HackerOne Vulnerabilities and Affected Products
Vulnerabilities associated with Nextcloud Server.
Products
Clear product- hapi node module4 vulnerabilities
- RubyGems4 vulnerabilities
- sequelize node module4 vulnerabilities
- coffeescript node module3 vulnerabilities
- crud-file-server node module2 vulnerabilities
- express-cart2 vulnerabilities
- html-janitor node module2 vulnerabilities
- i18next node module2 vulnerabilities
- m-server2 vulnerabilities
- marked node module2 vulnerabilities
- Nextcloud Server2 vulnerabilities
- private_address_check ruby gem2 vulnerabilities
- remarkable node module2 vulnerabilities
- sanitize-html node module2 vulnerabilities
- serve node module2 vulnerabilities
- ws node module2 vulnerabilities
- 11xiaoli node module1 vulnerability
- 22lixian node module1 vulnerability
- 360class.jansenhm node module1 vulnerability
- 626 node module1 vulnerability
- active-support ruby gem1 vulnerability
- adamvr-geoip-lite node module1 vulnerability
- aedes1 vulnerability
- aegir node module1 vulnerability
- aerospike node module1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-3776MEDIUM | Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log. | CVSS5.3v3.1 | EPSS1.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-3775HIGH | Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication. CWE-287Aug 12, 2018 | CVSS8.8v3.1 | EPSS1.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |