Vulnerabilidades en Nextcloud
288 resultadosAnálisis Vexday
Nextcloud possui 20 vulnerabilidades registradas na base, todas de severidade moderada ou inferior, com destaque para falhas de Cross-Site Scripting (CWE-79). Nenhuma vulnerabilidade está sob ataque ativo conhecido, e não há publicações recentes nos últimos 90 dias, indicando um panorama de risco estável e sem pressão imediata.
CVE-2023-28997MEDIUMNextcloud Desktop: Initialization vector reuse in E2EE allows malicious server admin to break, manipulate, access filesEPSS 1.1%CVE-2021-32652HIGHMissing permission check on email metadata retrievalEPSS 1.1%CVE-2021-32733MEDIUMXSS in Nextcloud Text applicationEPSS 1.1%CVE-2022-35932LOWMissing rate limit when trying to join a password protected Nextcloud Talk conversationEPSS 1.1%CVE-2021-41256MEDIUMIntent URI permissions manipulation in nextcloud news-androidEPSS 1.1%CVE-2022-29163LOWBypass of password requirements when sharing a folder via the Circles app in Nextcloud ServerEPSS 1.1%CVE-2022-24906LOWError in deleting deck cards attachment reveals the full application path in Nextcloud DeckEPSS 1.1%CVE-2021-39222MEDIUMXSS in TalkEPSS 1.1%CVE-2021-41180MEDIUMGeolocation preview links can be set to arbitrary links in nextcloud talkEPSS 1.0%CVE-2023-49792MEDIUMBruteforce protection can be bypassed with misconfigured proxyEPSS 1.0%CVE-2021-32655LOWFiles Drop public link can be added as federated shareEPSS 1.0%CVE-2021-39223MEDIUMFile path disclosure of shared files in Richdocuments applicationEPSS 1.0%CVE-2021-32689HIGHNextcloud Talk not properly disassociating users from chats after account deletionEPSS 1.0%CVE-2022-39346LOWMissing length validation of user displayname in nextcloud serverEPSS 1.0%CVE-2021-32748MEDIUMWOPI API not protected by credentials/IP checkEPSS 1.0%CVE-2017-0892—Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to EPSS 1.0%CVE-2023-35928HIGHNextcloud user scoped external storage can be used to gather credentials of other usersEPSS 1.0%CVE-2021-32694MEDIUMMalicious Android application can crash the Nextcloud Android ClientEPSS 1.0%CVE-2022-29159MEDIUMPossibility for anyone to add a stack with existing tasks on anyone's board in Nextcloud DeckEPSS 1.0%CVE-2021-32676MEDIUMSession Fixation in Nextcloud TalkEPSS 1.0%