4.3

CVSS3.1

CVE-2025-66513 - Nextcloud Tables app share information not limited to relevant users

Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6, and 1.0.1, the information which table (numeric ID) is shared with which groups or users and the respective permissions was not limited to privileged users. This vulnerability is fixed in 0.8.9, 0.…

πŸ“… Published: Dec. 5, 2025, 5:11 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 7:32 p.m.

5.1

CVSS4.0

CVE-2025-14094 - Edimax BR-6478AC V3 formSysCmd sub_44CCE4 os command injection

A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm/formSysCmd. This manipulation of the argument sysCmd causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used. The vendor…

πŸ“… Published: Dec. 5, 2025, 5:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 5:41 a.m.

5.7

CVSS3.1

CVE-2025-66550 - Nextcloud Calendar attachments of local files are offered to downloaded

Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar event with a crafted attachment that links to a download link of a file on the same Nextcloud server, the file would be downloaded without the user confirming the action. This vul…

πŸ“… Published: Dec. 5, 2025, 4:56 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 2:13 p.m.

3.3

CVSS3.1

CVE-2025-66546 - Nextcloud Calendar app allowed booking appointments without the generated token

Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1.

πŸ“… Published: Dec. 5, 2025, 4:49 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 4:36 p.m.

4.8

CVSS3.1

CVE-2025-66511 - Nextcloud Calendar app used predictable proposal participant tokens

Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker to compute valid participant tokens, which allowed them to request details and submit dates in meeting proposals. The t…

πŸ“… Published: Dec. 5, 2025, 4:42 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 4:14 p.m.

4.3

CVSS3.1

CVE-2025-66552 - Nextcloud Server admin_audit does not log all actions on files in groupfolders

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed i…

πŸ“… Published: Dec. 5, 2025, 4:36 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 3:14 p.m.

7.7

CVSS3.1

CVE-2024-9183 - Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged users and perform actions in their context under specific condit…

πŸ“… Published: Dec. 5, 2025, 4:34 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

4.3

CVSS3.1

CVE-2025-66547 - Nextcloud Server users can modify tags on files that do not belong to them

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This vulnerability is fixed in 31.0.1.

πŸ“… Published: Dec. 5, 2025, 4:32 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 4:31 p.m.

5.1

CVSS4.0

CVE-2025-14093 - Edimax BR-6478AC V3 formTracerouteDiagnosticRun sub_416990 os command injection

A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/formTracerouteDiagnosticRun. The manipulation of the argument host results in os command injection. The attack can be launched remotely. The exploit is now public and may be used. The…

πŸ“… Published: Dec. 5, 2025, 4:32 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 5:41 a.m.

5.4

CVSS3.1

CVE-2025-66512 - Nextcloud Server vulnerable to XSS in SVG images when opened outside of Nextcloud

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to trick a user it viewing an uploaded SVG outside o…

πŸ“… Published: Dec. 5, 2025, 4:22 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 4:38 p.m.
Total resulsts: 349182
Page 2806 of 34,919
Β« previous page Β» next page
Filters