Vulnerabilities > Nuance

DATE CVE VULNERABILITY TITLE RISK
2021-08-12 CVE-2021-37599 SQL Injection vulnerability in Nuance Winscribe Dictation 4.1.0.99
The exporter/Login.aspx login form in the Exporter in Nuance Winscribe Dictation 4.1.0.99 is vulnerable to SQL injection that allows a remote, unauthenticated attacker to read the database (and execute code in some situations) via the txtPassword parameter.
network
low complexity
nuance CWE-89
critical
9.8
2021-01-07 CVE-2018-18688 Improper Verification of Cryptographic Signature vulnerability in multiple products
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures.
5.3