8.9

CVSS4.0

CVE-2025-66562 - TUUI vulnerable to Remote Code Execution (RCE) via XSS in Markdown ECharts Rendering

TUUI is a desktop MCP client designed as a tool unitary utility integration. Prior to 1.3.4, a critical Remote Code Execution (RCE) vulnerability exists in Tuui due to an unsafe Cross-Site Scripting (XSS) flaw in the Markdown rendering component. Tuui allows the execution of arbitrary JavaScript wi…

📅 Published: Dec. 5, 2025, 6:03 p.m. 🔄 Last Modified: March 17, 2026, 8:24 p.m.

3.1

CVSS3.1

CVE-2025-66558 - Nextcloud Twofactor WebAuthn app was updated based on public key

Nextcloud Twofactor WebAuthn is the WebAuthn Two-Factor Provider for Nextcloud. Prior to 1.4.2 and 2.4.1, a missing ownership check allowed an attack to take-away a 2FA webauthn device when correctly guessing a 80-128 character long random string of letters, numbers and symbols. The victim would th…

📅 Published: Dec. 5, 2025, 6 p.m. 🔄 Last Modified: Dec. 9, 2025, 4:44 p.m.

3.5

CVSS3.1

CVE-2025-66556 - Nextcloud talk allows participants to blindly delete poll drafts of other users by ID

Nextcloud talk is a video & audio conferencing app for Nextcloud. Prior to 20.1.8 and 21.1.2, a participant with chat permissions was able to delete poll drafts of other participants within the conversation based on their numeric ID. This vulnerability is fixed in 20.1.8 and 21.1.2.

📅 Published: Dec. 5, 2025, 5:56 p.m. 🔄 Last Modified: Dec. 9, 2025, 4:52 p.m.

3.5

CVSS3.1

CVE-2025-66554 - Nextcloud Contacts vulnerable to Stored XSS in contacts app via organisation and title field

Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. Prior to 5.5.4, 6.0.6, and 7.2.5, a malicious user was able to modify their organisation and title field to load additional CSS files. Javascript and other options were correctly blocked by…

📅 Published: Dec. 5, 2025, 5:50 p.m. 🔄 Last Modified: Dec. 9, 2025, 5:01 p.m.

2.4

CVSS3.1

CVE-2025-66549 - Nextcloud Desktop discloses information when attempting to lock a file inside a end-to-end encrypte…

Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This vulnerability is fix…

📅 Published: Dec. 5, 2025, 5:47 p.m. 🔄 Last Modified: Dec. 9, 2025, 6:58 p.m.

3.5

CVSS3.1

CVE-2025-66545 - Nextcloud Groupfolders users with read-only permissions for team folder can restore deleted files f…

Nextcloud Groupfolders provides admin-configured folders shared by everyone in a group or team. Prior to 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2, a user with read-only permission can restore a file from the trash bin. This vulnerability is fixed in 14.0.11, 15.3.12, 16.0.15, …

📅 Published: Dec. 5, 2025, 5:44 p.m. 🔄 Last Modified: Dec. 9, 2025, 7:10 p.m.

2.7

CVSS3.1

CVE-2025-66515 - Nextcloud Approval app allows users to request approval for other users file

The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id. This vulnerability …

📅 Published: Dec. 5, 2025, 5:37 p.m. 🔄 Last Modified: Dec. 9, 2025, 5:22 p.m.

8.7

CVSS4.0

CVE-2020-36882 - Flexsense DiskBoss Application Crash Denial of Service

Flexsense DiskBoss 7.7.14 allows unauthenticated attackers to upload arbitrary files via /Command/Search Files/Directory field, leading to a denial of service by crashing the application.

📅 Published: Dec. 5, 2025, 5:33 p.m. 🔄 Last Modified: Dec. 10, 2025, 3:08 p.m.

3.5

CVSS3.1

CVE-2025-66514 - Nextcloud Mail stored HTML injection in subject text

Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Prior to 5.5.3, a stored HTML injection in the Mail app's message list allowed an authenticated user to inject HTML into the email subjects. Javascript was correctly blocked by the content security policy of the Next…

📅 Published: Dec. 5, 2025, 5:32 p.m. 🔄 Last Modified: Dec. 9, 2025, 7:23 p.m.

5.4

CVSS3.1

CVE-2025-66557 - Nextcloud Deck app allowed user with "Can share" permission to modify permissions of other non-owne…

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.14.6 and 1.15.2, a bug in the permission logic allowed users with "Can share" permission to modify the permissions of other recipients. This vulnera…

📅 Published: Dec. 5, 2025, 5:28 p.m. 🔄 Last Modified: Dec. 9, 2025, 4:46 p.m.
Total resulsts: 349182
Page 2803 of 34,919
« previous page » next page
Filters