Vulnerabilities > Osisoft > PI WEB API > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-06-23 CVE-2020-12021 Cross-site Scripting vulnerability in Osisoft PI web API
In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cross-site scripting attack, which may allow an attacker to remotely execute arbitrary code.
network
low complexity
osisoft CWE-79
critical
9.0
2018-03-14 CVE-2018-7500 Unspecified vulnerability in Osisoft PI Vision and PI web API
A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior.
network
low complexity
osisoft
critical
9.8