Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.4) | 0.06% | — | Arcinfo Pcvue | 7/7/2026 | 9/7/2026 | The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alter the existing configuration and ultimately gain privileged access to… | |
| Analizada | Media (6.8) | 0.13% | — | Arcinfo Pcvue | 7/7/2026 | 9/7/2026 | Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could retrieve users’ credentials. Active Directory accounts are not affected by this vulnerability. | |
| Analizada | Media (5.3) | 0.21% | — | Arcinfo Pcvue | 26/2/2026 | 9/7/2026 | A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior. This vulnerability only affects the endpoints /Authentication/ExternalLogin,… | |
| Analizada | Media (5.3) | 0.12% | — | Arcinfo Pcvue | 26/2/2026 | 9/7/2026 | The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included. | |
| Analizada | Baja (2.3) | 0.15% | — | Arcinfo Pcvue | 26/2/2026 | 9/7/2026 | Some HTTP security headers are not properly set by the web server when sending responses to the client application. | |
| Analizada | Media (5.3) | 0.21% | — | Arcinfo Pcvue | 26/2/2026 | 9/7/2026 | An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to trick a legitimate user into loading content from another site upon unsuccessful user authentication on an unknown… | |
| Analizada | Baja (2.3) | 0.17% | — | Arcinfo Pcvue | 26/2/2026 | 9/7/2026 | HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It unnecessarily exposes sensitive information about the server… | |
| Analizada | Media (5.3) | 0.32% | — | Arcinfo Pcvue | 26/2/2026 | 9/7/2026 | The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It might allow a remote attacker to steal user credentials. | |
| Analizada | Media (5.3) | 0.11% | — | Arcinfo Pcvue | 26/2/2026 | 9/7/2026 | A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to lure a successfully authenticated user to a malicious website. This… | |
| Aplazada | Media (6) | 0.13% | — | Pcvue Mqtt Add-onAI | 6/5/2025 | 17/6/2026 | The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet become valid. This allows malicious devices to present certificates that are not rejected properly. The use of a client certificate reduces the risk for random devices to take advantage of this flaw. | |
| Aplazada | Baja (1.8) | 0.14% | — | Pcvue WEBAI | 9/12/2024 | 17/6/2026 | User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end. By exploiting this vulnerability, an attacker could retrieve the credentials of a user by accessing the Log File. Successful… | |
| Modificada | Media (5.5) | 0.12% | — | Arcinfo Pcvue | 12/12/2022 | 9/7/2026 | A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files to discover the associated simple mail transfer protocol (SMTP) account credentials and the… | |
| Modificada | Media (6.5) | 0.34% | — | Arcinfo Pcvue | 12/12/2022 | 9/7/2026 | An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect, which could include credentials. Successful exploitation of this vulnerability… | |
| Modificada | Media (5.5) | 0.14% | — | Arcinfo Pcvue | 24/8/2022 | 9/7/2026 | The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users | |
| Modificada | Alta (7.5) | 1.7% | — | Arcinfo Pcvue | 12/10/2020 | 9/7/2026 | ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data of legitimate users. This issue also affects third-party systems based on the Web Services Toolkit. | |
| Modificada | Alta (7.5) | 2.2% | — | Arcinfo Pcvue | 12/10/2020 | 9/7/2026 | ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients. This issue also affects third-party systems based on the Web Services Toolkit. | |
| Modificada | Crítica (9.8) | 3.8% | — | Arcinfo Pcvue | 12/10/2020 | 9/7/2026 | ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server. | |
| Analizada | Media (4.3) | 3.7% | — | Arcinfo FrontvueArcinfo PcvueArcinfo Plantvue | 3/4/2012 | 9/7/2026 | Buffer overflow in an unspecified ActiveX control in aipgctl.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to cause a denial of service via a crafted HTML document. | |
| Analizada | Media (5.8) | 27% | — | Arcinfo FrontvueArcinfo PcvueArcinfo Plantvue | 3/4/2012 | 9/7/2026 | An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to modify files via calls to unknown methods. | |
| Analizada | Alta (9.3) | 7.4% | — | Arcinfo FrontvueArcinfo PcvueArcinfo Plantvue | 3/4/2012 | 9/7/2026 | Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code via a large value for an integer parameter, leading to a buffer overflow. | |
| Analizada | Alta (9.3) | 6.4% | — | Arcinfo FrontvueArcinfo PcvueArcinfo Plantvue | 3/4/2012 | 9/7/2026 | An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code by using a crafted HTML document to obtain control of a function pointer. |