Vulnerabilidades em NextCloud

288 resultados
Análise Vexday

Nextcloud apresenta apenas 2 vulnerabilidades catalogadas na base, nenhuma em ataque ativo (KEV) e nenhuma crítica. A fraqueza dominante é injeção de conteúdo (CWE-79), típica de falhas de validação em interfaces web. Com nenhuma publicação nos últimos 90 dias, o perfil de risco atual é baixo, embora demande atenção contínua em validação de entrada para contextos de rendering.

CVE-2023-30539MEDIUMUsers can set up workflows using restricted and invisible system tags in NextcloudEPSS 0.6%CVE-2023-28644MEDIUMReference fetch can saturate the server bandwidth for 10 seconds in nextcloud serverEPSS 0.6%CVE-2023-28844MEDIUMUser without download rights can download older version of that file in nextcloud serverEPSS 0.6%CVE-2018-3763In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could lead to a stored XSS EPSS 0.6%CVE-2023-49791MEDIUMWorkflows do not require password confirmation on API levelEPSS 0.6%CVE-2023-39959LOWExistence of calendars and address books can be checked by unauthenticated usersEPSS 0.6%CVE-2023-48304MEDIUMNextcloud Server vulnerable to attacker enabling/disabling birthday calendar for any userEPSS 0.6%CVE-2023-25818MEDIUMMissing brute force protection on password reset token in Nextcloud ServerEPSS 0.6%CVE-2023-45660MEDIUMRequire strict cookies for image proxy requests in Nextcloud MailEPSS 0.6%CVE-2022-41970LOWNextcloud Server's disabled download shares still allow download through preview imagesEPSS 0.6%CVE-2023-35171MEDIUMNextcloud Server vulnerable to open redirect on "Unsupported browser" warningEPSS 0.6%CVE-2017-0883Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue witEPSS 0.6%CVE-2024-52517MEDIUMNextcloud Server's global credentials of external storages are sent back to the frontendEPSS 0.6%CVE-2023-39955LOWNotes attachment render HTML in preview modeEPSS 0.6%CVE-2023-39961LOWText does not respect "Allow download" permissionsEPSS 0.6%CVE-2022-31024MEDIUMFederated editing allows iframing remote servers by default in richdocumentsEPSS 0.6%CVE-2022-39338LOWStored cross site scripting (XSS) vulnerability via Authorization Endpoint in user_oidcEPSS 0.6%CVE-2023-39960MEDIUMNextcloud Server has improper restriction of excessive authentication attempts on WebDAV endpointEPSS 0.6%CVE-2023-48302LOWNextcloud Server vulnerable to Self XSS when pasting HTML into Text app with Ctrl+Shift+VEPSS 0.6%CVE-2022-39212MEDIUMLast video frame is still sent after video is disabled in a call in Nextcloud TalkEPSS 0.6%