Vulnerabilidades en NextCloud
297 resultadosAnálisis Vexday
Nextcloud apresenta apenas 2 vulnerabilidades catalogadas na base, nenhuma em ataque ativo (KEV) e nenhuma crítica. A fraqueza dominante é injeção de conteúdo (CWE-79), típica de falhas de validação em interfaces web. Com nenhuma publicação nos últimos 90 dias, o perfil de risco atual é baixo, embora demande atenção contínua em validação de entrada para contextos de rendering.
CVE-2025-66554LOWNextcloud Contacts vulnerable to Stored XSS in contacts app via organisation and title fieldEPSS 0.3%CVE-2025-66514LOWNextcloud Mail stored HTML injection in subject textEPSS 0.3%CVE-2023-48305MEDIUMNextcloud Server user_ldap app logs user passwords in the log file on level debugEPSS 0.2%CVE-2024-37886MEDIUMNextcloud user_oidc's ID4me does not validate signature or expirationEPSS 0.2%CVE-2021-32801MEDIUMExceptions may have logged Encryption-at-Rest key content in Nextcloud serverEPSS 0.2%CVE-2023-25820MEDIUMNextcloud Server and Enterprise Server missing brute force protection on password confirmation modalEPSS 0.2%CVE-2023-28646MEDIUMApp lockout in nextcloud Android app can be bypassed via thirdparty appsEPSS 0.2%CVE-2026-68493LOWAfter guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they arEPSS 0.2%CVE-2023-32318HIGHUser session not correctly destroyed on logoutEPSS 0.2%CVE-2022-39334LOWnextcloudcmd incorrectly trusts bad TLS certificatesEPSS 0.2%CVE-2026-45153MEDIUMNextcloud: PIN bypass in PassCodeActivity via back buttonEPSS 0.2%CVE-2023-22472MEDIUMNextcloud Deck Desktop Client is vulnerable to Cross-Site Request Forgery (CSRF) via malicious linkEPSS 0.2%CVE-2026-77164MEDIUMCircles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, EPSS 0.2%CVE-2025-47792MEDIUMNextcloud Desktop 3rdparty applications can create share links via socket APIEPSS 0.2%CVE-2026-45277LOWNextcloud: Information disclosure in Nextcloud Approval app via fileId parameter reveals workflow associationsEPSS 0.2%CVE-2025-66548LOWNextcloud Deck app allows to spoof file extensions by using RTLO charactersEPSS 0.2%CVE-2025-66546LOWNextcloud Calendar app allowed booking appointments without the generated tokenEPSS 0.1%