CVE-2023-25821
- EPSS 0.26%
- Veröffentlicht 25.02.2023 00:15:11
- Zuletzt bearbeitet 21.11.2024 07:50:16
Nextcloud is an Open Source private cloud software. Versions 24.0.4 and above, prior to 24.0.7, and 25.0.0 and above, prior to 25.0.1, contain Improper Access Control. Secure view for internal shares can be circumvented if reshare permissions are als...
CVE-2023-25579
- EPSS 0.07%
- Veröffentlicht 22.02.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:49:45
Nextcloud server is a self hosted home cloud product. In affected versions the `OC\Files\Node\Folder::getFullPath()` function was validating and normalizing the string in the wrong order. The function is used in the `newFile()` and `newFolder()` item...
CVE-2023-25162
- EPSS 0.13%
- Veröffentlicht 13.02.2023 21:15:15
- Zuletzt bearbeitet 21.11.2024 07:49:13
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior to 24.0.8 and 23.0.12 and Nextcloud Enterprise server prior to 24.0.8 and 23.0.12 are vulnerable to server-side request forgery (S...
CVE-2023-25161
- EPSS 0.08%
- Veröffentlicht 13.02.2023 21:15:14
- Zuletzt bearbeitet 21.11.2024 07:49:13
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 25.0.1 24.0.8, and 23.0.12 missing rate limiting on password reset functionality. This...
CVE-2023-25159
- EPSS 0.13%
- Veröffentlicht 13.02.2023 17:15:11
- Zuletzt bearbeitet 21.11.2024 07:49:13
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Office is a document collaboration app for the same platform. Nextcloud Server 24.0.x prior to 24.0.8 and 25.0.x prior to 25.0.1, Nextcloud...
CVE-2022-41968
- EPSS 0.09%
- Veröffentlicht 01.12.2022 21:15:19
- Zuletzt bearbeitet 21.11.2024 07:24:10
Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths are not validated before writing to a database. As a result, an attacker can send unnecessary amounts of data against the database. ...
CVE-2022-41969
- EPSS 0.06%
- Veröffentlicht 01.12.2022 21:15:19
- Zuletzt bearbeitet 21.11.2024 07:24:10
Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.11, 24.0.7, and 25.0.0, there is no password length limit when creating a user as an administrator. An administrator can cause a limited DoS attack against their own ser...
CVE-2022-41970
- EPSS 0.12%
- Veröffentlicht 01.12.2022 21:15:19
- Zuletzt bearbeitet 21.11.2024 07:24:10
Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through preview images. Images could be downloaded and previews of documents (first page) can be downloaded w...
CVE-2022-39346
- EPSS 0.23%
- Veröffentlicht 25.11.2022 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:18:05
Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a denial of service. It is recomm...
CVE-2022-39364
- EPSS 0.09%
- Veröffentlicht 27.10.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 07:18:07
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server prior to versions 23.0.9 and 24.0.5 and Nextcloud Enterprise Server prior to versions 22.2.10.5, 23.0.9, and 24.0.5 an attacker readi...