-20 | 2026-06-17 |
| CVE-2025-46748 | An authenticated user attempting to change their password could do so without using the current password. | 2.7 | 0.20% | 2025-05-12 | 2026-06-17 |
| CVE-2025-46744 | An authenticated administrator could modify the Created By username for a user account | 2.7 | 0.20% | 2025-05-12 | 2026-06-17 |
| CVE-2023-31173 | Use of Hard-coded Credentials vulnerability in Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator on Windows allows Authentication Bypass. See Instruction Manual Appendix A and Appendix E dated 20230615 for more details. This issue affects SEL-5037 SEL Grid Configurator: before 4.5.0.20. | 7.7 | 0.20% | 2023-08-31 | 2026-06-17 |
| CVE-2023-31174 | A Cross-Site Request Forgery (CSRF) vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to embed instructions that could be executed by an authorized device operator. See Instruction Manual Appendix A and Appendix E dated 20230615 for more details. This issue affects SEL-5037 SEL Grid Configurator: before 4.5.0.20. | 7.4 | 0.20% | 2023-08-31 | 2026-06-17 |
| CVE-2023-2264 | An improper input validation vulnerability in the Schweitzer Engineering Laboratories SEL-411L could allow a malicious actor to manipulate authorized users to click on a link that could allow undesired behavior. See product Instruction Manual Appendix A dated 20230830 for more details. | 4.0 | 0.21% | 2023-11-30 | 2026-06-17 |
| CVE-2025-46749 | An authenticated user could submit scripting to fields that lack proper input and output sanitization leading to subsequent client-side script execution. | 4.3 | 0.22% | 2025-05-12 | 2026-06-17 |
| CVE-2025-46747 | An authenticated user without user-management permissions could identify other user accounts. | 5.7 | 0.26% | 2025-05-12 | 2026-06-17 |
| CVE-2025-46745 | An authenticated user without user-management permissions could view other users account information. | 6.5 | 0.26% | 2025-05-12 | 2026-06-17 |