CVE-2026-14868
- EPSS 0.05%
- Veröffentlicht 07.07.2026 09:26:55
- Zuletzt bearbeitet 09.07.2026 18:32:08
The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alte...
CVE-2026-14867
- EPSS 0.09%
- Veröffentlicht 07.07.2026 09:25:57
- Zuletzt bearbeitet 09.07.2026 18:32:08
Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could retrieve users’ credentials. Active Directory accounts are not affected by this vulnerability.
CVE-2026-1698
- EPSS 0.21%
- Veröffentlicht 26.02.2026 07:58:00
- Zuletzt bearbeitet 09.07.2026 18:32:08
A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior. This vulnerabilit...
CVE-2026-1697
- EPSS 0.12%
- Veröffentlicht 26.02.2026 07:57:46
- Zuletzt bearbeitet 09.07.2026 18:32:08
The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included.
CVE-2026-1696
- EPSS 0.14%
- Veröffentlicht 26.02.2026 07:57:29
- Zuletzt bearbeitet 09.07.2026 18:32:08
Some HTTP security headers are not properly set by the web server when sending responses to the client application.
CVE-2026-1695
- EPSS 0.21%
- Veröffentlicht 26.02.2026 07:57:11
- Zuletzt bearbeitet 09.07.2026 18:32:08
An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to trick a legitimate user into loading content f...
CVE-2026-1694
- EPSS 0.17%
- Veröffentlicht 26.02.2026 07:56:57
- Zuletzt bearbeitet 09.07.2026 18:32:08
HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included....
CVE-2026-1693
- EPSS 0.31%
- Veröffentlicht 26.02.2026 07:56:10
- Zuletzt bearbeitet 09.07.2026 18:32:08
The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It mig...
CVE-2026-1692
- EPSS 0.11%
- Veröffentlicht 26.02.2026 07:55:18
- Zuletzt bearbeitet 09.07.2026 18:32:08
A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to lur...
CVE-2025-9999
- EPSS 0.16%
- Veröffentlicht 05.09.2025 16:41:01
- Zuletzt bearbeitet 15.04.2026 00:35:42
Some payload elements of the messages sent between two stations in a networking architecture are not properly checked on the receiving station allowing an attacker to execute unauthorized commands in the application.