ZeroHour

Vulnerabilities

15 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-14868
+1 in the same advisory: …14867
The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0

The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alter the existing configuration and ultimately gain privileged access to the PcVue application.

NVD description · AI analysis pending
8.4
group max
<1%
  • arcinfo pcvue
CVE-2026-1693
The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue fe

The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It might allow a remote attacker to steal user credentials.

NVD description · AI analysis pending
5.3
group max
<1%
  • arcinfo pcvue
CVE-2022-4311
+1 in the same advisory: …4312
An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2.

An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users unauthorized access to the underlying data sources.

NVD description · AI analysis pending
6.5
group max
<1%
  • arcinfo pcvue
CVE-2022-2569
The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belongi

The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users

NVD description · AI analysis pending
5.5<1%
  • arcinfo pcvue
CVE-2020-26867
+2 in the same advisory: …26868 …26869
ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbi

ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.

NVD description · AI analysis pending
9.8
group max
4%
  • arcinfo pcvue