目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

Nextcloud 厂商漏洞列表 / CVE 中文分析 261

Nextcloud 厂商相关 261 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

Nextcloud 是一款开源文件同步与共享平台,旨在提供私有云存储解决方案,支持多端数据同步及协作办公。其历史漏洞多集中于远程代码执行、跨站脚本及权限绕过,部分源于集成组件缺陷。项目采用模块化架构,定期发布安全更新以修复已知风险。鉴于已收录 261 条 CVE,用户需保持版本更新,并严格配置访问控制策略,以防范潜在的数据泄露与未授权访问威胁。

CVE IDタイトルCVSS深刻度公開日
CVE-2023-39952 Advanced permissions not respected when copying entire group folders — security-advisoriesCWE-284 6.5 Medium2023-08-10
CVE-2023-35928 Nextcloud user scoped external storage can be used to gather credentials of other users — security-advisoriesCWE-274 8.5 High2023-06-23
CVE-2023-35927 Nextcloud system addressbooks can be modified by malicious trusted server — security-advisoriesCWE-284 7.6 High2023-06-23
CVE-2023-35173 End-to-End encrypted file-drops can be made inaccessible — security-advisoriesCWE-284 5.7 Medium2023-06-23
CVE-2023-35172 Nextcloud Server password reset endpoint is not brute force protected — security-advisoriesCWE-307 8.7 High2023-06-23
CVE-2023-35171 Nextcloud Server vulnerable to open redirect on "Unsupported browser" warning — security-advisoriesCWE-601 4.1 Medium2023-06-23
CVE-2023-32320 Nextcloud Server's brute force protection allows someone to send more requests than intended — security-advisoriesCWE-307 8.7 High2023-06-22
CVE-2023-33183 Error in calendar when booking an appointment reveals the full path of the website — security-advisoriesCWE-285 2.6 Low2023-05-30
CVE-2023-33182 Nextcloud Contacts photos only sanitized if mime type is all lower case — security-advisoriesCWE-20--2023-05-30
CVE-2023-33184 Blind SSRF in the Nextcloud Mail app on avatar endpoint — security-advisoriesCWE-918 3.5 Low2023-05-27
CVE-2023-32319 Basic auth header on WebDAV requests is not brute-force protected in Nextcloud — security-advisoriesCWE-307 8.1 High2023-05-26
CVE-2023-31128 NextCloud Cookbook's pull-checks.yml workflow is vulnerable to OS Command Injection — cookbookCWE-78 8.1 High2023-05-26
CVE-2023-32318 User session not correctly destroyed on logout — security-advisoriesCWE-613 7.2 High2023-05-26
CVE-2023-32074 Nextcloud user_oidc app is missing brute force protection — security-advisoriesCWE-307 8.0 High2023-05-25
CVE-2023-28847 Nextcloud Server missing brute force protection for passwords of password protected share links — security-advisoriesCWE-307 3.1 Low2023-04-25
CVE-2023-30540 Chat poll data can still be queried from API after purging history in Nextcloud talk — security-advisoriesCWE-200 3.5 Low2023-04-17
CVE-2023-30539 Users can set up workflows using restricted and invisible system tags in Nextcloud — security-advisoriesCWE-284 6.5 Medium2023-04-17
CVE-2023-29000 Nextcloud Desktop client does not verify received singed certificate in end-to-end encryption — security-advisoriesCWE-295 5.4 Medium2023-04-04
CVE-2023-28999 Nextcloud: Lack of authenticity of metadata keys allows a malicious server to gain access to E2EE folders — security-advisoriesCWE-325 6.9 Medium2023-04-04
CVE-2023-28998 Nextcloud Desktop client misbehaves with E2EE when the server returns empty list of metadata keys — security-advisoriesCWE-325 6.7 Medium2023-04-04
CVE-2023-28997 Nextcloud Desktop: Initialization vector reuse in E2EE allows malicious server admin to break, manipulate, access files — security-advisoriesCWE-323 6.7 Medium2023-04-04
CVE-2023-28848 CSRF protection on user_oidc login returned the expected token in case of an error — security-advisoriesCWE-352 4.8 Medium2023-04-04
CVE-2023-28834 Full path of data directory exposed to Nextcloud server users — security-advisoriesCWE-212 3.5 Low2023-04-03
CVE-2023-28845 Chat room membership disclosed via autocompletion in Nextcloud talk — security-advisoriesCWE-284 3.5 Low2023-03-31
CVE-2023-28844 User without download rights can download older version of that file in nextcloud server — security-advisoriesCWE-284 5.7 Medium2023-03-31
CVE-2023-28645 Secure view can be bypassed by using internal API endpoint in Nextcloud richdocuments — security-advisoriesCWE-284 5.7 Medium2023-03-31
CVE-2023-28835 Insecure randomness for default password in nextcloud — security-advisoriesCWE-338 3.5 Low2023-03-30
CVE-2023-28833 Unrestricted filenames for logo or favicon as admin in the theming settings in nextcloud server — security-advisoriesCWE-22 2.4 Low2023-03-30
CVE-2023-28644 Reference fetch can saturate the server bandwidth for 10 seconds in nextcloud server — security-advisoriesCWE-400 5.7 Medium2023-03-30
CVE-2023-28643 Potential share collision for recipients when caching is enabled in nextcloud server — security-advisoriesCWE-706 5.5 Medium2023-03-30

本页汇总了 Nextcloud 厂商截至目前公开的全部 261 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。