CVE-2023-25817
- EPSS 0.1%
- Veröffentlicht 27.03.2023 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:50:15
Nextcloud server is an open source, personal cloud implementation. In versions from 24.0.0 and before 24.0.9 a user could escalate their permissions to delete files they were not supposed to deletable but only viewed or downloaded. This issue has bee...
CVE-2023-25818
- EPSS 0.31%
- Veröffentlicht 27.03.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 07:50:15
Nextcloud server is an open source, personal cloud implementation. In affected versions a malicious user could try to reset the password of another user and then brute force the 62^21 combinations for the password reset token. As of commit `704eb3aa`...
CVE-2023-25820
- EPSS 0.13%
- Veröffentlicht 22.03.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:50:15
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Enterprise Server is the enterprise version of the file server software. In Nextcloud Server versions 25.0.x prior to 25.0.5 and versions 2...
CVE-2023-25816
- EPSS 0.17%
- Veröffentlicht 25.02.2023 00:15:11
- Zuletzt bearbeitet 21.11.2024 07:50:15
Nextcloud is an Open Source private cloud software. Versions 25.0.0 and above, prior to 25.0.3, are subject to Uncontrolled Resource Consumption. A user can configure a very long password, consuming more resources on password validation than desired....
CVE-2023-25821
- EPSS 0.32%
- Veröffentlicht 25.02.2023 00:15:11
- Zuletzt bearbeitet 21.11.2024 07:50:16
Nextcloud is an Open Source private cloud software. Versions 24.0.4 and above, prior to 24.0.7, and 25.0.0 and above, prior to 25.0.1, contain Improper Access Control. Secure view for internal shares can be circumvented if reshare permissions are als...
CVE-2023-25579
- EPSS 0.09%
- Veröffentlicht 22.02.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:49:45
Nextcloud server is a self hosted home cloud product. In affected versions the `OC\Files\Node\Folder::getFullPath()` function was validating and normalizing the string in the wrong order. The function is used in the `newFile()` and `newFolder()` item...
CVE-2023-25162
- EPSS 0.15%
- Veröffentlicht 13.02.2023 21:15:15
- Zuletzt bearbeitet 21.11.2024 07:49:13
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior to 24.0.8 and 23.0.12 and Nextcloud Enterprise server prior to 24.0.8 and 23.0.12 are vulnerable to server-side request forgery (S...
CVE-2023-25161
- EPSS 0.11%
- Veröffentlicht 13.02.2023 21:15:14
- Zuletzt bearbeitet 21.11.2024 07:49:13
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 25.0.1 24.0.8, and 23.0.12 missing rate limiting on password reset functionality. This...
CVE-2023-25159
- EPSS 0.18%
- Veröffentlicht 13.02.2023 17:15:11
- Zuletzt bearbeitet 21.11.2024 07:49:13
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Office is a document collaboration app for the same platform. Nextcloud Server 24.0.x prior to 24.0.8 and 25.0.x prior to 25.0.1, Nextcloud...
CVE-2022-41968
- EPSS 0.34%
- Veröffentlicht 01.12.2022 21:15:19
- Zuletzt bearbeitet 21.11.2024 07:24:10
Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths are not validated before writing to a database. As a result, an attacker can send unnecessary amounts of data against the database. ...