Pi web api
This hub aggregates every CVE we track for Pi web api, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
10
CVEs tracked
2
Critical
4
High
0
In CISA KEV
Severity distribution
HIGH4MEDIUM4CRITICAL2
Monthly trend
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 10 most recently published vulnerabilities affecting Pi web api.
- CVE-2025-2745AVEVA PI Web API Cross-site Scripting6.5
- CVE-2024-3468Deserialization of Untrusted Data in AVEVA PI Web API7.6
- CVE-2021-43549OSIsoft PI Web API6.9
- CVE-2020-12021In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cross-site scripting attack, which may allow an attacker to remotely execute arbi...9.0
- CVE-2019-13516In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection setting that has not taken effect.8.8
- CVE-2019-13515OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.6.5
- CVE-2018-7500A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Privileges may be escalated, giving attackers access to the PI System via the s...9.8
- CVE-2018-7508A Cross-site Scripting issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Cross-site scripting may occur when input is incorrectly neutralized.6.1
- CVE-2017-7926A Cross-Site Request Forgery issue was discovered in OSIsoft PI Web API versions prior to 2017 (1.9.0). The vulnerability allows cross-site request forgery (CSRF) attacks to occur when an otherwise...8.8
- CVE-2017-5153An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 integrated install kit. An information exposure t...7.8
Product normalization is registry-driven with AI assist and human review. How it works