Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
nchsoftware vulnerabilities and exploits
(subscribe to this query)
5.5
CVSSv2
CVE-2021-37447
In NCH Quorum v2.03 and previous versions, an authenticated user can use directory traversal via documentdelete?file=/.. for file deletion.
Nchsoftware Quorum
3.5
CVSSv2
CVE-2021-37464
In NCH Quorum v2.03 and previous versions, XSS exists via Conference Description (stored).
Nchsoftware Quorum
3.5
CVSSv2
CVE-2021-37466
In NCH Quorum v2.03 and previous versions, XSS exists via /conference?id= (reflected).
Nchsoftware Quorum
4
CVSSv2
CVE-2021-37445
In NCH Quorum v2.03 and previous versions, an authenticated user can use directory traversal via logprop?file=/.. for file reading.
Nchsoftware Quorum
4
CVSSv2
CVE-2021-37446
In NCH Quorum v2.03 and previous versions, an authenticated user can use directory traversal via documentprop?file=/.. for file reading.
Nchsoftware Quorum
3.5
CVSSv2
CVE-2021-37463
In NCH Quorum v2.03 and previous versions, XSS exists via User Display Name (stored).
Nchsoftware Quorum
3.5
CVSSv2
CVE-2021-37465
In NCH Quorum v2.03 and previous versions, XSS exists via /uploaddoc?id= (reflected).
Nchsoftware Quorum
3.5
CVSSv2
CVE-2021-37467
In NCH Quorum v2.03 and previous versions, XSS exists via /conferencebrowseuploadfile?confid= (reflected).
Nchsoftware Quorum
3.5
CVSSv2
CVE-2021-37470
In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affected field to inject arbitrary JavaScript.
Nchsoftware Webdictate
4
CVSSv2
CVE-2020-13474
In NCH Express Accounts 8.24 and previous versions, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.
Nchsoftware Express Accounts
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »