nextcloud kayıtları
nextcloud üreticisine ait 372 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %0,3
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %22,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-284 Improper Access Control52
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')34
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor27
- CWE-639 Authorization Bypass Through User-Controlled Key25
- CWE-287 Improper Authentication18
- CWE-307 Improper Restriction of Excessive Authentication Attempts14
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
372 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
49Planlayın | CVE-2022-24838İstismar yok | Command Injection in Appointment Emails for Nextcloud Calendarnextcloud · calendar · CWE-74 | Kritik9,8 | — | %33,0 | 11 Nis 2022 |
40Planlayın | CVE-2021-32802İstismar yok | Preview generation used third-party library not suited for user-generated content in Nextcloud servernextcloud · nextcloud server · CWE-829 | Kritik9,8 | — | %2,6 | 7 Eyl 2021 |
40Planlayın | CVE-2024-30247İstismar yok | Command Injection as root in NextCloudPi web panelnextcloud · nextcloudpi · CWE-78 | Kritik9,8 | — | %2,1 | 29 Mar 2024 |
40Planlayın | CVE-2019-5454Kavram kanıtı | SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiringnextcloud · nextcloud · CWE-89 | Kritik9,8 | — | %2,0 | 30 Tem 2019 |
40Planlayın | CVE-2019-5476İstismar yok | An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able tnextcloud · lookup-server · CWE-89 | Kritik9,8 | — | %1,8 | 7 Ağu 2019 |
40Planlayın | CVE-2021-32726İstismar yok | Webauthn tokens not removed after user has been deletednextcloud · nextcloud server · CWE-708 | Kritik9,8 | — | %1,8 | 12 Tem 2021 |
40Planlayın | CVE-2021-22915İstismar yok | Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limitnextcloud · nextcloud server · CWE-307 | Kritik9,8 | — | %1,7 | 11 Haz 2021 |
40Planlayın | CVE-2020-8180İstismar yok | A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by anextcloud · talk · CWE-94 | Kritik9,9 | — | %1,7 | 8 Haz 2020 |
39İzleyin | CVE-2023-49792Kavram kanıtı | Bruteforce protection can be bypassed with misconfigured proxynextcloud · nextcloud server · CWE-307 | Kritik9,8 | — | %1,0 | 22 Ara 2023 |
39İzleyin | CVE-2023-48307İstismar yok | Nextcloud Mail app vulnerable to Server-Side Request Forgerynextcloud · mail · CWE-918 | Kritik9,8 | — | %0,9 | 21 Kas 2023 |
39İzleyin | CVE-2023-32074İstismar yok | Nextcloud user_oidc app is missing brute force protectionnextcloud · user oidc · CWE-307 | Kritik9,8 | — | %0,9 | 25 May 2023 |
39İzleyin | CVE-2023-48306İstismar yok | Nextcloud Server DNS pin middleware can be tricked into DNS rebinding allowing SSRFnextcloud · nextcloud server · CWE-918 | Kritik9,8 | — | %0,8 | 21 Kas 2023 |
39İzleyin | CVE-2024-22212İstismar yok | Nextcloud global site selector authentication bypassnextcloud · global site selector · CWE-306 | Kritik9,8 | — | %0,8 | 18 Oca 2024 |
39İzleyin | CVE-2022-31132İstismar yok | Unauthenticated SSRF in 3rd party module "cerdic/csstidy"nextcloud · mail · CWE-918 | Kritik9,8 | — | %0,7 | 4 Ağu 2022 |
37İzleyin | CVE-2021-32654İstismar yok | Attacker can obtain write access to any federated share/public linknextcloud · nextcloud server · CWE-639 | Kritik9,1 | — | %1,8 | 1 Haz 2021 |
36İzleyin | CVE-2021-22879İstismar yok | Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious servenextcloud · desktop · CWE-99 | Yüksek8,8 | — | %4,7 | 14 Nis 2021 |
36İzleyin | CVE-2023-26482Silahlaştırılmış | Scope of workflow operations is not validated in nextcloud servernextcloud · nextcloud server · CWE-78 | Yüksek8,8 | — | %4,2 | 30 Mar 2023 |
36İzleyin | CVE-2023-31128İstismar yok | NextCloud Cookbook's pull-checks.yml workflow is vulnerable to OS Command Injectionnextcloud · cookbook · CWE-78 | Yüksek8,8 | — | %3,3 | 26 May 2023 |
36İzleyin | CVE-2019-12739İstismar yok | lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharactenextcloud · extract · CWE-78 | Yüksek8,8 | — | %2,5 | 5 Haz 2019 |
36İzleyin | CVE-2021-32688İstismar yok | Application specific tokens can change their own scopenextcloud · nextcloud server · CWE-285 | Yüksek8,8 | — | %2,3 | 12 Tem 2021 |
36İzleyin | CVE-2023-35172İstismar yok | Nextcloud Server password reset endpoint is not brute force protectednextcloud · nextcloud server · CWE-307 | Kritik9,1 | — | %0,9 | 23 Haz 2023 |
36İzleyin | CVE-2024-46958İstismar yok | In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or nextcloud · desktop | Kritik9,1 | — | %0,6 | 15 Eyl 2024 |
