Total
842 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2025-3519 | 2025-04-23 | N/A | ||
An authorization bypass in Unblu Spark allows a participant of a conversation to replace an existing, uploaded file. Every uploaded file in Unblu gets assigned with a randomly generated Universally Unique ID (UUID). In case a participant of this or another conversation gets access to such a file ID, it can be used to replace the file without changing the file name and details or the name of the user who uploaded the file. During the upload, file interception and allowed file type rules are still applied correctly. | ||||
CVE-2022-29159 | 1 Nextcloud | 1 Deck | 2025-04-22 | 5 Medium |
Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud. In versions prior to 1.4.8, 1.5.6, and 1.6.1, an authenticated user can move stacks with cards from their own board to a board of another user. The Nextcloud Deck app contains a patch for this issue in versions 1.4.8, 1.5.6, and 1.6.1. There are no known currently-known workarounds available. | ||||
CVE-2022-31131 | 1 Nextcloud | 1 Nextcloud Mail | 2025-04-22 | 5.4 Medium |
Nextcloud mail is a Mail app for the Nextcloud home server product. Versions of Nextcloud mail prior to 1.12.2 were found to be missing user account ownership checks when performing tasks related to mail attachments. Attachments may have been exposed to incorrect system users. It is recommended that the Nextcloud Mail app is upgraded to 1.12.2. There are no known workarounds for this issue. ### Workarounds No workaround available ### References * [Pull request](https://github.com/nextcloud/mail/pull/6600) * [HackerOne](https://hackerone.com/reports/1579820) ### For more information If you have any questions or comments about this advisory: * Create a post in [nextcloud/security-advisories](https://github.com/nextcloud/security-advisories/discussions) * Customers: Open a support ticket at [support.nextcloud.com](https://support.nextcloud.com) | ||||
CVE-2022-31295 | 1 Razormist | 1 Online Discussion Forum Site | 2025-04-22 | 7.5 High |
An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily delete posts. | ||||
CVE-2025-22931 | 2025-04-21 | 7.5 High | ||
An insecure direct object reference (IDOR) in the component /assets/stafffiles of OS4ED openSIS v7.0 to v9.1 allows unauthenticated attackers to access files uploaded by staff members. | ||||
CVE-2017-15206 | 1 Kanboard | 1 Kanboard | 2025-04-20 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can add an internal link to a private project of another user. | ||||
CVE-2017-15199 | 1 Kanboard | 1 Kanboard | 2025-04-20 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit metadata of a private project of another user, as demonstrated by Name, Email, Identifier, and Description. | ||||
CVE-2017-15196 | 1 Kanboard | 1 Kanboard | 2025-04-20 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove columns from a private project of another user. | ||||
CVE-2017-15197 | 1 Kanboard | 1 Kanboard | 2025-04-20 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new category to a private project of another user. | ||||
CVE-2017-0882 | 1 Gitlab | 1 Gitlab | 2025-04-20 | N/A |
Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC. | ||||
CVE-2017-15195 | 1 Kanboard | 1 Kanboard | 2025-04-20 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of another user. | ||||
CVE-2017-15201 | 1 Kanboard | 1 Kanboard | 2025-04-20 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tags of a private project of another user. | ||||
CVE-2017-15211 | 1 Kanboard | 1 Kanboard | 2025-04-20 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can add an external link to a private project of another user. | ||||
CVE-2017-15200 | 1 Kanboard | 1 Kanboard | 2025-04-20 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new task to a private project of another user. | ||||
CVE-2017-15207 | 1 Kanboard | 1 Kanboard | 2025-04-20 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tasks of a private project of another user. | ||||
CVE-2017-15203 | 1 Kanboard | 1 Kanboard | 2025-04-20 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove categories from a private project of another user. | ||||
CVE-2017-15209 | 1 Kanboard | 1 Kanboard | 2025-04-20 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove attachments from a private project of another user. | ||||
CVE-2017-15204 | 1 Kanboard | 1 Kanboard | 2025-04-20 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can add automatic actions to a private project of another user. | ||||
CVE-2017-15208 | 1 Kanboard | 1 Kanboard | 2025-04-20 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove automatic actions from a private project of another user. | ||||
CVE-2017-15202 | 1 Kanboard | 1 Kanboard | 2025-04-20 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit columns of a private project of another user. |