Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2021-37444
NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execut…
Ivm Attendant
after 5.12
HIGH 8.1
CVE-2021-37443
NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.
Ivm Attendant
after 5.12
HIGH 8.1
CVE-2021-37447
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/.. for file deletion.
Quorum
after 2.03
MEDIUM 6.5
CVE-2021-37445
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading.
Quorum
after 2.03
MEDIUM 5.4
CVE-2021-37448
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via the Mailbox name (stored).
Ivm Attendant
after 5.12
MEDIUM 5.4
CVE-2021-37449
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmlist?folder= (reflected).
Ivm Attendant
after 5.12
MEDIUM 6.5
CVE-2021-37442
NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files.
Ivm Attendant
after 5.12
MEDIUM 5.4
CVE-2021-37457
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).
Axon Pbx
after 2.22
MEDIUM 5.4
CVE-2021-37458
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).
Axon Pbx
after 2.22
MEDIUM 5.4
CVE-2021-37459
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).
Axon Pbx
after 2.22
MEDIUM 5.4
CVE-2021-37460
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected).
Axon Pbx
after 2.22
MEDIUM 5.4
CVE-2021-37461
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected).
Axon Pbx
after 2.22
MEDIUM 5.4
CVE-2021-37462
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected).
Axon Pbx
after 2.22
MEDIUM 5.4
CVE-2021-37463
In NCH Quorum v2.03 and earlier, XSS exists via User Display Name (stored).
Quorum
after 2.03
MEDIUM 5.4
CVE-2021-37464
In NCH Quorum v2.03 and earlier, XSS exists via Conference Description (stored).
Quorum
after 2.03
MEDIUM 5.4
CVE-2021-37465
In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected).
Quorum
after 2.03
MEDIUM 5.4
CVE-2021-37466
In NCH Quorum v2.03 and earlier, XSS exists via /conference?id= (reflected).
Quorum
after 2.03
MEDIUM 5.4
CVE-2021-37467
In NCH Quorum v2.03 and earlier, XSS exists via /conferencebrowseuploadfile?confid= (reflected).
Quorum
after 2.03
MEDIUM 5.4
CVE-2021-37470
In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affect…
Webdictate
after 2.13
MEDIUM 5.4
CVE-2021-37450
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).
Ivm Attendant
after 5.12
MEDIUM 5.4
CVE-2021-37451
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).
Ivm Attendant
after 5.12
MEDIUM 5.4
CVE-2021-37453
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).
Axon Pbx
after 2.22
MEDIUM 5.4
CVE-2021-37454
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).
Axon Pbx
after 2.22
MEDIUM 5.4
CVE-2021-37455
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).
Axon Pbx
after 2.22
MEDIUM 5.4
CVE-2021-37456
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).
Axon Pbx
after 2.22
MEDIUM 6.5
CVE-2020-13474
In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities suc…
Express Accounts
after 8.24
MEDIUM 5.5
CVE-2020-13473
NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.
Express Accounts
after 8.24
HIGH 7.8
CVE-2020-11560
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
Express Invoice
No fix yet
HIGH 8.8
CVE-2020-11561
In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add…
Express Invoice
No fix yet
MEDIUM 5.4
CVE-2019-16330
In NCH Express Accounts Accounting v7.02, persistent cross site scripting (XSS) exists in Invoices/Sales Orders/Items/Customers/Quotes input field. A…
Express Accounts Accounting
No fix yet