35İzleyin | CVE-2020-8227İstismar yok | Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files ounextcloud · desktop · CWE-22 | Orta6,8 | — | %25,8 | 21 Ağu 2020 |
35İzleyin | CVE-2026-22683Kavram kanıtı | Windmill < 1.615.0 Operator Role Missing Authorization Checks RCEwindmill · windmill · CWE-862 | Yüksek8,7 | — | %2,6 | 7 Nis 2026 |
35İzleyin | CVE-2021-32656İstismar yok | Trusted servers exchange can be triggered by attackernextcloud · nextcloud server · CWE-284 | Yüksek8,6 | — | %1,8 | 1 Haz 2021 |
- CVE-2022-2483849Planlayın
Command Injection in Appointment Emails for Nextcloud Calendar
KritikCVSS 9,8İstismar yokEPSS %33nextcloud · calendar11 Nis 2022
- CVE-2021-3280240Planlayın
Preview generation used third-party library not suited for user-generated content in Nextcloud server
KritikCVSS 9,8İstismar yokEPSS %3nextcloud · nextcloud server7 Eyl 2021
- CVE-2024-3024740Planlayın
Command Injection as root in NextCloudPi web panel
KritikCVSS 9,8İstismar yokEPSS %2nextcloud · nextcloudpi29 Mar 2024
- CVE-2019-545440Planlayın
SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring
KritikCVSS 9,8Kavram kanıtıEPSS %2nextcloud · nextcloud30 Tem 2019
- CVE-2019-547640Planlayın
An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able t
KritikCVSS 9,8İstismar yokEPSS %2nextcloud · lookup-server7 Ağu 2019
- CVE-2021-3272640Planlayın
Webauthn tokens not removed after user has been deleted
KritikCVSS 9,8İstismar yokEPSS %2nextcloud · nextcloud server12 Tem 2021
- CVE-2021-2291540Planlayın
Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limit
KritikCVSS 9,8İstismar yokEPSS %2nextcloud · nextcloud server11 Haz 2021
- CVE-2020-818040Planlayın
A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by a
KritikCVSS 9,9İstismar yokEPSS %2nextcloud · talk8 Haz 2020
- CVE-2023-4979239İzleyin
Bruteforce protection can be bypassed with misconfigured proxy
KritikCVSS 9,8Kavram kanıtıEPSS %1nextcloud · nextcloud server22 Ara 2023
- CVE-2023-4830739İzleyin
Nextcloud Mail app vulnerable to Server-Side Request Forgery
KritikCVSS 9,8İstismar yokEPSS %1nextcloud · mail21 Kas 2023
- CVE-2023-3207439İzleyin
Nextcloud user_oidc app is missing brute force protection
KritikCVSS 9,8İstismar yokEPSS %1nextcloud · user oidc25 May 2023
- CVE-2023-4830639İzleyin
Nextcloud Server DNS pin middleware can be tricked into DNS rebinding allowing SSRF
KritikCVSS 9,8İstismar yokEPSS %1nextcloud · nextcloud server21 Kas 2023
- CVE-2024-2221239İzleyin
Nextcloud global site selector authentication bypass
KritikCVSS 9,8İstismar yokEPSS %1nextcloud · global site selector18 Oca 2024
- CVE-2022-3113239İzleyin
Unauthenticated SSRF in 3rd party module "cerdic/csstidy"
KritikCVSS 9,8İstismar yokEPSS %1nextcloud · mail4 Ağu 2022
- CVE-2021-3265437İzleyin
Attacker can obtain write access to any federated share/public link
KritikCVSS 9,1İstismar yokEPSS %2nextcloud · nextcloud server1 Haz 2021
- CVE-2021-2287936İzleyin
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious serve
YüksekCVSS 8,8İstismar yokEPSS %5nextcloud · desktop14 Nis 2021
- CVE-2023-2648236İzleyin
Scope of workflow operations is not validated in nextcloud server
YüksekCVSS 8,8SilahlaştırılmışEPSS %4nextcloud · nextcloud server30 Mar 2023
- CVE-2023-3112836İzleyin
NextCloud Cookbook's pull-checks.yml workflow is vulnerable to OS Command Injection
YüksekCVSS 8,8İstismar yokEPSS %3nextcloud · cookbook26 May 2023
- CVE-2019-1273936İzleyin
lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacte
YüksekCVSS 8,8İstismar yokEPSS %3nextcloud · extract5 Haz 2019
- CVE-2021-3268836İzleyin
Application specific tokens can change their own scope
YüksekCVSS 8,8İstismar yokEPSS %2nextcloud · nextcloud server12 Tem 2021
- CVE-2023-3517236İzleyin
Nextcloud Server password reset endpoint is not brute force protected
KritikCVSS 9,1İstismar yokEPSS %1nextcloud · nextcloud server23 Haz 2023
- CVE-2024-4695836İzleyin
In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or
KritikCVSS 9,1İstismar yokEPSS %1nextcloud · desktop15 Eyl 2024
- CVE-2020-822735İzleyin
Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files ou
OrtaCVSS 6,8İstismar yokEPSS %26nextcloud · desktop21 Ağu 2020
- CVE-2026-2268335İzleyin
Windmill < 1.615.0 Operator Role Missing Authorization Checks RCE
YüksekCVSS 8,7Kavram kanıtıEPSS %3windmill · windmill7 Nis 2026
- CVE-2021-3265635İzleyin
Trusted servers exchange can be triggered by attacker
YüksekCVSS 8,6İstismar yokEPSS %2nextcloud · nextcloud server1 Haz 2021