Vulnerabilidades em NextCloud

288 resultados
Análise Vexday

Nextcloud apresenta apenas 2 vulnerabilidades catalogadas na base, nenhuma em ataque ativo (KEV) e nenhuma crítica. A fraqueza dominante é injeção de conteúdo (CWE-79), típica de falhas de validação em interfaces web. Com nenhuma publicação nos últimos 90 dias, o perfil de risco atual é baixo, embora demande atenção contínua em validação de entrada para contextos de rendering.

CVE-2021-32728MEDIUMEnd-to-end encryption device setup did not verify public keyEPSS 0.9%CVE-2021-41241MEDIUMAdvanced permissions is not respected for subfolders in Nextcloud serverEPSS 0.9%CVE-2021-39224LOWFile path disclosure of shared files in OfficeOnline applicationEPSS 0.8%CVE-2023-33182NONENextcloud Contacts photos only sanitized if mime type is all lower caseEPSS 0.8%CVE-2022-41968LOWNextcloud Server's calendar name length not validated before writing to databaseEPSS 0.8%CVE-2022-31120LOWFederated share accepting/declining is not logged in audit log in Nextcloud ServerEPSS 0.8%CVE-2021-32782MEDIUMCross-Site Scripting in Nextcloud CirclesEPSS 0.8%CVE-2023-25162MEDIUMNextcloud Server vulnerable to SSRF via filter bypass due to lax checking on IPsEPSS 0.8%CVE-2023-28834LOWFull path of data directory exposed to Nextcloud server usersEPSS 0.8%CVE-2023-39952MEDIUMAdvanced permissions not respected when copying entire group foldersEPSS 0.8%CVE-2022-41969LOWNextcloud Server has no password length limit when creating a user as an administratorEPSS 0.8%CVE-2023-35927HIGHNextcloud system addressbooks can be modified by malicious trusted serverEPSS 0.8%CVE-2023-26041LOWNextcloud Talk messages can still be seen on conversation after expiring when cron is misconfiguredEPSS 0.8%CVE-2023-48306MEDIUMNextcloud Server DNS pin middleware can be tricked into DNS rebinding allowing SSRFEPSS 0.8%CVE-2023-28643MEDIUMPotential share collision for recipients when caching is enabled in nextcloud serverEPSS 0.8%CVE-2021-41233MEDIUMMissing authorization in Nextcloud textEPSS 0.8%CVE-2024-52520MEDIUMNextcloud Server's link reference provider can be tricked into downloading bigger files than intendedEPSS 0.8%CVE-2023-28847LOWNextcloud Server missing brute force protection for passwords of password protected share linksEPSS 0.8%CVE-2022-31119LOWPassword disclosure in log file in Nextcloud Mail AppEPSS 0.8%CVE-2022-39211LOWServer-Side Request Forgery (SSRF) via potential filter bypass in Nextcloud ServerEPSS 0.8%