Vulnerabilidades en nextcloud

297 resultados
Análisis Vexday

O ecossistema Nextcloud acumula 266 CVEs catalogadas, com volume de novas vulnerabilidades ainda ativo — 27 surgiram nos últimos 90 dias —, mas apresenta taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. O tipo de falha predominante é CWE-284 (controle de acesso inadequado), o que indica fragilidades estruturais na gestão de permissões que tendem a ampliar a superfície de ataque em ambientes colaborativos. A CVE mais relevante no momento é CVE-2022-24838, com escore EPSS de 0,3155 — o mais alto observado no conjunto —, sinalizando probabilidade não negligenciável de exploração e merecendo atenção prioritária em qualquer plano de remediação. A existência de 2 CVEs com PoC pública, combinada a 4 falhas críticas, reforça a necessidade de monitoramento contínuo mesmo em um cenário onde a exploração confirmada ainda é ausente.

CVE-2023-45148MEDIUMRate limiter not working reliable when Memcached is installed in NextcloudEPSS 0.7%CVE-2023-32319HIGHBasic auth header on WebDAV requests is not brute-force protected in NextcloudEPSS 0.7%CVE-2022-31132HIGHUnauthenticated SSRF in 3rd party module "cerdic/csstidy"EPSS 0.7%CVE-2023-22469MEDIUMNextcloud Deck card vulnerable to data leak to unauthorized users via reference preview cacheEPSS 0.7%CVE-2023-23942MEDIUMSelf reflected HTML injection in Desktop clientEPSS 0.7%CVE-2023-28998MEDIUMNextcloud Desktop client misbehaves with E2EE when the server returns empty list of metadata keysEPSS 0.7%CVE-2023-28999MEDIUMNextcloud: Lack of authenticity of metadata keys allows a malicious server to gain access to E2EE foldersEPSS 0.7%CVE-2022-39212MEDIUMLast video frame is still sent after video is disabled in a call in Nextcloud TalkEPSS 0.7%CVE-2023-48303LOWNextcloud Server admins can change authentication details of user configured external storageEPSS 0.7%CVE-2017-0884Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permissions issue. Due to EPSS 0.7%CVE-2023-22470LOWNextcloud Deck vulnerable to uncontrolled resource consumption EPSS 0.7%CVE-2024-52515MEDIUMNextcloud Server has incomplete sanitization of SVG files allows to embed other images into previewsEPSS 0.7%CVE-2023-30540LOWChat poll data can still be queried from API after purging history in Nextcloud talkEPSS 0.7%CVE-2022-24889LOWInsufficient Verification of Data Authenticity in Nextcloud ServerEPSS 0.7%CVE-2022-39329LOWProfile of disabled user stays accessibleEPSS 0.7%CVE-2017-0891Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilitiEPSS 0.6%CVE-2017-0893Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which EPSS 0.6%CVE-2018-3764In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring EPSS 0.6%CVE-2023-48301LOWNextcloud Server HTML injection in search UI when selecting a circle with HTML in the display nameEPSS 0.6%CVE-2024-52523MEDIUMNextcloud Server Custom defined credentials of external storages are sent back to the frontendEPSS 0.6%