Записи nextcloud
372 опубликованных записей вендора nextcloud.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 0,3 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 22,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-284 Improper Access Control52
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')34
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor27
- CWE-639 Authorization Bypass Through User-Controlled Key25
- CWE-287 Improper Authentication18
- CWE-307 Improper Restriction of Excessive Authentication Attempts14
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
372 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
49В плане | CVE-2022-24838Эксплойта нет | Command Injection in Appointment Emails for Nextcloud Calendarnextcloud · calendar · CWE-74 | Критическая9,8 | — | 33,0 % | 11 апр. 2022 г. |
40В плане | CVE-2021-32802Эксплойта нет | Preview generation used third-party library not suited for user-generated content in Nextcloud servernextcloud · nextcloud server · CWE-829 | Критическая9,8 | — | 2,6 % | 7 сент. 2021 г. |
40В плане | CVE-2024-30247Эксплойта нет | Command Injection as root in NextCloudPi web panelnextcloud · nextcloudpi · CWE-78 | Критическая9,8 | — | 2,1 % | 29 мар. 2024 г. |
40В плане | CVE-2019-5454Proof of concept | SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiringnextcloud · nextcloud · CWE-89 | Критическая9,8 | — | 2,0 % | 30 июл. 2019 г. |
40В плане | CVE-2019-5476Эксплойта нет | An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able tnextcloud · lookup-server · CWE-89 | Критическая9,8 | — | 1,8 % | 7 авг. 2019 г. |
40В плане | CVE-2021-32726Эксплойта нет | Webauthn tokens not removed after user has been deletednextcloud · nextcloud server · CWE-708 | Критическая9,8 | — | 1,8 % | 12 июл. 2021 г. |
40В плане | CVE-2021-22915Эксплойта нет | Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limitnextcloud · nextcloud server · CWE-307 | Критическая9,8 | — | 1,7 % | 11 июн. 2021 г. |
40В плане | CVE-2020-8180Эксплойта нет | A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by anextcloud · talk · CWE-94 | Критическая9,9 | — | 1,7 % | 8 июн. 2020 г. |
39Наблюдать | CVE-2023-49792Proof of concept | Bruteforce protection can be bypassed with misconfigured proxynextcloud · nextcloud server · CWE-307 | Критическая9,8 | — | 1,0 % | 22 дек. 2023 г. |
39Наблюдать | CVE-2023-48307Эксплойта нет | Nextcloud Mail app vulnerable to Server-Side Request Forgerynextcloud · mail · CWE-918 | Критическая9,8 | — | 0,9 % | 21 нояб. 2023 г. |
39Наблюдать | CVE-2023-32074Эксплойта нет | Nextcloud user_oidc app is missing brute force protectionnextcloud · user oidc · CWE-307 | Критическая9,8 | — | 0,9 % | 25 мая 2023 г. |
39Наблюдать | CVE-2023-48306Эксплойта нет | Nextcloud Server DNS pin middleware can be tricked into DNS rebinding allowing SSRFnextcloud · nextcloud server · CWE-918 | Критическая9,8 | — | 0,8 % | 21 нояб. 2023 г. |
39Наблюдать | CVE-2024-22212Эксплойта нет | Nextcloud global site selector authentication bypassnextcloud · global site selector · CWE-306 | Критическая9,8 | — | 0,8 % | 18 янв. 2024 г. |
39Наблюдать | CVE-2022-31132Эксплойта нет | Unauthenticated SSRF in 3rd party module "cerdic/csstidy"nextcloud · mail · CWE-918 | Критическая9,8 | — | 0,7 % | 4 авг. 2022 г. |
37Наблюдать | CVE-2021-32654Эксплойта нет | Attacker can obtain write access to any federated share/public linknextcloud · nextcloud server · CWE-639 | Критическая9,1 | — | 1,8 % | 1 июн. 2021 г. |
36Наблюдать | CVE-2021-22879Эксплойта нет | Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious servenextcloud · desktop · CWE-99 | Высокая8,8 | — | 4,7 % | 14 апр. 2021 г. |
36Наблюдать | CVE-2023-26482Готовый эксплойт | Scope of workflow operations is not validated in nextcloud servernextcloud · nextcloud server · CWE-78 | Высокая8,8 | — | 4,2 % | 30 мар. 2023 г. |
36Наблюдать | CVE-2023-31128Эксплойта нет | NextCloud Cookbook's pull-checks.yml workflow is vulnerable to OS Command Injectionnextcloud · cookbook · CWE-78 | Высокая8,8 | — | 3,3 % | 26 мая 2023 г. |
36Наблюдать | CVE-2019-12739Эксплойта нет | lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharactenextcloud · extract · CWE-78 | Высокая8,8 | — | 2,5 % | 5 июн. 2019 г. |
36Наблюдать | CVE-2021-32688Эксплойта нет | Application specific tokens can change their own scopenextcloud · nextcloud server · CWE-285 | Высокая8,8 | — | 2,3 % | 12 июл. 2021 г. |
36Наблюдать | CVE-2023-35172Эксплойта нет | Nextcloud Server password reset endpoint is not brute force protectednextcloud · nextcloud server · CWE-307 | Критическая9,1 | — | 0,9 % | 23 июн. 2023 г. |
36Наблюдать | CVE-2024-46958Эксплойта нет | In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or nextcloud · desktop | Критическая9,1 | — | 0,6 % | 15 сент. 2024 г. |
35Наблюдать | CVE-2020-8227Эксплойта нет | Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files ounextcloud · desktop · CWE-22 | Средняя6,8 | — | 25,8 % | 21 авг. 2020 г. |
35Наблюдать | CVE-2026-22683Proof of concept | Windmill < 1.615.0 Operator Role Missing Authorization Checks RCEwindmill · windmill · CWE-862 | Высокая8,7 | — | 2,6 % | 7 апр. 2026 г. |
35Наблюдать | CVE-2021-32656Эксплойта нет | Trusted servers exchange can be triggered by attackernextcloud · nextcloud server · CWE-284 | Высокая8,6 | — | 1,8 % | 1 июн. 2021 г. |
- CVE-2022-2483849В плане
Command Injection in Appointment Emails for Nextcloud Calendar
КритическаяCVSS 9,8Эксплойта нетEPSS 33 %nextcloud · calendar11 апр. 2022 г.
- CVE-2021-3280240В плане
Preview generation used third-party library not suited for user-generated content in Nextcloud server
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %nextcloud · nextcloud server7 сент. 2021 г.
- CVE-2024-3024740В плане
Command Injection as root in NextCloudPi web panel
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nextcloud · nextcloudpi29 мар. 2024 г.
- CVE-2019-545440В плане
SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring
КритическаяCVSS 9,8Proof of conceptEPSS 2 %nextcloud · nextcloud30 июл. 2019 г.
- CVE-2019-547640В плане
An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able t
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nextcloud · lookup-server7 авг. 2019 г.
- CVE-2021-3272640В плане
Webauthn tokens not removed after user has been deleted
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nextcloud · nextcloud server12 июл. 2021 г.
- CVE-2021-2291540В плане
Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limit
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nextcloud · nextcloud server11 июн. 2021 г.
- CVE-2020-818040В плане
A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by a
КритическаяCVSS 9,9Эксплойта нетEPSS 2 %nextcloud · talk8 июн. 2020 г.
- CVE-2023-4979239Наблюдать
Bruteforce protection can be bypassed with misconfigured proxy
КритическаяCVSS 9,8Proof of conceptEPSS 1 %nextcloud · nextcloud server22 дек. 2023 г.
- CVE-2023-4830739Наблюдать
Nextcloud Mail app vulnerable to Server-Side Request Forgery
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nextcloud · mail21 нояб. 2023 г.
- CVE-2023-3207439Наблюдать
Nextcloud user_oidc app is missing brute force protection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nextcloud · user oidc25 мая 2023 г.
- CVE-2023-4830639Наблюдать
Nextcloud Server DNS pin middleware can be tricked into DNS rebinding allowing SSRF
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nextcloud · nextcloud server21 нояб. 2023 г.
- CVE-2024-2221239Наблюдать
Nextcloud global site selector authentication bypass
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nextcloud · global site selector18 янв. 2024 г.
- CVE-2022-3113239Наблюдать
Unauthenticated SSRF in 3rd party module "cerdic/csstidy"
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nextcloud · mail4 авг. 2022 г.
- CVE-2021-3265437Наблюдать
Attacker can obtain write access to any federated share/public link
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %nextcloud · nextcloud server1 июн. 2021 г.
- CVE-2021-2287936Наблюдать
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious serve
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %nextcloud · desktop14 апр. 2021 г.
- CVE-2023-2648236Наблюдать
Scope of workflow operations is not validated in nextcloud server
ВысокаяCVSS 8,8Готовый эксплойтEPSS 4 %nextcloud · nextcloud server30 мар. 2023 г.
- CVE-2023-3112836Наблюдать
NextCloud Cookbook's pull-checks.yml workflow is vulnerable to OS Command Injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %nextcloud · cookbook26 мая 2023 г.
- CVE-2019-1273936Наблюдать
lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacte
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %nextcloud · extract5 июн. 2019 г.
- CVE-2021-3268836Наблюдать
Application specific tokens can change their own scope
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %nextcloud · nextcloud server12 июл. 2021 г.
- CVE-2023-3517236Наблюдать
Nextcloud Server password reset endpoint is not brute force protected
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %nextcloud · nextcloud server23 июн. 2023 г.
- CVE-2024-4695836Наблюдать
In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %nextcloud · desktop15 сент. 2024 г.
- CVE-2020-822735Наблюдать
Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files ou
СредняяCVSS 6,8Эксплойта нетEPSS 26 %nextcloud · desktop21 авг. 2020 г.
- CVE-2026-2268335Наблюдать
Windmill < 1.615.0 Operator Role Missing Authorization Checks RCE
ВысокаяCVSS 8,7Proof of conceptEPSS 3 %windmill · windmill7 апр. 2026 г.
- CVE-2021-3265635Наблюдать
Trusted servers exchange can be triggered by attacker
ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %nextcloud · nextcloud server1 июн. 2021 г.