VYPR
Vendor

CAXPerts

Products
3
CVEs
2
Across products
3
Status
Private

Products

3

Recent CVEs

2
  • CVE-2026-36035Jul 14, 2026
    risk 0.00cvss epss 0.00

    Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service (DoS) via removing the license from the webserver.

  • CVE-2026-35552Jul 8, 2026
    risk 0.00cvss epss 0.00

    In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, this allows the attacker to deactivate the…