Vulnerabilidades em NextCloud

288 resultados
Análise Vexday

Nextcloud apresenta apenas 2 vulnerabilidades catalogadas na base, nenhuma em ataque ativo (KEV) e nenhuma crítica. A fraqueza dominante é injeção de conteúdo (CWE-79), típica de falhas de validação em interfaces web. Com nenhuma publicação nos últimos 90 dias, o perfil de risco atual é baixo, embora demande atenção contínua em validação de entrada para contextos de rendering.

CVE-2023-25817LOWDelete permissions are not saved when creating public share in Nextcloud serverEPSS 0.6%CVE-2023-22473LOWPasscode bypass on Talk-Android appEPSS 0.6%CVE-2023-48308LOWCalendar app returns full stacktrace when an error happens while editing appointmentEPSS 0.5%CVE-2023-39953MEDIUMIssuer not verified from obtained token in user_oidcEPSS 0.5%CVE-2023-28835LOWInsecure randomness for default password in nextcloudEPSS 0.5%CVE-2024-37882HIGHNextcloud Server can reshare read&share only folder with more permissionsEPSS 0.5%CVE-2024-52518MEDIUMNextcloud Server is missing password confirmation when changing external storage optionsEPSS 0.5%CVE-2023-33184LOWBlind SSRF in the Nextcloud Mail app on avatar endpointEPSS 0.5%CVE-2023-22471LOWNextcloud Deck vulnerable to authorization bypassEPSS 0.5%CVE-2024-22404MEDIUMPermissions bypass in Nextcloud with the files zip appEPSS 0.5%CVE-2024-52513LOWNextcloud Server's Attachments folder for Text app is accessible on "Files drop" and "Password protected" sharesEPSS 0.5%CVE-2024-22402MEDIUMImproper handling of request URLs in Nextcloud Guests app allows guest users to bypass app allowlistEPSS 0.5%CVE-2023-25579MEDIUMDirectory traversal in Nextcloud serverEPSS 0.5%CVE-2024-22213NONECross-site Scripting when sending HTML as a comment in the Nextcloud Deck appEPSS 0.5%CVE-2021-39221MEDIUMXSS in ContactsEPSS 0.5%CVE-2024-52509LOWNextcloud Mail app does not respect download permissions in sharesEPSS 0.5%CVE-2025-58051MEDIUMNextcloud Tables app allowed to include local file via PhpSpreadsheet when importing a tableEPSS 0.5%CVE-2023-35173MEDIUMEnd-to-End encrypted file-drops can be made inaccessibleEPSS 0.5%CVE-2024-52519LOWNextcloud Server's OAuth2 client secrets were stored in a recoverable wayEPSS 0.5%CVE-2023-45151MEDIUMOAuth2 client_secret stored in plain text in the Nextcloud databaseEPSS 0.5%