Vulnerabilidades em NextCloud

288 resultados
Análise Vexday

Nextcloud apresenta apenas 2 vulnerabilidades catalogadas na base, nenhuma em ataque ativo (KEV) e nenhuma crítica. A fraqueza dominante é injeção de conteúdo (CWE-79), típica de falhas de validação em interfaces web. Com nenhuma publicação nos últimos 90 dias, o perfil de risco atual é baixo, embora demande atenção contínua em validação de entrada para contextos de rendering.

CVE-2021-32676MEDIUMSession Fixation in Nextcloud TalkEPSS 1.0%CVE-2023-48239HIGHNextcloud Server users can make external storage mount points inaccessible for other usersEPSS 0.9%CVE-2021-41166MEDIUMPermission bypass in Nextcloud Android AppEPSS 0.9%CVE-2023-25821MEDIUMNextcloud download permissions can be changed by resharerEPSS 0.9%CVE-2022-24890LOWExposure of Private Personal Information to an Unauthorized Actor in Nextcloud TalkEPSS 0.9%CVE-2022-24887MEDIUMOpen Redirect in Nextcloud TalkEPSS 0.9%CVE-2023-23943MEDIUMBlind SSRF via server URL input in the Nextcloud Mail appEPSS 0.9%CVE-2023-35172HIGHNextcloud Server password reset endpoint is not brute force protectedEPSS 0.9%CVE-2022-39332MEDIUMCross-site scripting (XSS) in Nextcloud Desktop Client EPSS 0.9%CVE-2022-39333MEDIUMCross-site scripting (XSS) in Nextcloud Desktop ClientEPSS 0.9%CVE-2017-0885Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in EPSS 0.9%CVE-2022-39331MEDIUMCross-site Scripting (XSS) in Nexcloud Desktop ClientEPSS 0.9%CVE-2018-3762Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still rEPSS 0.9%CVE-2017-0887Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by tEPSS 0.9%CVE-2018-3780A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-intEPSS 0.9%CVE-2021-32695LOWMalicious Android app could access Shared Preferences of the Nextcloud Android clientEPSS 0.9%CVE-2023-32320HIGHNextcloud Server's brute force protection allows someone to send more requests than intendedEPSS 0.9%CVE-2023-48307LOWNextcloud Mail app vulnerable to Server-Side Request ForgeryEPSS 0.9%CVE-2022-39330MEDIUMDatabase resource exhaustion for logged-in users via sharee recommendations with circlesEPSS 0.9%CVE-2023-32074HIGHNextcloud user_oidc app is missing brute force protectionEPSS 0.9%