CVE-2024-52516
- EPSS 0.05%
- Published 15.11.2024 17:15:21
- Last modified 06.01.2025 20:51:23
Nextcloud Server is a self hosted personal cloud system. When a server is configured to only allow sharing with users that are in ones own groups, after a user was removed from a group, previously shared items were not unshared. It is recommended tha...
CVE-2024-52517
- EPSS 0.14%
- Published 15.11.2024 17:15:21
- Last modified 06.01.2025 20:58:07
Nextcloud Server is a self hosted personal cloud system. After storing "Global credentials" on the server, the API returns them and adds them into the frontend again, allowing to read them in plain text when an attacker already has access to an activ...
CVE-2024-52518
- EPSS 0.06%
- Published 15.11.2024 17:15:21
- Last modified 23.01.2025 15:15:58
Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would be able to create, change or delete external storages without having to confirm the password. It is re...
CVE-2024-52519
- EPSS 0.16%
- Published 15.11.2024 17:15:21
- Last modified 23.01.2025 15:05:17
Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so that an attacker that got access to a backup of the database and the Nextcloud config file, would be able to decrypt them. It is r...
CVE-2024-52515
- EPSS 0.18%
- Published 15.11.2024 17:15:20
- Last modified 01.10.2025 18:34:21
Nextcloud Server is a self hosted personal cloud system. After an admin enables the default-disabled SVG preview provider, a malicious user could upload a manipulated SVG file referencing paths. If the file would exist the preview of the SVG would pr...
CVE-2024-37887
- EPSS 0.39%
- Published 14.06.2024 16:15:14
- Last modified 02.10.2025 01:47:30
Nextcloud Server is a self hosted personal cloud system. Private shared calendar events' recurrence exceptions can be read by sharees. It is recommended that the Nextcloud Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1 and that the Nextcloud Enter...
CVE-2024-37884
- EPSS 0.16%
- Published 14.06.2024 16:15:13
- Last modified 21.11.2024 09:24:28
Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versions of files they only got shared with read permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.12 or 27....
CVE-2024-37882
- EPSS 0.32%
- Published 14.06.2024 16:15:12
- Last modified 21.11.2024 09:24:27
Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.13 or 27.1.8 or 28.0.4 and that ...
CVE-2024-37315
- EPSS 0.39%
- Published 14.06.2024 16:15:11
- Last modified 21.11.2024 09:23:35
Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file is able to restore older versions of a document when the files_versions app is enabled. It is recommended that the Nextcloud Server is upgraded to 26...
CVE-2024-37313
- EPSS 0.18%
- Published 14.06.2024 15:15:51
- Last modified 26.09.2025 23:39:11
Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfully providing the user credentials. It is recommended that the Nextcloud Server is upgraded to 26.0.13,...