Vulnerabilidades em NextCloud

288 resultados
Análise Vexday

Nextcloud apresenta apenas 2 vulnerabilidades catalogadas na base, nenhuma em ataque ativo (KEV) e nenhuma crítica. A fraqueza dominante é injeção de conteúdo (CWE-79), típica de falhas de validação em interfaces web. Com nenhuma publicação nos últimos 90 dias, o perfil de risco atual é baixo, embora demande atenção contínua em validação de entrada para contextos de rendering.

CVE-2023-32319HIGHBasic auth header on WebDAV requests is not brute-force protected in NextcloudEPSS 0.7%CVE-2023-22469MEDIUMNextcloud Deck card vulnerable to data leak to unauthorized users via reference preview cacheEPSS 0.7%CVE-2022-31132HIGHUnauthenticated SSRF in 3rd party module "cerdic/csstidy"EPSS 0.7%CVE-2023-23942MEDIUMSelf reflected HTML injection in Desktop clientEPSS 0.7%CVE-2023-28998MEDIUMNextcloud Desktop client misbehaves with E2EE when the server returns empty list of metadata keysEPSS 0.7%CVE-2023-28999MEDIUMNextcloud: Lack of authenticity of metadata keys allows a malicious server to gain access to E2EE foldersEPSS 0.7%CVE-2023-48303LOWNextcloud Server admins can change authentication details of user configured external storageEPSS 0.7%CVE-2017-0884Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permissions issue. Due to EPSS 0.7%CVE-2023-22470LOWNextcloud Deck vulnerable to uncontrolled resource consumption EPSS 0.7%CVE-2023-30540LOWChat poll data can still be queried from API after purging history in Nextcloud talkEPSS 0.7%CVE-2024-52515MEDIUMNextcloud Server has incomplete sanitization of SVG files allows to embed other images into previewsEPSS 0.7%CVE-2022-24889LOWInsufficient Verification of Data Authenticity in Nextcloud ServerEPSS 0.6%CVE-2017-0891Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilitiEPSS 0.6%CVE-2017-0893Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which EPSS 0.6%CVE-2018-3764In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring EPSS 0.6%CVE-2023-48301LOWNextcloud Server HTML injection in search UI when selecting a circle with HTML in the display nameEPSS 0.6%CVE-2024-37312MEDIUMNextcloud user_oidc app's ID4me feature is available even when disabledEPSS 0.6%CVE-2024-52523MEDIUMNextcloud Server Custom defined credentials of external storages are sent back to the frontendEPSS 0.6%CVE-2022-36074MEDIUMAuthentication headers exposed on by Nextcloud ServerEPSS 0.6%CVE-2023-30539MEDIUMUsers can set up workflows using restricted and invisible system tags in NextcloudEPSS 0.6%