Nextcloud

Nextcloud Server

175 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.28%
  • Published 27.04.2022 15:15:09
  • Last modified 21.11.2024 06:51:19

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 21.0.8, 22.2.4, and 23.0.1, it is possible to trick administrators into enabling "recommended" apps for the Nextcloud server that they ...

  • EPSS 0.27%
  • Published 10.03.2022 21:15:13
  • Last modified 21.11.2024 06:25:50

Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application, which is by default shipped with Nextcloud Server, an attacker is able to access the folder names o...

Exploit
  • EPSS 0.96%
  • Published 09.03.2022 22:15:09
  • Last modified 21.11.2024 06:50:59

Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uploading specially crafted files which will cause the server to allocate too much memory / CPU. It is re...

  • EPSS 0.28%
  • Published 08.03.2022 19:15:07
  • Last modified 21.11.2024 06:25:51

Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition, it allows setting "advanced permissions" on subfolders, for exa...

  • EPSS 0.44%
  • Published 08.03.2022 18:15:07
  • Last modified 21.11.2024 06:25:51

Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status API did not consider the user enumeration settings by the administrator. This allowed a user to enumerate other users on the insta...

  • EPSS 0.54%
  • Published 25.10.2021 22:15:07
  • Last modified 21.11.2024 06:25:40

Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, Nextcloud Server did not implement a database backend for rate-limiting purposes. Any component of Nextcloud using rate-limits (as as `Anon...

  • EPSS 0.33%
  • Published 07.09.2021 22:15:08
  • Last modified 21.11.2024 06:07:46

Nextcloud server is an open source, self hosted personal cloud. In affected versions an attacker is able to bypass Two Factor Authentication in Nextcloud. Thus knowledge of a password, or access to a WebAuthN trusted device of a user was sufficient t...

  • EPSS 0.06%
  • Published 07.09.2021 22:15:08
  • Last modified 21.11.2024 06:07:46

Nextcloud server is an open source, self hosted personal cloud. In affected versions logging of exceptions may have resulted in logging potentially sensitive key material for the Nextcloud Encryption-at-Rest functionality. It is recommended that the ...

  • EPSS 2.25%
  • Published 07.09.2021 22:15:08
  • Last modified 21.11.2024 06:07:46

Nextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user provided file content. For some image types, the Nextcloud server was invoking a third-party library that wasn't suited for untrusted...

  • EPSS 0.38%
  • Published 07.09.2021 21:15:08
  • Last modified 21.11.2024 06:07:41

Nextcloud Text is an open source plaintext editing application which ships with the nextcloud server. In affected versions the Nextcloud Text application returned different error messages depending on whether a folder existed in a public link share. ...