Skip to main content

Vendor archive

nchsoftware CVEs

Beta · best-effort

34 CVEs tagged to vendor nchsoftware0 Critical, 5 High, 29 Medium, 0 Low, 0 Unrated.

CVE-2020-13474

Published Dec 28, 2020

In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13473

Published Dec 28, 2020

NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11561

Published Apr 7, 2020

In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add New Item" screen.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16330

Published Oct 17, 2019

In NCH Express Accounts Accounting v7.02, persistent cross site scripting (XSS) exists in Invoices/Sales Orders/Items/Customers/Quotes input field. An authenticated unprivileged u…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16282

Published Oct 14, 2019

In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5220

Published Sep 6, 2012

Untrusted search path vulnerability in MEO Encryption Software 2.02 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as d…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-34 of 34 CVEsPage 2 of 2