İçeriğe atla
Noroxi

nchsoftware kayıtları

nchsoftware üreticisine ait 34 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

34 kayıt
  • CVE-2020-11561
    36İzleyin

    In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as

    YüksekCVSS 8,8İstismar yokEPSS %2

    nchsoftware · express invoice7 Nis 2020

  • CVE-2021-37444
    36İzleyin

    NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive.

    YüksekCVSS 8,8İstismar yokEPSS %2

    nchsoftware · ivm attendant25 Tem 2021

  • CVE-2021-37447
    32İzleyin

    In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/..

    YüksekCVSS 8,1İstismar yokEPSS %2

    nchsoftware · quorum25 Tem 2021

  • CVE-2021-37443
    32İzleyin

    NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.

    YüksekCVSS 8,1İstismar yokEPSS %1

    nchsoftware · ivm attendant25 Tem 2021

  • CVE-2020-11560
    31İzleyin

    NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.

    YüksekCVSS 7,8Kavram kanıtıEPSS %1

    nchsoftware · express invoice7 Nis 2020

  • CVE-2010-5220
    27İzleyin

    Untrusted search path vulnerability in MEO Encryption Software 2.02 allows local users to gain privileges via a Trojan horse dwmapi.dll file

    OrtaCVSS 6,9İstismar yokEPSS %0

    nchsoftware · meo encryption software6 Eyl 2012

  • CVE-2021-37445
    26İzleyin

    In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/..

    OrtaCVSS 6,5İstismar yokEPSS %1

    nchsoftware · quorum25 Tem 2021

  • CVE-2021-37442
    26İzleyin

    NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/..

    OrtaCVSS 6,5İstismar yokEPSS %1

    nchsoftware · ivm attendant25 Tem 2021

  • CVE-2020-13474
    26İzleyin

    In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functional

    OrtaCVSS 6,5İstismar yokEPSS %1

    nchsoftware · express accounts28 Ara 2020

  • CVE-2020-13473
    22İzleyin

    NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.

    OrtaCVSS 5,5İstismar yokEPSS %0

    nchsoftware · express accounts28 Ara 2020

  • CVE-2021-37451
    21İzleyin

    Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).

    OrtaCVSS 5,4İstismar yokEPSS %1

    nchsoftware · ivm attendant25 Tem 2021

  • CVE-2021-37457
    21İzleyin

    Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).

    OrtaCVSS 5,4İstismar yokEPSS %1

    nchsoftware · axon pbx25 Tem 2021

  • CVE-2021-37458
    21İzleyin

    Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).

    OrtaCVSS 5,4İstismar yokEPSS %1

    nchsoftware · axon pbx25 Tem 2021

  • CVE-2021-37459
    21İzleyin

    Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).

    OrtaCVSS 5,4İstismar yokEPSS %1

    nchsoftware · axon pbx25 Tem 2021

  • CVE-2021-37463
    21İzleyin

    In NCH Quorum v2.03 and earlier, XSS exists via User Display Name (stored).

    OrtaCVSS 5,4İstismar yokEPSS %1

    nchsoftware · quorum25 Tem 2021

  • CVE-2021-37465
    21İzleyin

    In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected).

    OrtaCVSS 5,4İstismar yokEPSS %1

    nchsoftware · quorum25 Tem 2021

  • CVE-2021-37450
    21İzleyin

    Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).

    OrtaCVSS 5,4İstismar yokEPSS %1

    nchsoftware · ivm attendant25 Tem 2021

  • CVE-2021-37462
    21İzleyin

    Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected).

    OrtaCVSS 5,4İstismar yokEPSS %1

    nchsoftware · axon pbx25 Tem 2021

  • CVE-2021-37464
    21İzleyin

    In NCH Quorum v2.03 and earlier, XSS exists via Conference Description (stored).

    OrtaCVSS 5,4İstismar yokEPSS %1

    nchsoftware · quorum25 Tem 2021

  • CVE-2021-37453
    21İzleyin

    Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).

    OrtaCVSS 5,4İstismar yokEPSS %1

    nchsoftware · axon pbx25 Tem 2021

  • CVE-2021-37454
    21İzleyin

    Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).

    OrtaCVSS 5,4İstismar yokEPSS %1

    nchsoftware · axon pbx25 Tem 2021

  • CVE-2021-37455
    21İzleyin

    Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).

    OrtaCVSS 5,4İstismar yokEPSS %1

    nchsoftware · axon pbx25 Tem 2021

  • CVE-2021-37456
    21İzleyin

    Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).

    OrtaCVSS 5,4İstismar yokEPSS %1

    nchsoftware · axon pbx25 Tem 2021

  • CVE-2021-37466
    21İzleyin

    In NCH Quorum v2.03 and earlier, XSS exists via /conference?id= (reflected).

    OrtaCVSS 5,4İstismar yokEPSS %1

    nchsoftware · quorum25 Tem 2021

  • CVE-2021-37467
    21İzleyin

    In NCH Quorum v2.03 and earlier, XSS exists via /conferencebrowseuploadfile?confid= (reflected).

    OrtaCVSS 5,4İstismar yokEPSS %1

    nchsoftware · quorum25 Tem 2021