Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Nextcloud Server

Nextcloud Serverнабор клиент-серверных программ для создания и использования хранилища данных.

Релизный цикл, информация об уязвимостях

Продукт: Nextcloud Server
Вендор: nextcloud

График релизов

323334352025202620272028

Недавние уязвимости Nextcloud Server

Количество 456

github логотип

GHSA-mqg9-fwrm-2gxr

больше 4 лет назад

A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-63cq-5v5v-47mp

больше 4 лет назад

A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.

EPSS: Низкий
github логотип

GHSA-fjpp-r368-h9gx

больше 4 лет назад

A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received.

EPSS: Низкий
github логотип

GHSA-rw2m-m5fq-rcj4

больше 4 лет назад

Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is opened via the gallery app.

EPSS: Низкий
github логотип

GHSA-wgxr-73ph-q4xr

больше 4 лет назад

Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non-public event.

EPSS: Низкий
github логотип

GHSA-gwpm-3v8h-j4wh

больше 4 лет назад

An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.

EPSS: Низкий
github логотип

GHSA-pqcg-83hr-mr43

больше 4 лет назад

Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.

EPSS: Низкий
github логотип

GHSA-7vfj-8rgw-2c3q

больше 4 лет назад

Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.

EPSS: Низкий
github логотип

GHSA-mvc5-w9jr-jvqm

больше 4 лет назад

Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.

EPSS: Низкий
github логотип

GHSA-cg3p-cjqp-v7hh

больше 4 лет назад

Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-mqg9-fwrm-2gxr

A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-63cq-5v5v-47mp

A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-fjpp-r368-h9gx

A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-rw2m-m5fq-rcj4

Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is opened via the gallery app.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-wgxr-73ph-q4xr

Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non-public event.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-gwpm-3v8h-j4wh

An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-pqcg-83hr-mr43

Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-7vfj-8rgw-2c3q

Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-mvc5-w9jr-jvqm

Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-cg3p-cjqp-v7hh

Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться