Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
nchsoftware vulnerabilities and exploits
(subscribe to this query)
356
VMScore
CVE-2021-37445
In NCH Quorum v2.03 and previous versions, an authenticated user can use directory traversal via logprop?file=/.. for file reading.
Nchsoftware Quorum
356
VMScore
CVE-2021-37446
In NCH Quorum v2.03 and previous versions, an authenticated user can use directory traversal via documentprop?file=/.. for file reading.
Nchsoftware Quorum
490
VMScore
CVE-2021-37447
In NCH Quorum v2.03 and previous versions, an authenticated user can use directory traversal via documentdelete?file=/.. for file deletion.
Nchsoftware Quorum
312
VMScore
CVE-2021-37463
In NCH Quorum v2.03 and previous versions, XSS exists via User Display Name (stored).
Nchsoftware Quorum
312
VMScore
CVE-2021-37464
In NCH Quorum v2.03 and previous versions, XSS exists via Conference Description (stored).
Nchsoftware Quorum
312
VMScore
CVE-2021-37465
In NCH Quorum v2.03 and previous versions, XSS exists via /uploaddoc?id= (reflected).
Nchsoftware Quorum
312
VMScore
CVE-2021-37466
In NCH Quorum v2.03 and previous versions, XSS exists via /conference?id= (reflected).
Nchsoftware Quorum
312
VMScore
CVE-2021-37467
In NCH Quorum v2.03 and previous versions, XSS exists via /conferencebrowseuploadfile?confid= (reflected).
Nchsoftware Quorum
312
VMScore
CVE-2021-37470
In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affected field to inject arbitrary JavaScript.
Nchsoftware Webdictate
578
VMScore
CVE-2021-37444
NCH IVM Attendant v5.12 and previous versions suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathname is set to a Windows startup folder, a file for the inbuilt Out-Going Message functio...
Nchsoftware Ivm Attendant
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23316
SQL injection
type confusion
CVE-2024-20697
CVE-2024-4344
local
CVE-2024-30043
CVE-2024-3821
CVE-2024-5041
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »