Vulnerabilidades em NextCloud
288 resultadosAnálise Vexday
Nextcloud apresenta apenas 2 vulnerabilidades catalogadas na base, nenhuma em ataque ativo (KEV) e nenhuma crítica. A fraqueza dominante é injeção de conteúdo (CWE-79), típica de falhas de validação em interfaces web. Com nenhuma publicação nos últimos 90 dias, o perfil de risco atual é baixo, embora demande atenção contínua em validação de entrada para contextos de rendering.
CVE-2017-0936—Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownershiEPSS 0.8%CVE-2023-28833LOWUnrestricted filenames for logo or favicon as admin in the theming settings in nextcloud serverEPSS 0.8%CVE-2021-39220LOWBypass of image blocking in Nextcloud MailEPSS 0.8%CVE-2022-41971MEDIUMNextcloud Talk guests can continue to receive video streams from call after being removed from a conversationEPSS 0.8%CVE-2024-22212CRITICALNextcloud global site selector authentication bypassEPSS 0.8%CVE-2023-28645MEDIUMSecure view can be bypassed by using internal API endpoint in Nextcloud richdocumentsEPSS 0.7%CVE-2018-3781—A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2.5 could lead to a stored XSS requiring user-interaEPSS 0.7%CVE-2022-31131MEDIUMOwnership check missing when updating or deleting mail attachments in Nextcloud mailEPSS 0.7%CVE-2017-0890—Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitablEPSS 0.7%CVE-2023-25150MEDIUMDocument content of files can be obtained through Collabora for files of other usersEPSS 0.7%CVE-2021-32727MEDIUMEnd-to-end encryption device setup did not verify public keyEPSS 0.7%CVE-2023-25161LOWNextcloud Server's missing rate limiting on password reset functionality allows sending lots of emailsEPSS 0.7%CVE-2024-52510MEDIUMNextcloud Desktop client behaves incorrectly if the initial end-to-end-encryption signature is emptyEPSS 0.7%CVE-2017-0895—Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note thatEPSS 0.7%CVE-2025-47793MEDIUMNextcloud Server and Groupfolders app vulnerable to bypass of group folder quota limit using attachment in text fileEPSS 0.7%CVE-2022-31118MEDIUMMissing brute force protection on cloud federation sharing in Nextcloud ServerEPSS 0.7%CVE-2023-39958MEDIUMMissing brute force protection on password reset token OAuth2 API controllerEPSS 0.7%CVE-2021-29438MEDIUMImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in @nextcloud/dialogsEPSS 0.7%CVE-2023-45148MEDIUMRate limiter not working reliable when Memcached is installed in NextcloudEPSS 0.7%CVE-2024-52508HIGHNextcloud Mail auto configurator can be tricked into sending account information to wrong serversEPSS 0.7%