Vulnerabilidades en NextCloud
297 resultadosAnálisis Vexday
Nextcloud apresenta apenas 2 vulnerabilidades catalogadas na base, nenhuma em ataque ativo (KEV) e nenhuma crítica. A fraqueza dominante é injeção de conteúdo (CWE-79), típica de falhas de validação em interfaces web. Com nenhuma publicação nos últimos 90 dias, o perfil de risco atual é baixo, embora demande atenção contínua em validação de entrada para contextos de rendering.
CVE-2026-45283MEDIUMNextcloud: Files Lock app allows users to lock and unlock files of other usersEPSS 0.4%CVE-2024-37316MEDIUMNextcloud Calendar's event create can create attachments that link to other websitesEPSS 0.4%CVE-2025-66510MEDIUMNextcloud Server Contacts Search allowed users to retrieve contact information of other users beyond their contact listEPSS 0.4%CVE-2021-32680LOWAudit log is not properly logging unsetting of share expiration dateEPSS 0.4%CVE-2026-45266LOWNextcloud: Unauthorized force-mute from missing permission check when using internal signalingEPSS 0.4%CVE-2026-45159LOWNextcloud: Files drop share links for end-to-end encrypted folders allowed to drop files into other folders of the share ownerEPSS 0.4%CVE-2024-52525LOWNextcloud Server User password is available in memory of the PHP processEPSS 0.3%CVE-2025-66550MEDIUMNextcloud Calendar attachments of local files are offered to downloadedEPSS 0.3%CVE-2023-28848MEDIUMCSRF protection on user_oidc login returned the expected token in case of an errorEPSS 0.3%CVE-2026-82982MEDIUMThe Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from appEPSS 0.3%CVE-2026-45278LOWNextcloud: Open Redirect in user_oidc login flow via protocol-relative URL bypassEPSS 0.3%CVE-2024-37885LOWCode injection in Nextcloud Desktop Client for macOSEPSS 0.3%CVE-2024-37317MEDIUMNextcloud Notes app can be tricked into using a received share created before the user logged inEPSS 0.3%CVE-2025-66515LOWNextcloud Approval app allows users to request approval for other users fileEPSS 0.3%CVE-2022-39210LOWAccess to internal files of the Nextcloud Android appEPSS 0.3%CVE-2025-66552MEDIUMNextcloud Server admin_audit does not log all actions on files in groupfoldersEPSS 0.3%CVE-2021-41181LOWNextcloud Talk app exposes chat messages on lockscreenEPSS 0.3%CVE-2026-45154LOWNextcloud: Improper Access Control in CollectivesEPSS 0.3%CVE-2026-45155LOWNextcloud: Private circle can be added to another circle via APIEPSS 0.3%CVE-2021-32658MEDIUMSensitive data may not be removed from storage on account removalEPSS 0.3%