VYPR
Vendor

PcVue

Products
3
CVEs
14
Across products
17
Status
Private

Products

3

Recent CVEs

14
  • CVE-2026-1693HigFeb 26, 2026
    risk 0.49cvss 7.5epss 0.00

    The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It might allow a remote attacker to…

  • CVE-2025-9999HigSep 5, 2025
    risk 0.49cvss epss 0.00

    Some payload elements of the messages sent between two stations in a networking architecture are not properly checked on the receiving station allowing an attacker to execute unauthorized commands in the application.

  • CVE-2026-1697MedFeb 26, 2026
    risk 0.42cvss 6.5epss 0.00

    The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included.

  • CVE-2026-1698MedFeb 26, 2026
    risk 0.40cvss 6.1epss 0.00

    A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior. This vulnerability only affects the endpoints…

  • CVE-2026-1696MedFeb 26, 2026
    risk 0.40cvss 6.1epss 0.00

    Some HTTP security headers are not properly set by the web server when sending responses to the client application.

  • CVE-2026-1695MedFeb 26, 2026
    risk 0.40cvss 6.1epss 0.00

    An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to trick a legitimate user into loading content from another site upon…

  • CVE-2026-1692MedFeb 26, 2026
    risk 0.40cvss 6.1epss 0.00

    A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to lure a successfully…

  • CVE-2025-4384MedMay 6, 2025
    risk 0.39cvss epss 0.00

    The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet become valid. This allows malicious devices to present certificates that are not rejected properly. The use of a client certificate reduces the risk for random…

  • CVE-2022-4312MedDec 12, 2022
    risk 0.36cvss 5.5epss 0.00

    A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files to discover the associated simple mail transfer…

  • CVE-2026-1694MedFeb 26, 2026
    risk 0.28cvss 4.3epss 0.00

    HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It unnecessarily exposes…

  • CVE-2024-12056LowDec 4, 2024
    risk 0.15cvss epss 0.00

    The Client secret is not checked when using the OAuth Password grant type. By exploiting this vulnerability, an attacker could connect to a web server using a client application not explicitly authorized as part of the OAuth deployment. Exploitation requires valid credentials…

  • CVE-2024-12057LowDec 9, 2024
    risk 0.12cvss epss 0.00

    User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end. By exploiting this vulnerability, an attacker could retrieve the credentials of a user by…

  • CVE-2026-14868MedJul 7, 2026
    risk 0.00cvss 5.5epss 0.00

    The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alter the existing configuration…

  • CVE-2026-14867MedJul 7, 2026
    risk 0.00cvss 5.5epss 0.00

    Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could retrieve users’ credentials.  Active Directory accounts are not affected by this vulnerability.