Filtered by vendor Nchsoftware Subscriptions
Total 34 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-11560 1 Nchsoftware 1 Express Invoice 2023-06-27 7.8 High
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
CVE-2010-5220 1 Nchsoftware 1 Meo Encryption Software 2022-10-03 N/A
Untrusted search path vulnerability in MEO Encryption Software 2.02 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .meo or .cry file. NOTE: some of these details are obtained from third party information.
CVE-2021-37446 1 Nchsoftware 1 Quorum 2021-08-04 4.3 Medium
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentprop?file=/.. for file reading.
CVE-2021-37447 1 Nchsoftware 1 Quorum 2021-08-04 8.1 High
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/.. for file deletion.
CVE-2021-37448 1 Nchsoftware 1 Ivm Attendant 2021-08-04 5.4 Medium
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via the Mailbox name (stored).
CVE-2021-37449 1 Nchsoftware 1 Ivm Attendant 2021-08-04 5.4 Medium
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmlist?folder= (reflected).
CVE-2021-37463 1 Nchsoftware 1 Quorum 2021-07-30 5.4 Medium
In NCH Quorum v2.03 and earlier, XSS exists via User Display Name (stored).
CVE-2021-37464 1 Nchsoftware 1 Quorum 2021-07-30 5.4 Medium
In NCH Quorum v2.03 and earlier, XSS exists via Conference Description (stored).
CVE-2021-37465 1 Nchsoftware 1 Quorum 2021-07-30 5.4 Medium
In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected).
CVE-2021-37466 1 Nchsoftware 1 Quorum 2021-07-30 5.4 Medium
In NCH Quorum v2.03 and earlier, XSS exists via /conference?id= (reflected).
CVE-2021-37467 1 Nchsoftware 1 Quorum 2021-07-30 5.4 Medium
In NCH Quorum v2.03 and earlier, XSS exists via /conferencebrowseuploadfile?confid= (reflected).
CVE-2021-37470 1 Nchsoftware 1 Webdictate 2021-07-30 5.4 Medium
In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affected field to inject arbitrary JavaScript.
CVE-2021-37442 1 Nchsoftware 1 Ivm Attendant 2021-07-30 6.5 Medium
NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files.
CVE-2021-37444 1 Nchsoftware 1 Ivm Attendant 2021-07-30 8.8 High
NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathname is set to a Windows startup folder, a file for the inbuilt Out-Going Message function, or a file for the the inbuilt Autodial function.
CVE-2021-37443 1 Nchsoftware 1 Ivm Attendant 2021-07-30 8.1 High
NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.
CVE-2021-37445 1 Nchsoftware 1 Quorum 2021-07-30 6.5 Medium
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading.
CVE-2021-37450 1 Nchsoftware 1 Ivm Attendant 2021-07-28 5.4 Medium
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).
CVE-2021-37451 1 Nchsoftware 1 Ivm Attendant 2021-07-28 5.4 Medium
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).
CVE-2021-37453 1 Nchsoftware 1 Axon Pbx 2021-07-28 5.4 Medium
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).
CVE-2021-37454 1 Nchsoftware 1 Axon Pbx 2021-07-28 5.4 Medium
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).