Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Nextcloud Server

Nextcloud Serverнабор клиент-серверных программ для создания и использования хранилища данных.

Релизный цикл, информация об уязвимостях

Продукт: Nextcloud Server
Вендор: nextcloud

График релизов

3233342025202620272028

Недавние уязвимости Nextcloud Server

Количество 456

nvd логотип

CVE-2026-45281

около 2 месяцев назад

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, with the knowledge of other users’ principal URL an attacker could possibly send a request to gain full access to their calendar. Therefore, the attacker must be an authenticated user. This is because of improper authorization controls in the backend of the calendar. If the attacker had access to the calendar, they would be able to view and modify it. It is recommended that the Nextcloud Server is upgraded to 33.0.3 or 32.0.9. It is recommended that the Nextcloud Enterprise Server is upgraded to 33.0.3, 32.0.9, 31.0.14.5, 30.0.17.9, 29.0.16.16, 28.0.14.17, 27.1.11.26, 26.0.13.26, 25.0.13.29, 24.0.12.34, 23.0.12.35, 22.2.10.39, or 21.0.9.23

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-45279

около 2 месяцев назад

Nextcloud is an open source content collaboration platform. In Nextclo ...

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2026-45279

около 2 месяцев назад

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14, and 32.0.0 to before 32.0.4, if {lang} is used in the template directory config value, non-admin users can in some cases copy arbitrary files (depending on unix permissions) into their own Nextcloud directory via a path traversal. It is recommended that the Nextcloud Server is upgraded to 32.0.4, 31.0.14. It is recommended that the Nextcloud Enterprise Server is upgraded to 32.0.4, 31.0.14, 30.0.17.7, 29.0.17.12, 28.0.14.15

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-h6j9-6xjq-44c4

8 месяцев назад

Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews of arbitrary files belonging to other users by manipulating the fileId parameter. This allows unauthorized disclosure of sensitive data, such as text files or images, without prior sharing permissions.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-64011

8 месяцев назад

Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews of arbitrary files belonging to other users by manipulating the fileId parameter. This allows unauthorized disclosure of sensitive data, such as text files or images, without prior sharing permissions.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-64011

8 месяцев назад

Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Ref ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-66552

8 месяцев назад

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-66552

8 месяцев назад

Nextcloud Server is a self hosted personal cloud system. In Nextcloud ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-66547

8 месяцев назад

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This vulnerability is fixed in 31.0.1.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-66547

8 месяцев назад

Nextcloud Server is a self hosted personal cloud system. In Nextcloud ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2026-45281

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, with the knowledge of other users’ principal URL an attacker could possibly send a request to gain full access to their calendar. Therefore, the attacker must be an authenticated user. This is because of improper authorization controls in the backend of the calendar. If the attacker had access to the calendar, they would be able to view and modify it. It is recommended that the Nextcloud Server is upgraded to 33.0.3 or 32.0.9. It is recommended that the Nextcloud Enterprise Server is upgraded to 33.0.3, 32.0.9, 31.0.14.5, 30.0.17.9, 29.0.16.16, 28.0.14.17, 27.1.11.26, 26.0.13.26, 25.0.13.29, 24.0.12.34, 23.0.12.35, 22.2.10.39, or 21.0.9.23

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-45279

Nextcloud is an open source content collaboration platform. In Nextclo ...

CVSS3: 4.4
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-45279

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14, and 32.0.0 to before 32.0.4, if {lang} is used in the template directory config value, non-admin users can in some cases copy arbitrary files (depending on unix permissions) into their own Nextcloud directory via a path traversal. It is recommended that the Nextcloud Server is upgraded to 32.0.4, 31.0.14. It is recommended that the Nextcloud Enterprise Server is upgraded to 32.0.4, 31.0.14, 30.0.17.7, 29.0.17.12, 28.0.14.15

CVSS3: 4.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-h6j9-6xjq-44c4

Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews of arbitrary files belonging to other users by manipulating the fileId parameter. This allows unauthorized disclosure of sensitive data, such as text files or images, without prior sharing permissions.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-64011

Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews of arbitrary files belonging to other users by manipulating the fileId parameter. This allows unauthorized disclosure of sensitive data, such as text files or images, without prior sharing permissions.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-64011

Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Ref ...

CVSS3: 4.3
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-66552

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-66552

Nextcloud Server is a self hosted personal cloud system. In Nextcloud ...

CVSS3: 4.3
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-66547

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This vulnerability is fixed in 31.0.1.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-66547

Nextcloud Server is a self hosted personal cloud system. In Nextcloud ...

CVSS3: 4.3
0%
Низкий
8 месяцев назад

Уязвимостей на страницу


Поделиться