VulnSea

pcvue vulnerabilities

CVEs whose affected-version data names the pcvue package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

17 CVEsRSS

CVE-2026-1698Medium· 6.1
6mo ago

A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior. This…

A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior. This…

Sunlitarcinfo · pcvueEPSS 0.21%via NVD
CVE-2026-1697Medium· 6.5
6mo ago

The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included.

The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included.

Sunlitarcinfo · pcvueEPSS 0.12%via NVD
CVE-2026-1696Medium· 6.1
6mo ago

Some HTTP security headers are not properly set by the web server when sending responses to the client application.

Some HTTP security headers are not properly set by the web server when sending responses to the client application.

Sunlitarcinfo · pcvueEPSS 0.14%via NVD
CVE-2026-1695Medium· 6.1
6mo ago

An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included

An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to trick a legitimate user into load…

Sunlitarcinfo · pcvueEPSS 0.21%via NVD
CVE-2026-1694Medium· 4.3
6mo ago

HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.…

HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.…

Sunlitarcinfo · pcvueEPSS 0.17%via NVD
CVE-2026-1693High· 7.5
6mo ago

The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being depre…

The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being depre…

Twilightarcinfo · pcvueEPSS 0.31%via NVD
CVE-2026-1692Medium· 6.1
6mo ago

A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included

A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote at…

Sunlitarcinfo · pcvueEPSS 0.11%via NVD
CVE-2022-4312Medium· 5.5
3y ago

A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3

A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files to disco…

Sunlitarcinfo · pcvueEPSS 0.11%via NVD
CVE-2022-4311Medium· 4.7
3y ago

An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2

An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConne…

Sunlitarcinfo · pcvueEPSS 0.33%via NVD
CVE-2022-2569Medium· 5.5
4y ago

The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users

The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users

Sunlitarcinfo · pcvueEPSS 0.14%via NVD
CVE-2020-26869High· 7.5
5y ago

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data of legitimate users

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data of legitimate users. This issue also affects third-party systems based on the Web Services Toolkit.

Twilightarcinformatique · pcvueEPSS 1.7%via NVD
CVE-2020-26868High· 7.5
5y ago

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients. This issue also affect…

Twilightarcinformatique · pcvueEPSS 2.2%via NVD
CVE-2020-26867Critical· 9.8
5y ago

ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.

ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.

Midnightarcinformatique · pcvueEPSS 3.8%via NVD
CVE-2011-4045Medium· 4.3PoC
14y ago

Buffer overflow in an unspecified ActiveX control in aipgctl.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to cause a denial of service via a crafted HTML document.

Buffer overflow in an unspecified ActiveX control in aipgctl.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to cause a denial of service via a crafted HTML document.

Twilightarcinformatique · frontvueEPSS 3.7%via NVD
CVE-2011-4044Medium· 5.8PoC
14y ago

An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to modify files via calls to unknown methods.

An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to modify files via calls to unknown methods.

Twilightarcinformatique · frontvueEPSS 27%via NVD
CVE-2011-4043Critical· 9.3PoC
14y ago

Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code via a large value for an integer parameter, leading to…

Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code via a large value for an integer parameter, leading to…

Abyssalarcinformatique · frontvueEPSS 7.4%via NVD
CVE-2011-4042Critical· 9.3PoC
14y ago

An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code by using a crafted HTML document to obtain control of a function pointer.

An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code by using a crafted HTML document to obtain control of a function pointer.

Abyssalarcinformatique · frontvueEPSS 6.4%via NVD
pcvue vulnerabilities (CVEs) · VulnSea