nchsoftware records
34 published records for vendor nchsoftware.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')23
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-425 Direct Request ('Forced Browsing')2
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-522 Insufficiently Protected Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAll records
34 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2020-11561No exploit | In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such asnchsoftware · express invoice · CWE-425 | High8.8 | — | 2.2% | Apr 7, 2020 |
36Monitor | CVE-2021-37444No exploit | NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive.nchsoftware · ivm attendant · CWE-22 | High8.8 | — | 1.9% | Jul 25, 2021 |
32Monitor | CVE-2021-37447No exploit | In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/..nchsoftware · quorum · CWE-22 | High8.1 | — | 1.6% | Jul 25, 2021 |
32Monitor | CVE-2021-37443No exploit | NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.nchsoftware · ivm attendant · CWE-22 | High8.1 | — | 1.2% | Jul 25, 2021 |
31Monitor | CVE-2020-11560Proof of concept | NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.nchsoftware · express invoice · CWE-522 | High7.8 | — | 1.0% | Apr 7, 2020 |
27Monitor | CVE-2010-5220No exploit | Untrusted search path vulnerability in MEO Encryption Software 2.02 allows local users to gain privileges via a Trojan horse dwmapi.dll filenchsoftware · meo encryption software | Medium6.9 | — | 0.4% | Sep 6, 2012 |
26Monitor | CVE-2021-37445No exploit | In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/..nchsoftware · quorum · CWE-22 | Medium6.5 | — | 1.4% | Jul 25, 2021 |
26Monitor | CVE-2021-37442No exploit | NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/..nchsoftware · ivm attendant · CWE-22 | Medium6.5 | — | 1.2% | Jul 25, 2021 |
26Monitor | CVE-2020-13474No exploit | In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalnchsoftware · express accounts · CWE-425 | Medium6.5 | — | 0.8% | Dec 28, 2020 |
22Monitor | CVE-2020-13473No exploit | NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.nchsoftware · express accounts · CWE-312 | Medium5.5 | — | 0.3% | Dec 28, 2020 |
21Monitor | CVE-2021-37451No exploit | Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).nchsoftware · ivm attendant · CWE-79 | Medium5.4 | — | 0.6% | Jul 25, 2021 |
21Monitor | CVE-2021-37457No exploit | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).nchsoftware · axon pbx · CWE-79 | Medium5.4 | — | 0.6% | Jul 25, 2021 |
21Monitor | CVE-2021-37458No exploit | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).nchsoftware · axon pbx · CWE-79 | Medium5.4 | — | 0.6% | Jul 25, 2021 |
21Monitor | CVE-2021-37459No exploit | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).nchsoftware · axon pbx · CWE-79 | Medium5.4 | — | 0.6% | Jul 25, 2021 |
21Monitor | CVE-2021-37463No exploit | In NCH Quorum v2.03 and earlier, XSS exists via User Display Name (stored).nchsoftware · quorum · CWE-79 | Medium5.4 | — | 0.6% | Jul 25, 2021 |
21Monitor | CVE-2021-37465No exploit | In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected).nchsoftware · quorum · CWE-79 | Medium5.4 | — | 0.6% | Jul 25, 2021 |
21Monitor | CVE-2021-37450No exploit | Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).nchsoftware · ivm attendant · CWE-79 | Medium5.4 | — | 0.6% | Jul 25, 2021 |
21Monitor | CVE-2021-37462No exploit | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected).nchsoftware · axon pbx · CWE-79 | Medium5.4 | — | 0.6% | Jul 25, 2021 |
21Monitor | CVE-2021-37464No exploit | In NCH Quorum v2.03 and earlier, XSS exists via Conference Description (stored).nchsoftware · quorum · CWE-79 | Medium5.4 | — | 0.6% | Jul 25, 2021 |
21Monitor | CVE-2021-37453No exploit | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).nchsoftware · axon pbx · CWE-79 | Medium5.4 | — | 0.6% | Jul 25, 2021 |
21Monitor | CVE-2021-37454No exploit | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).nchsoftware · axon pbx · CWE-79 | Medium5.4 | — | 0.6% | Jul 25, 2021 |
21Monitor | CVE-2021-37455No exploit | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).nchsoftware · axon pbx · CWE-79 | Medium5.4 | — | 0.6% | Jul 25, 2021 |
21Monitor | CVE-2021-37456No exploit | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).nchsoftware · axon pbx · CWE-79 | Medium5.4 | — | 0.6% | Jul 25, 2021 |
21Monitor | CVE-2021-37466No exploit | In NCH Quorum v2.03 and earlier, XSS exists via /conference?id= (reflected).nchsoftware · quorum · CWE-79 | Medium5.4 | — | 0.6% | Jul 25, 2021 |
21Monitor | CVE-2021-37467No exploit | In NCH Quorum v2.03 and earlier, XSS exists via /conferencebrowseuploadfile?confid= (reflected).nchsoftware · quorum · CWE-79 | Medium5.4 | — | 0.6% | Jul 25, 2021 |
- CVE-2020-1156136Monitor
In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as
HighCVSS 8.8No exploitEPSS 2%nchsoftware · express invoiceApr 7, 2020
- CVE-2021-3744436Monitor
NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive.
