ARC Informatique
First CVE: Dec 4, 2024Active for: 2 years
14
CVEs Published
More CVEs Published than 34% of tracked CNAs
4.7
Avg CVEs / Year
More Avg CVEs / Year than 31% of tracked CNAs
5.5
Avg CVSS Score
Higher Avg CVSS Score than 5% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by ARC Informatique as a CNA, 100.0% affect products that ARC Informatique develops as a vendor.
100.0%
Self-reported: 14Third-party: 0
Of all the CVEs published that affect products developed by ARC Informatique, 58.3% are self-published by ARC Informatique as a CNA.
58.3%
41.7%
Self-published: 14Published by other CNAs: 10
Trends Over Time
The number and severity of CVEs published by ARC Informatique over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 4, 2024
19 months ago
Most Recent CVE
Jul 7, 2026
17 days ago
Top CVEs
All CVEs published by ARC Informatique as a CNA, regardless of affected vendor or product.
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-14868MEDIUM The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong en | Jul 7, 2026 | 5.5 | 29 | NO | NO |
CVE-2026-1693HIGH The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in v | Feb 26, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-14867MEDIUM Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could retrieve users’ credentials.
Act | Jul 7, 2026 | 5.5 | 27 | NO | NO |
CVE-2026-1697MEDIUM The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included. | Feb 26, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-1698MEDIUM A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject har | Feb 26, 2026 | 6.1 | 25 | NO | NO |
CVE-2026-1696MEDIUM Some HTTP security headers are not properly set by the web server when sending responses to the client application. | Feb 26, 2026 | 6.1 | 25 | NO | NO |
CVE-2026-1695MEDIUM An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might all | Feb 26, 2026 | 6.1 | 25 | NO | NO |
CVE-2026-1692MEDIUM A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 1 | Feb 26, 2026 | 6.1 | 25 | NO | NO |
CVE-2025-9999HIGH Some payload elements of the messages sent between two stations in a networking architecture are not properly checked on the receiving station allowing an attacker to execute unaut | Sep 5, 2025 | 7.6 | 24 | NO | NO |
CVE-2025-9998MEDIUM The sequence of packets received by a Networking server are not correctly checked.
An attacker could exploit this vulnerability to send specially crafted messages to force the app | Sep 5, 2025 | 6.0 | 21 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA14 CVEs
14%
71%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local3 (21.4%)
Network8 (57.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (71.4%)
High4 (28.6%)
Unknown0 (0.0%)
User Interaction
None8 (57.1%)
Unknown0 (0.0%)
Required5 (35.7%)
Privileges Required
Low2 (14.3%)
High1 (7.1%)
None11 (78.6%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by ARC Informatique as a CNA.
Media Mentions
Media articles that mention a CVE ID published by ARC Informatique as a CNA — matched by CVE ID, not by organization name.