Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
nchsoftware vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2021-37444
NCH IVM Attendant v5.12 and previous versions suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathname is set to a Windows startup folder, a file for the inbuilt Out-Going Message functio...
Nchsoftware Ivm Attendant
8.8
CVSSv3
CVE-2020-11561
In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add New Item" screen.
Nchsoftware Express Invoice 7.25
8.1
CVSSv3
CVE-2021-37443
NCH IVM Attendant v5.12 and previous versions allows path traversal via the logdeleteselected check0 parameter for file deletion.
Nchsoftware Ivm Attendant
8.1
CVSSv3
CVE-2021-37447
In NCH Quorum v2.03 and previous versions, an authenticated user can use directory traversal via documentdelete?file=/.. for file deletion.
Nchsoftware Quorum
7.8
CVSSv3
CVE-2020-11560
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
Nchsoftware Express Invoice 7.25
1 EDB exploit
6.5
CVSSv3
CVE-2021-37442
NCH IVM Attendant v5.12 and previous versions allows path traversal via viewfile?file=/.. to read files.
Nchsoftware Ivm Attendant
6.5
CVSSv3
CVE-2021-37445
In NCH Quorum v2.03 and previous versions, an authenticated user can use directory traversal via logprop?file=/.. for file reading.
Nchsoftware Quorum
6.5
CVSSv3
CVE-2020-13474
In NCH Express Accounts 8.24 and previous versions, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.
Nchsoftware Express Accounts
5.5
CVSSv3
CVE-2020-13473
NCH Express Accounts 8.24 and previous versions allows local users to discover the cleartext password by reading the configuration file.
Nchsoftware Express Accounts
5.4
CVSSv3
CVE-2021-37449
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and previous versions via /ogmlist?folder= (reflected).
Nchsoftware Ivm Attendant
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23692
CVE-2012-1823
memory leak
CVE-2024-0627
CVE-2024-31402
privilege escalation
CVE-2024-36418
remote code execution
CVE-2024-27844
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »