İçeriğe atla
Noroxi

nextcloud kayıtları

nextcloud üreticisine ait 372 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %0,3
Pre-auth RCE
3
Düzeltme kaydı olan
%22,3
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

372 kayıt
  • CVE-2022-24838
    49Planlayın

    Command Injection in Appointment Emails for Nextcloud Calendar

    KritikCVSS 9,8İstismar yokEPSS %33

    nextcloud · calendar11 Nis 2022

  • CVE-2021-32802
    40Planlayın

    Preview generation used third-party library not suited for user-generated content in Nextcloud server

    KritikCVSS 9,8İstismar yokEPSS %3

    nextcloud · nextcloud server7 Eyl 2021

  • CVE-2024-30247
    40Planlayın

    Command Injection as root in NextCloudPi web panel

    KritikCVSS 9,8İstismar yokEPSS %2

    nextcloud · nextcloudpi29 Mar 2024

  • CVE-2019-5454
    40Planlayın

    SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring

    KritikCVSS 9,8Kavram kanıtıEPSS %2

    nextcloud · nextcloud30 Tem 2019

  • CVE-2019-5476
    40Planlayın

    An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able t

    KritikCVSS 9,8İstismar yokEPSS %2

    nextcloud · lookup-server7 Ağu 2019

  • CVE-2021-32726
    40Planlayın

    Webauthn tokens not removed after user has been deleted

    KritikCVSS 9,8İstismar yokEPSS %2

    nextcloud · nextcloud server12 Tem 2021

  • CVE-2021-22915
    40Planlayın

    Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limit

    KritikCVSS 9,8İstismar yokEPSS %2

    nextcloud · nextcloud server11 Haz 2021

  • CVE-2020-8180
    40Planlayın

    A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by a

    KritikCVSS 9,9İstismar yokEPSS %2

    nextcloud · talk8 Haz 2020

  • CVE-2023-49792
    39İzleyin

    Bruteforce protection can be bypassed with misconfigured proxy

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    nextcloud · nextcloud server22 Ara 2023

  • CVE-2023-48307
    39İzleyin

    Nextcloud Mail app vulnerable to Server-Side Request Forgery

    KritikCVSS 9,8İstismar yokEPSS %1

    nextcloud · mail21 Kas 2023

  • CVE-2023-32074
    39İzleyin

    Nextcloud user_oidc app is missing brute force protection

    KritikCVSS 9,8İstismar yokEPSS %1

    nextcloud · user oidc25 May 2023

  • CVE-2023-48306
    39İzleyin

    Nextcloud Server DNS pin middleware can be tricked into DNS rebinding allowing SSRF

    KritikCVSS 9,8İstismar yokEPSS %1

    nextcloud · nextcloud server21 Kas 2023

  • CVE-2024-22212
    39İzleyin

    Nextcloud global site selector authentication bypass

    KritikCVSS 9,8İstismar yokEPSS %1

    nextcloud · global site selector18 Oca 2024

  • CVE-2022-31132
    39İzleyin

    Unauthenticated SSRF in 3rd party module "cerdic/csstidy"

    KritikCVSS 9,8İstismar yokEPSS %1

    nextcloud · mail4 Ağu 2022

  • CVE-2021-32654
    37İzleyin

    Attacker can obtain write access to any federated share/public link

    KritikCVSS 9,1İstismar yokEPSS %2

    nextcloud · nextcloud server1 Haz 2021

  • CVE-2021-22879
    36İzleyin

    Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious serve

    YüksekCVSS 8,8İstismar yokEPSS %5

    nextcloud · desktop14 Nis 2021

  • CVE-2023-26482
    36İzleyin

    Scope of workflow operations is not validated in nextcloud server

    YüksekCVSS 8,8SilahlaştırılmışEPSS %4

    nextcloud · nextcloud server30 Mar 2023

  • CVE-2023-31128
    36İzleyin

    NextCloud Cookbook's pull-checks.yml workflow is vulnerable to OS Command Injection

    YüksekCVSS 8,8İstismar yokEPSS %3

    nextcloud · cookbook26 May 2023

  • CVE-2019-12739
    36İzleyin

    lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacte

    YüksekCVSS 8,8İstismar yokEPSS %3

    nextcloud · extract5 Haz 2019

  • CVE-2021-32688
    36İzleyin

    Application specific tokens can change their own scope

    YüksekCVSS 8,8İstismar yokEPSS %2

    nextcloud · nextcloud server12 Tem 2021

  • CVE-2023-35172
    36İzleyin

    Nextcloud Server password reset endpoint is not brute force protected

    KritikCVSS 9,1İstismar yokEPSS %1

    nextcloud · nextcloud server23 Haz 2023

  • CVE-2024-46958
    36İzleyin

    In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or

    KritikCVSS 9,1İstismar yokEPSS %1

    nextcloud · desktop15 Eyl 2024

  • CVE-2020-8227
    35İzleyin

    Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files ou

    OrtaCVSS 6,8İstismar yokEPSS %26

    nextcloud · desktop21 Ağu 2020

  • CVE-2026-22683
    35İzleyin

    Windmill < 1.615.0 Operator Role Missing Authorization Checks RCE

    YüksekCVSS 8,7Kavram kanıtıEPSS %3

    windmill · windmill7 Nis 2026

  • CVE-2021-32656
    35İzleyin

    Trusted servers exchange can be triggered by attacker

    YüksekCVSS 8,6İstismar yokEPSS %2

    nextcloud · nextcloud server1 Haz 2021