Vulnerabilities > NCH

DATE CVE VULNERABILITY TITLE RISK
2021-07-25 CVE-2021-37439 Path Traversal vulnerability in NCH Flexiserver 6.00
NCH FlexiServer v6.00 suffers from a syslog?file=/..
network
low complexity
nch CWE-22
6.5
2021-07-25 CVE-2021-37440 Path Traversal vulnerability in NCH Axon PBX 2.02
NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/..
network
low complexity
nch CWE-22
6.5
2021-07-25 CVE-2021-37441 Path Traversal vulnerability in NCH Axon PBX 2.02
NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/..
network
low complexity
nch CWE-22
8.8
2021-07-25 CVE-2021-37452 Cleartext Storage of Sensitive Information vulnerability in NCH Quorum
NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files.
local
low complexity
nch CWE-312
5.5
2021-07-25 CVE-2021-37468 Cleartext Storage of Sensitive Information vulnerability in NCH Reflect Customer Relationship Management 3.01
NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.
local
low complexity
nch CWE-312
3.3
2021-07-25 CVE-2021-37469 Path Traversal vulnerability in NCH Webdictate
In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/..
network
low complexity
nch CWE-22
6.5
2018-06-01 CVE-2018-11552 Cross-site Scripting vulnerability in NCH Axon PBX 2.02
There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field.
network
low complexity
nch CWE-79
6.1
2018-06-01 CVE-2018-11551 Untrusted Search Path vulnerability in NCH Axon PBX 2.02
AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system.
local
low complexity
nch CWE-426
7.8