Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 456

Количество 456

nvd логотип

CVE-2025-66512

8 месяцев назад

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to trick a user it viewing an uploaded SVG outside of the Nextcloud Servers web page.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2025-66512

8 месяцев назад

Nextcloud Server is a self hosted personal cloud system. In Nextcloud ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2025-66510

8 месяцев назад

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10, contacts search allowed to retrieve personal data of other users (emails, names, identifiers) without proper access control. This allows an authenticated user to retrieve information about accounts that are not related or added as contacts.

CVSS3: 4.5
EPSS: Низкий
debian логотип

CVE-2025-66510

8 месяцев назад

Nextcloud Server is a self hosted personal cloud system. In Nextcloud ...

CVSS3: 4.5
EPSS: Низкий
nvd логотип

CVE-2025-64011

8 месяцев назад

Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews of arbitrary files belonging to other users by manipulating the fileId parameter. This allows unauthorized disclosure of sensitive data, such as text files or images, without prior sharing permissions.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-64011

8 месяцев назад

Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Ref ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-59788

8 месяцев назад

Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367, but the root cause of this Nextcloud issue is that the product exposes executable example code on a same-origin basis.

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2025-59788

8 месяцев назад

Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewe ...

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2025-47794

около 1 года назад

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1, an attacker on a multi-user system may read temporary files from Nextcloud running with a different user account, or run a symlink attack. Nextcloud Server versions 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1 fix the issue. No known workarounds are available.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2025-47794

около 1 года назад

Nextcloud Server is a self hosted personal cloud system. In Nextcloud ...

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2025-47791

около 1 года назад

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server prior to 28.0.13, 29.0.10, and 30.0.3, a currently unused endpoint to verify a share recipient was not protected correctly, allowing to proxy requests to another server. The endpoint was removed in Nextcloud Server 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server 28.0.13, 29.0.10, and 30.0.3. No known workarounds are available.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-47791

около 1 года назад

Nextcloud Server is a self hosted personal cloud system. In Nextcloud ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-47790

около 1 года назад

Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextcloud Enterprise Server prior to 26.0.13.15, 27.1.11.15, 28.0.14.6, 29.0.15, 30.0.9, and 31.0.3 have a bug with session handling. The bug caused skipping the second factor confirmation after a successful login with the username and password when the server was configured with `remember_login_cookie_lifetime` set to `0`, once the session expired on the page to select the second factor and the page is reloaded. Nextcloud Server 29.0.15, 30.0.9, and 31.0.3 and Nextcloud Enterprise Server is upgraded to 26.0.13.15, 27.1.11.15, 28.0.14.6, 29.0.15, 30.0.9 and 31.0.3 contain a patch. As a workaround, set the `remember_login_cookie_lifetime` in config.php to a value other than `0`, e.g. `900`. Beware that this is only a workaround for new sessions created after the configuration change. System administration can delete affected sessions.

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2025-47790

около 1 года назад

Nextcloud Server is a self hosted personal cloud system. Nextcloud Ser ...

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2024-52525

больше 1 года назад

Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted before being saved in the session storage (Redis or disk), but it would allow a malicious process that gains access to the memory of the PHP process, to get access to the cleartext password of the user. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2.

CVSS3: 1.8
EPSS: Низкий
debian логотип

CVE-2024-52525

больше 1 года назад

Nextcloud Server is a self hosted personal cloud system. Under certain ...

CVSS3: 1.8
EPSS: Низкий
nvd логотип

CVE-2024-52523

больше 1 года назад

Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external storage with fixed credentials, the API returns them and adds them into the frontend again, allowing to read them in plain text when an attacker already has access to an active session of a user. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2 and Nextcloud Enterprise Server is upgraded to 25.0.13.14, 26.0.13.10, 27.1.11.10, 28.0.12, 29.0.9 or 30.0.2.

CVSS3: 4.6
EPSS: Низкий
debian логотип

CVE-2024-52523

больше 1 года назад

Nextcloud Server is a self hosted personal cloud system. After setting ...

CVSS3: 4.6
EPSS: Низкий
nvd логотип

CVE-2024-52521

больше 1 года назад

Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to check background jobs for their uniqueness. This increased the chances of a background job with arguments falsely being identified as already existing and not be queued for execution. By changing the Hash to SHA256 the probability was heavily decreased. It is recommended that the Nextcloud Server is upgraded to 28.0.10, 29.0.7 or 30.0.0.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2024-52521

больше 1 года назад

Nextcloud Server is a self hosted personal cloud system. MD5 hashes we ...

