Vulnerabilidades en Nextcloud
288 resultadosAnálisis Vexday
Nextcloud possui 20 vulnerabilidades registradas na base, todas de severidade moderada ou inferior, com destaque para falhas de Cross-Site Scripting (CWE-79). Nenhuma vulnerabilidade está sob ataque ativo conhecido, e não há publicações recentes nos últimos 90 dias, indicando um panorama de risco estável e sem pressão imediata.
CVE-2025-66551MEDIUMNextcloud Tables is missing an ownership check which allows moving columns into tables of other usersEPSS 0.2%CVE-2023-48305MEDIUMNextcloud Server user_ldap app logs user passwords in the log file on level debugEPSS 0.2%CVE-2025-66514LOWNextcloud Mail stored HTML injection in subject textEPSS 0.2%CVE-2025-66554LOWNextcloud Contacts vulnerable to Stored XSS in contacts app via organisation and title fieldEPSS 0.2%CVE-2023-39963HIGHMissing password confirmation when creating app passwordsEPSS 0.2%CVE-2024-37886MEDIUMNextcloud user_oidc's ID4me does not validate signature or expirationEPSS 0.2%CVE-2021-32801MEDIUMExceptions may have logged Encryption-at-Rest key content in Nextcloud serverEPSS 0.2%CVE-2023-25820MEDIUMNextcloud Server and Enterprise Server missing brute force protection on password confirmation modalEPSS 0.2%CVE-2026-45278LOWNextcloud: Open Redirect in user_oidc login flow via protocol-relative URL bypassEPSS 0.2%CVE-2026-45157MEDIUMNextcloud: Valid share tokens allow to access tempory upload files of share ownerEPSS 0.2%CVE-2026-45264MEDIUMNextcloud: ACL Rename Permission Bypass in Team Folders Allows Unauthorized File RenamesEPSS 0.2%CVE-2023-28646MEDIUMApp lockout in nextcloud Android app can be bypassed via thirdparty appsEPSS 0.2%CVE-2026-45544MEDIUMNextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewServiceEPSS 0.2%CVE-2026-45283MEDIUMNextcloud: Files Lock app allows users to lock and unlock files of other usersEPSS 0.2%CVE-2023-32318HIGHUser session not correctly destroyed on logoutEPSS 0.2%CVE-2023-22472MEDIUMNextcloud Deck Desktop Client is vulnerable to Cross-Site Request Forgery (CSRF) via malicious linkEPSS 0.2%CVE-2026-45159LOWNextcloud: Files drop share links for end-to-end encrypted folders allowed to drop files into other folders of the share ownerEPSS 0.2%CVE-2026-45266LOWNextcloud: Unauthorized force-mute from missing permission check when using internal signalingEPSS 0.2%CVE-2022-39334LOWnextcloudcmd incorrectly trusts bad TLS certificatesEPSS 0.2%CVE-2026-45155LOWNextcloud: Private circle can be added to another circle via APIEPSS 0.2%