Sploitus

CVE-2024-37884

No indexed exploits for CVE-2024-37884 yet

Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versions of files they only got shared with read permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.12 or 27.1.7 or 28.0.3 and that the Nextcloud Enterprise Server is upgraded to 26.0.12 or 27.1.7 or 28.0.3.

Nextcloud Nextcloud Server
< 25.0.13.7, 26.0.13, 27.1.8, 28.0.4
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
0.4% (30th percentile)
Weakness
CWE-284
NVD status
Modified
Published
2024-06-14
CVE-2024-37884 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-37884 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-37884 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.