CVSS3: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-66512

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to trick a user it viewing an uploaded SVG outside of the Nextcloud Servers web page.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-66512

Nextcloud Server is a self hosted personal cloud system. In Nextcloud ...

CVSS3: 5.4
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-66510

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10, contacts search allowed to retrieve personal data of other users (emails, names, identifiers) without proper access control. This allows an authenticated user to retrieve information about accounts that are not related or added as contacts.

CVSS3: 4.5
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-66510

Nextcloud Server is a self hosted personal cloud system. In Nextcloud ...

CVSS3: 4.5
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-64011

Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews of arbitrary files belonging to other users by manipulating the fileId parameter. This allows unauthorized disclosure of sensitive data, such as text files or images, without prior sharing permissions.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-64011

Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Ref ...

CVSS3: 4.3
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-59788

Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367, but the root cause of this Nextcloud issue is that the product exposes executable example code on a same-origin basis.

CVSS3: 6.4
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-59788

Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewe ...

CVSS3: 6.4
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-47794

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1, an attacker on a multi-user system may read temporary files from Nextcloud running with a different user account, or run a symlink attack. Nextcloud Server versions 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1 fix the issue. No known workarounds are available.

CVSS3: 2.6
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-47794

Nextcloud Server is a self hosted personal cloud system. In Nextcloud ...

CVSS3: 2.6
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-47791

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server prior to 28.0.13, 29.0.10, and 30.0.3, a currently unused endpoint to verify a share recipient was not protected correctly, allowing to proxy requests to another server. The endpoint was removed in Nextcloud Server 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server 28.0.13, 29.0.10, and 30.0.3. No known workarounds are available.

CVSS3: 4.3
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-47791

Nextcloud Server is a self hosted personal cloud system. In Nextcloud ...

CVSS3: 4.3
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-47790

Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextcloud Enterprise Server prior to 26.0.13.15, 27.1.11.15, 28.0.14.6, 29.0.15, 30.0.9, and 31.0.3 have a bug with session handling. The bug caused skipping the second factor confirmation after a successful login with the username and password when the server was configured with `remember_login_cookie_lifetime` set to `0`, once the session expired on the page to select the second factor and the page is reloaded. Nextcloud Server 29.0.15, 30.0.9, and 31.0.3 and Nextcloud Enterprise Server is upgraded to 26.0.13.15, 27.1.11.15, 28.0.14.6, 29.0.15, 30.0.9 and 31.0.3 contain a patch. As a workaround, set the `remember_login_cookie_lifetime` in config.php to a value other than `0`, e.g. `900`. Beware that this is only a workaround for new sessions created after the configuration change. System administration can delete affected sessions.

CVSS3: 6.4
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-47790

Nextcloud Server is a self hosted personal cloud system. Nextcloud Ser ...

CVSS3: 6.4
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-52525

Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted before being saved in the session storage (Redis or disk), but it would allow a malicious process that gains access to the memory of the PHP process, to get access to the cleartext password of the user. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2.

CVSS3: 1.8
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-52525

Nextcloud Server is a self hosted personal cloud system. Under certain ...

CVSS3: 1.8
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-52523

Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external storage with fixed credentials, the API returns them and adds them into the frontend again, allowing to read them in plain text when an attacker already has access to an active session of a user. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2 and Nextcloud Enterprise Server is upgraded to 25.0.13.14, 26.0.13.10, 27.1.11.10, 28.0.12, 29.0.9 or 30.0.2.

CVSS3: 4.6
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-52523

Nextcloud Server is a self hosted personal cloud system. After setting ...

CVSS3: 4.6
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-52521

Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to check background jobs for their uniqueness. This increased the chances of a background job with arguments falsely being identified as already existing and not be queued for execution. By changing the Hash to SHA256 the probability was heavily decreased. It is recommended that the Nextcloud Server is upgraded to 28.0.10, 29.0.7 or 30.0.0.

CVSS3: 2.6
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-52521

Nextcloud Server is a self hosted personal cloud system. MD5 hashes we ...

CVSS3: 2.6
0%
Низкий
больше 1 года назад

Уязвимостей на страницу