Show filters
448 Total Results
Displaying 201-210 of 448
Sort by:
Attacker Value
Unknown
CVE-2022-31093
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
NextAuth.js is a complete open source authentication solution for Next.js applications. In affected versions an attacker can send a request to an app using NextAuth.js with an invalid `callbackUrl` query parameter, which internally is converted to a `URL` object. The URL instantiation would fail due to a malformed URL being passed into the constructor, causing it to throw an unhandled error which led to the **API route handler timing out and logging in to fail**. This has been remedied in versions 3.29.5 and 4.5.0. If for some reason you cannot upgrade, the workaround requires you to rely on Advanced Initialization. Please see the documentation for more.
0
Attacker Value
Unknown
CVE-2022-31024
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6.0.0, 5.0.4, and 4.2.6, a user could be tricked into working against a remote Office by sending them a federated share. richdocuments versions 6.0.0, 5.0.4 and 4.2.6 contain a fix for this issue. There are currently no known workarounds available.
0
Attacker Value
Unknown
CVE-2022-29243
Disclosure Date: May 31, 2022 (last updated February 23, 2025)
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.7 and 23.0.4, missing input-size validation of new session names allows users to create app passwords with long names. These long names are then loaded into memory on usage, resulting in impacted performance. Versions 22.2.7 and 23.0.4 contain a fix for this issue. There are currently no known workarounds available.
0
Attacker Value
Unknown
CVE-2022-29439
Disclosure Date: May 26, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Image Slider by NextCode plugin <= 1.1.2 at WordPress allows deleting slides.
0
Attacker Value
Unknown
CVE-2022-29438
Disclosure Date: May 26, 2022 (last updated February 23, 2025)
Authenticated (author or higher user role) Persistent Cross-Site Scripting (XSS) vulnerability in Image Slider by NextCode plugin <= 1.1.2 at WordPress.
0
Attacker Value
Unknown
CVE-2022-29437
Disclosure Date: May 26, 2022 (last updated February 23, 2025)
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Image Slider by NextCode plugin <= 1.1.2 at WordPress.
0
Attacker Value
Unknown
CVE-2022-29214
Disclosure Date: May 21, 2022 (last updated February 23, 2025)
NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. Prior to versions 3.29.3 and 4.3.3, an open redirect vulnerability is present when the developer is implementing an OAuth 1 provider. Versions 3.29.3 and 4.3.3 contain a patch for this issue. The maintainers recommend adding a certain configuration to one's `callbacks` option as a workaround for those unable to upgrade.
0
Attacker Value
Unknown
CVE-2022-29163
Disclosure Date: May 20, 2022 (last updated February 23, 2025)
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.6 and 23.0.3, a user can create a link that is not password protected even if the administrator requires links to be password protected. Versions 22.2.6 and 23.0.3 contain a patch for this issue. There are currently no known workarounds.
0
Attacker Value
Unknown
CVE-2022-29160
Disclosure Date: May 20, 2022 (last updated February 23, 2025)
Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sensitive tokens, images, and user related details exist after deletion of a user account. This could result in misuse of the former account holder's information. Nextcloud Android version 3.19.0 contains a patch for this issue. There are no known workarounds available.
0
Attacker Value
Unknown
CVE-2022-29159
Disclosure Date: May 20, 2022 (last updated February 23, 2025)
Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud. In versions prior to 1.4.8, 1.5.6, and 1.6.1, an authenticated user can move stacks with cards from their own board to a board of another user. The Nextcloud Deck app contains a patch for this issue in versions 1.4.8, 1.5.6, and 1.6.1. There are no known currently-known workarounds available.
0