Vulnerabilidades en nextcloud

297 resultados
Análisis Vexday

O ecossistema Nextcloud acumula 266 CVEs catalogadas, com volume de novas vulnerabilidades ainda ativo — 27 surgiram nos últimos 90 dias —, mas apresenta taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. O tipo de falha predominante é CWE-284 (controle de acesso inadequado), o que indica fragilidades estruturais na gestão de permissões que tendem a ampliar a superfície de ataque em ambientes colaborativos. A CVE mais relevante no momento é CVE-2022-24838, com escore EPSS de 0,3155 — o mais alto observado no conjunto —, sinalizando probabilidade não negligenciável de exploração e merecendo atenção prioritária em qualquer plano de remediação. A existência de 2 CVEs com PoC pública, combinada a 4 falhas críticas, reforça a necessidade de monitoramento contínuo mesmo em um cenário onde a exploração confirmada ainda é ausente.

CVE-2021-41239MEDIUMUser enumeration setting not respected in Nextcloud serverEPSS 1.1%CVE-2023-28997MEDIUMNextcloud Desktop: Initialization vector reuse in E2EE allows malicious server admin to break, manipulate, access filesEPSS 1.1%CVE-2021-32652HIGHMissing permission check on email metadata retrievalEPSS 1.1%CVE-2021-32733MEDIUMXSS in Nextcloud Text applicationEPSS 1.1%CVE-2021-39222MEDIUMXSS in TalkEPSS 1.1%CVE-2022-29163LOWBypass of password requirements when sharing a folder via the Circles app in Nextcloud ServerEPSS 1.1%CVE-2021-41256MEDIUMIntent URI permissions manipulation in nextcloud news-androidEPSS 1.1%CVE-2022-24906LOWError in deleting deck cards attachment reveals the full application path in Nextcloud DeckEPSS 1.1%CVE-2021-39223MEDIUMFile path disclosure of shared files in Richdocuments applicationEPSS 1.1%CVE-2021-41180MEDIUMGeolocation preview links can be set to arbitrary links in nextcloud talkEPSS 1.0%CVE-2023-49792MEDIUMBruteforce protection can be bypassed with misconfigured proxyEPSS 1.0%CVE-2022-39346LOWMissing length validation of user displayname in nextcloud serverEPSS 1.0%CVE-2021-32655LOWFiles Drop public link can be added as federated shareEPSS 1.0%CVE-2023-39962HIGHUsers can delete external storage mount pointsEPSS 1.0%CVE-2021-32689HIGHNextcloud Talk not properly disassociating users from chats after account deletionEPSS 1.0%CVE-2021-32748MEDIUMWOPI API not protected by credentials/IP checkEPSS 1.0%CVE-2017-0892Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to EPSS 1.0%CVE-2023-35928HIGHNextcloud user scoped external storage can be used to gather credentials of other usersEPSS 1.0%CVE-2021-32694MEDIUMMalicious Android application can crash the Nextcloud Android ClientEPSS 1.0%CVE-2022-29159MEDIUMPossibility for anyone to add a stack with existing tasks on anyone's board in Nextcloud DeckEPSS 1.0%