Vulnerabilidades en Nextcloud

297 resultados
Análisis Vexday

Nextcloud possui 20 vulnerabilidades registradas na base, todas de severidade moderada ou inferior, com destaque para falhas de Cross-Site Scripting (CWE-79). Nenhuma vulnerabilidade está sob ataque ativo conhecido, e não há publicações recentes nos últimos 90 dias, indicando um panorama de risco estável e sem pressão imediata.

CVE-2024-22401MEDIUMAll users can reset the allowed apps list for Nextcloud Guest App usersEPSS 0.5%CVE-2026-45543MEDIUMNextcloud: Deleting a Forms collaborator share leaves uploaded response files accessible through a lingering Files shareEPSS 0.5%CVE-2023-25160MEDIUMIDOR Vulnerability in Nextcloud MailEPSS 0.5%CVE-2024-52511MEDIUMNextcloud Tables has an Authorization Bypass Through User-Controlled Key in TablesEPSS 0.5%CVE-2021-37617HIGHUntrusted Search Path in Nextcloud Desktop ClientEPSS 0.5%CVE-2022-39339MEDIUMCleartext Transmission of Sensitive Information in user_oidcEPSS 0.5%CVE-2026-45286MEDIUMNextcloud: Calendar app leaked user identifiers via attendee suggestion endpointEPSS 0.5%CVE-2023-25159LOWNextcloud Server previews are accessible without a watermarkEPSS 0.5%CVE-2024-22400LOWOpen redirect in user_saml via RelayState parameter in Nextcloud User SamlEPSS 0.5%CVE-2024-22403LOWOAuth2 authorization codes are valid indefinetly in Nextcloud serverEPSS 0.5%CVE-2022-35931LOWNextcloud Password Policy's generated passwords are not fully validated by HIBPValidatorEPSS 0.5%CVE-2023-28845LOWChat room membership disclosed via autocompletion in Nextcloud talkEPSS 0.4%CVE-2023-39954LOWuser_oidc app stores client secret unencrypted in databaseEPSS 0.4%CVE-2023-33183LOWError in calendar when booking an appointment reveals the full path of the websiteEPSS 0.4%CVE-2026-45810MEDIUMNextcloud: Propfind requests for file comments allowed to load comments for other filesEPSS 0.4%CVE-2026-45690MEDIUMNextcloud: Two-Factor Authentication Bypass via Pending Session Token ReplayEPSS 0.4%CVE-2026-45691MEDIUMNextcloud: Bypass of second factor authentication on DAV endpointsEPSS 0.4%CVE-2024-37315LOWNextcloud Server's read-only users can restore old versionsEPSS 0.4%CVE-2024-52516LOWNextcloud Server's shares are not removed when user is limited to share with in their groups and being removed from one of themEPSS 0.4%CVE-2024-52512LOWNextcloud User OIDC has an open redirection when logging in with User OIDCEPSS 0.4%