HighCVSS 8.8No exploitEPSS 2%nchsoftware · ivm attendantJul 25, 2021
- CVE-2021-3744732Monitor
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/..
HighCVSS 8.1No exploitEPSS 2%nchsoftware · quorumJul 25, 2021
- CVE-2021-3744332Monitor
NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.
HighCVSS 8.1No exploitEPSS 1%nchsoftware · ivm attendantJul 25, 2021
- CVE-2020-1156031Monitor
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
HighCVSS 7.8Proof of conceptEPSS 1%nchsoftware · express invoiceApr 7, 2020
- CVE-2010-522027Monitor
Untrusted search path vulnerability in MEO Encryption Software 2.02 allows local users to gain privileges via a Trojan horse dwmapi.dll file
MediumCVSS 6.9No exploitEPSS 0%nchsoftware · meo encryption softwareSep 6, 2012
- CVE-2021-3744526Monitor
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/..
MediumCVSS 6.5No exploitEPSS 1%nchsoftware · quorumJul 25, 2021
- CVE-2021-3744226Monitor
NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/..
MediumCVSS 6.5No exploitEPSS 1%nchsoftware · ivm attendantJul 25, 2021
- CVE-2020-1347426Monitor
In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functional
MediumCVSS 6.5No exploitEPSS 1%nchsoftware · express accountsDec 28, 2020
- CVE-2020-1347322Monitor
NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.
MediumCVSS 5.5No exploitEPSS 0%nchsoftware · express accountsDec 28, 2020
- CVE-2021-3745121Monitor
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).
MediumCVSS 5.4No exploitEPSS 1%nchsoftware · ivm attendantJul 25, 2021
- CVE-2021-3745721Monitor
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).
MediumCVSS 5.4No exploitEPSS 1%nchsoftware · axon pbxJul 25, 2021
- CVE-2021-3745821Monitor
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).
MediumCVSS 5.4No exploitEPSS 1%nchsoftware · axon pbxJul 25, 2021
- CVE-2021-3745921Monitor
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).
MediumCVSS 5.4No exploitEPSS 1%nchsoftware · axon pbxJul 25, 2021
- CVE-2021-3746321Monitor
In NCH Quorum v2.03 and earlier, XSS exists via User Display Name (stored).
MediumCVSS 5.4No exploitEPSS 1%nchsoftware · quorumJul 25, 2021
- CVE-2021-3746521Monitor
In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected).
MediumCVSS 5.4No exploitEPSS 1%nchsoftware · quorumJul 25, 2021
- CVE-2021-3745021Monitor
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).
MediumCVSS 5.4No exploitEPSS 1%nchsoftware · ivm attendantJul 25, 2021
- CVE-2021-3746221Monitor
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected).
MediumCVSS 5.4No exploitEPSS 1%nchsoftware · axon pbxJul 25, 2021
- CVE-2021-3746421Monitor
In NCH Quorum v2.03 and earlier, XSS exists via Conference Description (stored).
MediumCVSS 5.4No exploitEPSS 1%nchsoftware · quorumJul 25, 2021
- CVE-2021-3745321Monitor
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).
MediumCVSS 5.4No exploitEPSS 1%nchsoftware · axon pbxJul 25, 2021
- CVE-2021-3745421Monitor
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).
MediumCVSS 5.4No exploitEPSS 1%nchsoftware · axon pbxJul 25, 2021
- CVE-2021-3745521Monitor
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).
MediumCVSS 5.4No exploitEPSS 1%nchsoftware · axon pbxJul 25, 2021
- CVE-2021-3745621Monitor
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).
MediumCVSS 5.4No exploitEPSS 1%nchsoftware · axon pbxJul 25, 2021
- CVE-2021-3746621Monitor
In NCH Quorum v2.03 and earlier, XSS exists via /conference?id= (reflected).
MediumCVSS 5.4No exploitEPSS 1%nchsoftware · quorumJul 25, 2021
- CVE-2021-3746721Monitor
In NCH Quorum v2.03 and earlier, XSS exists via /conferencebrowseuploadfile?confid= (reflected).
MediumCVSS 5.4No exploitEPSS 1%nchsoftware · quorumJul 25, 2021