Filtered by vendor Nchsoftware Subscriptions
Total 34 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2010-5220 1 Nchsoftware 1 Meo Encryption Software 2024-09-17 N/A
Untrusted search path vulnerability in MEO Encryption Software 2.02 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .meo or .cry file. NOTE: some of these details are obtained from third party information.
CVE-2019-16282 1 Nchsoftware 1 Express Invoice 2024-08-05 5.4 Medium
In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Items/Customers fields parameter to inject arbitrary JavaScript.
CVE-2019-16330 1 Nchsoftware 1 Express Accounts Accounting 2024-08-05 5.4 Medium
In NCH Express Accounts Accounting v7.02, persistent cross site scripting (XSS) exists in Invoices/Sales Orders/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Sales Orders/Items/Customers/Quotes fields parameter to inject arbitrary JavaScript.
CVE-2020-13474 1 Nchsoftware 1 Express Accounts 2024-08-04 6.5 Medium
In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.
CVE-2020-13476 1 Nchsoftware 1 Express Invoice 2024-08-04 4.8 Medium
NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module.
CVE-2020-13473 1 Nchsoftware 1 Express Accounts 2024-08-04 5.5 Medium
NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.
CVE-2020-11560 1 Nchsoftware 1 Express Invoice 2024-08-04 7.8 High
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
CVE-2020-11561 1 Nchsoftware 1 Express Invoice 2024-08-04 8.8 High
In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add New Item" screen.
CVE-2021-37470 1 Nchsoftware 1 Webdictate 2024-08-04 5.4 Medium
In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affected field to inject arbitrary JavaScript.
CVE-2021-37465 1 Nchsoftware 1 Quorum 2024-08-04 5.4 Medium
In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected).
CVE-2021-37454 1 Nchsoftware 1 Axon Pbx 2024-08-04 5.4 Medium
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).
CVE-2021-37461 1 Nchsoftware 1 Axon Pbx 2024-08-04 5.4 Medium
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected).
CVE-2021-37462 1 Nchsoftware 1 Axon Pbx 2024-08-04 5.4 Medium
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected).
CVE-2021-37451 1 Nchsoftware 1 Ivm Attendant 2024-08-04 5.4 Medium
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).
CVE-2021-37453 1 Nchsoftware 1 Axon Pbx 2024-08-04 5.4 Medium
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).
CVE-2021-37450 1 Nchsoftware 1 Ivm Attendant 2024-08-04 5.4 Medium
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).
CVE-2021-37466 1 Nchsoftware 1 Quorum 2024-08-04 5.4 Medium
In NCH Quorum v2.03 and earlier, XSS exists via /conference?id= (reflected).
CVE-2021-37445 1 Nchsoftware 1 Quorum 2024-08-04 6.5 Medium
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading.
CVE-2021-37467 1 Nchsoftware 1 Quorum 2024-08-04 5.4 Medium
In NCH Quorum v2.03 and earlier, XSS exists via /conferencebrowseuploadfile?confid= (reflected).
CVE-2021-37464 1 Nchsoftware 1 Quorum 2024-08-04 5.4 Medium
In NCH Quorum v2.03 and earlier, XSS exists via Conference Description (stored).