Vulnerabilities in NextCloud

288 results
Vexday analysis

Nextcloud apresenta apenas 2 vulnerabilidades catalogadas na base, nenhuma em ataque ativo (KEV) e nenhuma crítica. A fraqueza dominante é injeção de conteúdo (CWE-79), típica de falhas de validação em interfaces web. Com nenhuma publicação nos últimos 90 dias, o perfil de risco atual é baixo, embora demande atenção contínua em validação de entrada para contextos de rendering.

CVE-2023-45149MEDIUMPassword of talk conversations can be bruteforced in NextcloudEPSS 0.5%CVE-2022-39364MEDIUMException logging in Sharepoint app reveals clear-text connection detailsEPSS 0.5%CVE-2023-23944LOWNexcloud Mail app temporarily stores cleartext password in databaseEPSS 0.5%CVE-2021-37617HIGHUntrusted Search Path in Nextcloud Desktop ClientEPSS 0.5%CVE-2024-52514MEDIUMNextcloud Server allows users to copy folder that contain files that are blocked by the files access controlEPSS 0.5%CVE-2019-5453Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protectiEPSS 0.5%CVE-2022-24885LOWImproper Authentication in Nextcloud Android FilesEPSS 0.5%CVE-2022-41882MEDIUMNextcloud Desktop vulnerable to code injection via malicious linkEPSS 0.5%CVE-2019-5455Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.EPSS 0.5%CVE-2024-22401MEDIUMAll users can reset the allowed apps list for Nextcloud Guest App usersEPSS 0.5%CVE-2023-25160MEDIUMIDOR Vulnerability in Nextcloud MailEPSS 0.5%CVE-2023-25159LOWNextcloud Server previews are accessible without a watermarkEPSS 0.5%CVE-2024-22400LOWOpen redirect in user_saml via RelayState parameter in Nextcloud User SamlEPSS 0.5%CVE-2024-22403LOWOAuth2 authorization codes are valid indefinetly in Nextcloud serverEPSS 0.5%CVE-2024-52511MEDIUMNextcloud Tables has an Authorization Bypass Through User-Controlled Key in TablesEPSS 0.4%CVE-2023-28845LOWChat room membership disclosed via autocompletion in Nextcloud talkEPSS 0.4%CVE-2023-39954LOWuser_oidc app stores client secret unencrypted in databaseEPSS 0.4%CVE-2025-47794LOWNextcloud Server vulnerable to insecure temporary file creation, race with write access and permissionEPSS 0.4%CVE-2023-33183LOWError in calendar when booking an appointment reveals the full path of the websiteEPSS 0.4%CVE-2022-36075LOWFile list exposure in Nextcloud Files Access ControlEPSS 0.4%