Vulnerabilidades en Nextcloud
288 resultadosAnálisis Vexday
Nextcloud possui 20 vulnerabilidades registradas na base, todas de severidade moderada ou inferior, com destaque para falhas de Cross-Site Scripting (CWE-79). Nenhuma vulnerabilidade está sob ataque ativo conhecido, e não há publicações recentes nos últimos 90 dias, indicando um panorama de risco estável e sem pressão imediata.
CVE-2023-23944LOWNexcloud Mail app temporarily stores cleartext password in databaseEPSS 0.5%CVE-2021-37617HIGHUntrusted Search Path in Nextcloud Desktop ClientEPSS 0.5%CVE-2024-52514MEDIUMNextcloud Server allows users to copy folder that contain files that are blocked by the files access controlEPSS 0.5%CVE-2023-39961LOWText does not respect "Allow download" permissionsEPSS 0.5%CVE-2019-5453—Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protectiEPSS 0.5%CVE-2022-24885LOWImproper Authentication in Nextcloud Android FilesEPSS 0.5%CVE-2022-41882MEDIUMNextcloud Desktop vulnerable to code injection via malicious linkEPSS 0.5%CVE-2019-5455—Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.EPSS 0.5%CVE-2024-22401MEDIUMAll users can reset the allowed apps list for Nextcloud Guest App usersEPSS 0.5%CVE-2023-25160MEDIUMIDOR Vulnerability in Nextcloud MailEPSS 0.5%CVE-2023-25159LOWNextcloud Server previews are accessible without a watermarkEPSS 0.5%CVE-2024-22400LOWOpen redirect in user_saml via RelayState parameter in Nextcloud User SamlEPSS 0.5%CVE-2024-22403LOWOAuth2 authorization codes are valid indefinetly in Nextcloud serverEPSS 0.5%CVE-2024-52511MEDIUMNextcloud Tables has an Authorization Bypass Through User-Controlled Key in TablesEPSS 0.4%CVE-2023-39953MEDIUMIssuer not verified from obtained token in user_oidcEPSS 0.4%CVE-2023-28845LOWChat room membership disclosed via autocompletion in Nextcloud talkEPSS 0.4%CVE-2025-47794LOWNextcloud Server vulnerable to insecure temporary file creation, race with write access and permissionEPSS 0.4%CVE-2023-33183LOWError in calendar when booking an appointment reveals the full path of the websiteEPSS 0.4%CVE-2022-36075LOWFile list exposure in Nextcloud Files Access ControlEPSS 0.4%CVE-2024-37315LOWNextcloud Server's read-only users can restore old versionsEPSS 0.4%