Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Nextcloud Server

Nextcloud Serverнабор клиент-серверных программ для создания и использования хранилища данных.

Релизный цикл, информация об уязвимостях

Продукт: Nextcloud Server
Вендор: nextcloud

График релизов

30312024202520262027

Недавние уязвимости Nextcloud Server

Количество 413

nvd логотип

CVE-2025-47793

4 месяца назад

Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured folders shared by everyone in a group or team. In Nextcloud Server prior to 30.0.2, 29.0.9, and 28.0.1, Nextcloud Enterprise Server prior to 30.0.2 and 29.0.9, and Nextcloud Groupfolders app prior to 18.0.3, 17.0.5, and 16.0.11, the absence of quota checking on attachments allowed logged-in users to upload files exceeding the group folder quota. Nextcloud Server versions 30.0.2 and 29.0.9, Nextcloud Enterprise Server versions 30.0.2, 29.0.9, or 28.0.12, and Nextcloud Groupfolders app 18.0.3, 17.0.5, and 16.0.11 fix the issue. No known workarounds are available.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-47793

4 месяца назад

Nextcloud Server is a self hosted personal cloud system, and the Nextc ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-52525

10 месяцев назад

Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted before being saved in the session storage (Redis or disk), but it would allow a malicious process that gains access to the memory of the PHP process, to get access to the cleartext password of the user. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2.

CVSS3: 1.8
EPSS: Низкий
debian логотип

CVE-2024-52525

10 месяцев назад

Nextcloud Server is a self hosted personal cloud system. Under certain ...

CVSS3: 1.8
EPSS: Низкий
nvd логотип

CVE-2024-52521

10 месяцев назад

Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to check background jobs for their uniqueness. This increased the chances of a background job with arguments falsely being identified as already existing and not be queued for execution. By changing the Hash to SHA256 the probability was heavily decreased. It is recommended that the Nextcloud Server is upgraded to 28.0.10, 29.0.7 or 30.0.0.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2024-52521

10 месяцев назад

Nextcloud Server is a self hosted personal cloud system. MD5 hashes we ...

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2024-52520

10 месяцев назад

Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger websites than intended, to find open-graph data. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.

CVSS3: 5.7
EPSS: Низкий
debian логотип

CVE-2024-52520

10 месяцев назад

Nextcloud Server is a self hosted personal cloud system. Due to a pre- ...

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2024-52519

10 месяцев назад

Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so that an attacker that got access to a backup of the database and the Nextcloud config file, would be able to decrypt them. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2024-52519

10 месяцев назад

Nextcloud Server is a self hosted personal cloud system. The OAuth2 cl ...

CVSS3: 2.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2025-47793

Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured folders shared by everyone in a group or team. In Nextcloud Server prior to 30.0.2, 29.0.9, and 28.0.1, Nextcloud Enterprise Server prior to 30.0.2 and 29.0.9, and Nextcloud Groupfolders app prior to 18.0.3, 17.0.5, and 16.0.11, the absence of quota checking on attachments allowed logged-in users to upload files exceeding the group folder quota. Nextcloud Server versions 30.0.2 and 29.0.9, Nextcloud Enterprise Server versions 30.0.2, 29.0.9, or 28.0.12, and Nextcloud Groupfolders app 18.0.3, 17.0.5, and 16.0.11 fix the issue. No known workarounds are available.

CVSS3: 4.3
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-47793

Nextcloud Server is a self hosted personal cloud system, and the Nextc ...

CVSS3: 4.3
0%
Низкий
4 месяца назад
nvd логотип
CVE-2024-52525

Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted before being saved in the session storage (Redis or disk), but it would allow a malicious process that gains access to the memory of the PHP process, to get access to the cleartext password of the user. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2.

CVSS3: 1.8
0%
Низкий
10 месяцев назад
debian логотип
CVE-2024-52525

Nextcloud Server is a self hosted personal cloud system. Under certain ...

CVSS3: 1.8
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-52521

Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to check background jobs for their uniqueness. This increased the chances of a background job with arguments falsely being identified as already existing and not be queued for execution. By changing the Hash to SHA256 the probability was heavily decreased. It is recommended that the Nextcloud Server is upgraded to 28.0.10, 29.0.7 or 30.0.0.

CVSS3: 2.6
0%
Низкий
10 месяцев назад
debian логотип
CVE-2024-52521

Nextcloud Server is a self hosted personal cloud system. MD5 hashes we ...

CVSS3: 2.6
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-52520

Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger websites than intended, to find open-graph data. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.

CVSS3: 5.7
0%
Низкий
10 месяцев назад
debian логотип
CVE-2024-52520

Nextcloud Server is a self hosted personal cloud system. Due to a pre- ...

CVSS3: 5.7
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-52519

Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so that an attacker that got access to a backup of the database and the Nextcloud config file, would be able to decrypt them. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.

CVSS3: 2.7
0%
Низкий
10 месяцев назад
debian логотип
CVE-2024-52519

Nextcloud Server is a self hosted personal cloud system. The OAuth2 cl ...

CVSS3: 2.7
0%
Низкий
10 месяцев назад

Уязвимостей на страницу


Поделиться