Vulnerabilities in arcinfo
14 resultsVexday analysis
A Arcinfo apresenta um perfil de risco moderado com 14 vulnerabilidades catalogadas, predominantemente relacionadas a injeção de código (CWE-79), embora nenhuma tenha atingido severidade crítica. Não há indicadores de exploração ativa em campo, mas 2 vulnerabilidades publicadas nos últimos 90 dias sugerem que o fornecedor continua exposto a descobertas recentes. O risco permanece contido pela ausência de exploração documentada, porém recomenda-se monitoramento das fraquezas de entrada de dados.
CVE-2024-12056LOWClient Secret not checked with OAuth Password grant typeEPSS 0.3%CVE-2026-1693MEDIUMUse of vulnerable Resource Owner Password Credentials flowEPSS 0.3%CVE-2025-9998MEDIUMImproper validation of packets sequencingEPSS 0.3%CVE-2026-1698MEDIUMHTTP Host header vulnerability in WebClient and WebScheduler web appsEPSS 0.2%CVE-2026-1695MEDIUMXSS vulnerability upon unsuccessful authenticationEPSS 0.2%CVE-2026-1694LOWServer configuration details in HTTP headersEPSS 0.2%CVE-2025-9999HIGHImproper validation of payload elementsEPSS 0.2%CVE-2026-1696LOWMissing security HTTP headersEPSS 0.1%CVE-2024-12057LOWUser credentials recorded in log filesEPSS 0.1%CVE-2025-4384MEDIUMCertificate validity not properly verifiedEPSS 0.1%CVE-2026-1697MEDIUMUse of unsecure cookies for GraphicalData web service and WebClient web appEPSS 0.1%CVE-2026-1692MEDIUMMissing origin validation in GraphicalData web service requestsEPSS 0.1%CVE-2026-14867MEDIUMInsecure password storage in User directoryEPSS 0.1%CVE-2026-14868HIGHWeak encryption mechanism for User directoryEPSS 0.1%