Vulnerabilidades em Nextcloud
297 resultadosAnálise Vexday
Nextcloud possui 20 vulnerabilidades registradas na base, todas de severidade moderada ou inferior, com destaque para falhas de Cross-Site Scripting (CWE-79). Nenhuma vulnerabilidade está sob ataque ativo conhecido, e não há publicações recentes nos últimos 90 dias, indicando um panorama de risco estável e sem pressão imediata.
CVE-2025-66551MEDIUMNextcloud Tables is missing an ownership check which allows moving columns into tables of other usersEPSS 0.3%CVE-2025-66556LOWNextcloud talk allows participants to blindly delete poll drafts of other users by IDEPSS 0.3%CVE-2026-45810MEDIUMNextcloud: Propfind requests for file comments allowed to load comments for other filesEPSS 0.3%CVE-2025-66554LOWNextcloud Contacts vulnerable to Stored XSS in contacts app via organisation and title fieldEPSS 0.3%CVE-2025-66514LOWNextcloud Mail stored HTML injection in subject textEPSS 0.3%CVE-2023-48305MEDIUMNextcloud Server user_ldap app logs user passwords in the log file on level debugEPSS 0.2%CVE-2026-77169MEDIUMA vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegEPSS 0.2%CVE-2024-37886MEDIUMNextcloud user_oidc's ID4me does not validate signature or expirationEPSS 0.2%CVE-2021-32801MEDIUMExceptions may have logged Encryption-at-Rest key content in Nextcloud serverEPSS 0.2%CVE-2023-25820MEDIUMNextcloud Server and Enterprise Server missing brute force protection on password confirmation modalEPSS 0.2%CVE-2026-45278LOWNextcloud: Open Redirect in user_oidc login flow via protocol-relative URL bypassEPSS 0.2%CVE-2026-45157MEDIUMNextcloud: Valid share tokens allow to access tempory upload files of share ownerEPSS 0.2%CVE-2023-28646MEDIUMApp lockout in nextcloud Android app can be bypassed via thirdparty appsEPSS 0.2%CVE-2026-45264MEDIUMNextcloud: ACL Rename Permission Bypass in Team Folders Allows Unauthorized File RenamesEPSS 0.2%CVE-2026-45544MEDIUMNextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewServiceEPSS 0.2%CVE-2026-45283MEDIUMNextcloud: Files Lock app allows users to lock and unlock files of other usersEPSS 0.2%CVE-2023-32318HIGHUser session not correctly destroyed on logoutEPSS 0.2%CVE-2026-82980MEDIUMAny authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves fEPSS 0.2%CVE-2022-39334LOWnextcloudcmd incorrectly trusts bad TLS certificatesEPSS 0.2%CVE-2023-22472MEDIUMNextcloud Deck Desktop Client is vulnerable to Cross-Site Request Forgery (CSRF) via malicious linkEPSS 0.2%