Vulnerabilities (CVE)

Filtered by CWE-671
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-24024 2025-01-21 N/A 9.1 CRITICAL
Mjolnir is a moderation tool for Matrix. Mjolnir v1.9.0 responds to management commands from any room the bot is member of. This can allow users who aren't operators of the bot to use the bot's functions, including server administration components if enabled. Version 1.9.1 reverts the feature that introduced the bug, and version 1.9.2 reintroduces the feature safely. Downgrading to version 1.8.3 is recommended if upgrading to 1.9.1 or higher isn't possible.
CVE-2022-29163 1 Nextcloud 1 Nextcloud Server 2024-11-21 4.0 MEDIUM 3.5 LOW
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.6 and 23.0.3, a user can create a link that is not password protected even if the administrator requires links to be password protected. Versions 22.2.6 and 23.0.3 contain a patch for this issue. There are currently no known workarounds.