CVE Tools

Nchsoftware

31 CVEs tracked since 2019. Since Oct 2019, none of them reached CISA KEV.

Nchsoftware CVEs per month

Oct 2019 to Jul 2021. Point at a month, or focus the strip and use the arrow keys.
Nchsoftware CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2019-1020
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-1230
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07260

Products

The products that kept showing up in Nchsoftware's monthly top three, with their CVEs summed over those months.

  1. Axon Pbx101 month
  2. Quorum81 month
  3. Ivm Attendant71 month
  4. Express Accounts21 month
  5. Express Invoice22 months
  6. Express Accounts Accounting11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Nchsoftware.

  1. CVE-2021-37442NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files.6.5
  2. CVE-2021-37443NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.8.1
  3. CVE-2021-37444NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathname is set to a Wind...8.8
  4. CVE-2021-37445In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading.6.5
  5. CVE-2021-37446In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentprop?file=/.. for file reading.4.3
  6. CVE-2021-37447In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/.. for file deletion.8.1
  7. CVE-2021-37448Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via the Mailbox name (stored).5.4
  8. CVE-2021-37449Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmlist?folder= (reflected).5.4
  9. CVE-2021-37450Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).5.4
  10. CVE-2021-37451Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).5.4
  11. CVE-2021-37453Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).5.4
  12. CVE-2021-37454Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).5.4
  13. CVE-2021-37455Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).5.4
  14. CVE-2021-37456Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).5.4
  15. CVE-2021-37457Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).5.4

The record

Peak rank
#19 in Jul 2021
Busiest month shown
Jul 2021, 26 CVEs
Months with a KEV entry
0 since Oct 2019
Monthly snapshots
3 since 2019
Nchsoftware's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store