Nextcloud Server — набор клиент-серверных программ для создания и использования хранилища данных.
Релизный цикл, информация об уязвимостях
График релизов
Количество 456
CVE-2019-15619
Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.
CVE-2019-15618
Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a ...
CVE-2019-15618
Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.
CVE-2019-15617
A missing check in Nextcloud Server 17.0.0 allowed an attacker to set ...
CVE-2019-15617
A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login.
CVE-2019-15616
Dangling remote share attempts in Nextcloud 16 allow a DNS pollution w ...
CVE-2019-15616
Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.
CVE-2019-15613
A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend t ...
CVE-2019-15613
A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.
CVE-2019-15612
A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be c ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2019-15619 Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project. | CVSS3: 4.8 | 1% Низкий | больше 6 лет назад | |
CVE-2019-15618 Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a ... | CVSS3: 4.8 | 1% Низкий | больше 6 лет назад | |
CVE-2019-15618 Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location. | CVSS3: 4.8 | 1% Низкий | больше 6 лет назад | |
CVE-2019-15617 A missing check in Nextcloud Server 17.0.0 allowed an attacker to set ... | CVSS3: 5.4 | 1% Низкий | больше 6 лет назад | |
CVE-2019-15617 A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login. | CVSS3: 5.4 | 1% Низкий | больше 6 лет назад | |
CVE-2019-15616 Dangling remote share attempts in Nextcloud 16 allow a DNS pollution w ... | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-15616 Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long. | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2019-15613 A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend t ... | CVSS3: 8 | 1% Низкий | больше 6 лет назад | |
CVE-2019-15613 A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes. | CVSS3: 8 | 1% Низкий | больше 6 лет назад | |
CVE-2019-15612 A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be c ... | CVSS3: 5.9 | 0% Низкий | больше 6 лет назад |
Уязвимостей на страницу