Every CVE whose affected-product data names Arcinfo Pcvue, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (19)
CVE-2020-26867 — CVSS 9.8 (critical): ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to…
CVE-2011-4043 — CVSS 9.3 (critical): Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows…
CVE-2011-4042 — CVSS 9.3 (critical): An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to…
CVE-2020-26869 — CVSS 7.5 (high): ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data…
CVE-2026-1693 — CVSS 7.5 (high): The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler…
CVE-2020-26868 — CVSS 7.5 (high): ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to…
CVE-2026-1697 — CVSS 6.5 (medium): The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through…
CVE-2026-1698 — CVSS 6.1 (medium): A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included…
CVE-2026-1692 — CVSS 6.1 (medium): A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue…
CVE-2026-1695 — CVSS 6.1 (medium): An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version…
CVE-2026-1696 — CVSS 6.1 (medium): Some HTTP security headers are not properly set by the web server when sending responses to the client application.
CVE-2011-4044 — CVSS 5.8 (medium): An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to…
CVE-2022-2569 — CVSS 5.5 (medium): The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the…
CVE-2026-14868 — CVSS 5.5 (medium): The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all…
CVE-2022-4312 — CVSS 5.5 (medium): A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized…
CVE-2026-14867 — CVSS 5.5 (medium): Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker…
CVE-2022-4311 — CVSS 4.7 (medium): An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with…
CVE-2026-1694 — CVSS 4.3 (medium): HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used…
CVE-2011-4045 — CVSS 4.3 (medium): Buffer overflow in an unspecified ActiveX control in aipgctl.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows…