Vulnerabilidades en Nextcloud

297 resultados
Análisis Vexday

Nextcloud possui 20 vulnerabilidades registradas na base, todas de severidade moderada ou inferior, com destaque para falhas de Cross-Site Scripting (CWE-79). Nenhuma vulnerabilidade está sob ataque ativo conhecido, e não há publicações recentes nos últimos 90 dias, indicando um panorama de risco estável e sem pressão imediata.

CVE-2024-52507LOWShare information of the Nextcloud Tables app is not limited to affected usersEPSS 0.4%CVE-2026-77165MEDIUMFile owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of EPSS 0.4%CVE-2024-37314LOWNextcloud Photos' shared albums have no restriction on photo removalEPSS 0.4%CVE-2024-37313HIGHNextcloud server allows the by-pass the second factorEPSS 0.4%CVE-2024-52521LOWNextcloud Server has a potential hash collision for background jobs could skip queuing themEPSS 0.4%CVE-2026-45264MEDIUMNextcloud: ACL Rename Permission Bypass in Team Folders Allows Unauthorized File RenamesEPSS 0.4%CVE-2022-24886LOWExposure of Sensitive Information to an Unauthorized Actor in com.nextcloud.clientEPSS 0.4%CVE-2026-45157MEDIUMNextcloud: Valid share tokens allow to access tempory upload files of share ownerEPSS 0.4%CVE-2023-29000MEDIUMNextcloud Desktop client does not verify received singed certificate in end-to-end encryptionEPSS 0.4%CVE-2023-45150MEDIUMInviting excessive long email addresses to a calendar event makes the Nextcloud server unresponsiveEPSS 0.4%CVE-2024-37887LOWNextcloud Server's events information leaked with shared calendars on recurrence exceptionsEPSS 0.4%CVE-2024-37883MEDIUMNextcloud Deck can access comments and attachments of deleted cardsEPSS 0.4%CVE-2026-82985MEDIUMThe Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewiEPSS 0.4%CVE-2025-47790MEDIUMNextcloud Server doesn't request second factor after session timeoutEPSS 0.4%CVE-2026-45544MEDIUMNextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewServiceEPSS 0.4%CVE-2024-37884LOWNextcloud Server's users can delete old versions of read-only shared filesEPSS 0.4%CVE-2023-39957HIGHPath traversal allows tricking the Talk Android app into writing files into it's root directoryEPSS 0.4%CVE-2025-47791MEDIUMNextcloud Server's test remote endpoint is not rate limitedEPSS 0.4%CVE-2026-45284MEDIUMNextcloud: Wrong condition in the User OIDC app's LdapService allowed deleted LDAP users to authenticateEPSS 0.4%CVE-2022-29160LOWSensitive files/data exist after deletion of user account in Nextcloud AndroidEPSS 0.4%