Vulnerabilidades em Nextcloud

297 resultados
Análise Vexday

Nextcloud possui 20 vulnerabilidades registradas na base, todas de severidade moderada ou inferior, com destaque para falhas de Cross-Site Scripting (CWE-79). Nenhuma vulnerabilidade está sob ataque ativo conhecido, e não há publicações recentes nos últimos 90 dias, indicando um panorama de risco estável e sem pressão imediata.

CVE-2023-32320HIGHNextcloud Server's brute force protection allows someone to send more requests than intendedEPSS 0.9%CVE-2023-48307LOWNextcloud Mail app vulnerable to Server-Side Request ForgeryEPSS 0.9%CVE-2022-31120LOWFederated share accepting/declining is not logged in audit log in Nextcloud ServerEPSS 0.9%CVE-2023-32074HIGHNextcloud user_oidc app is missing brute force protectionEPSS 0.9%CVE-2021-32728MEDIUMEnd-to-end encryption device setup did not verify public keyEPSS 0.9%CVE-2021-41241MEDIUMAdvanced permissions is not respected for subfolders in Nextcloud serverEPSS 0.9%CVE-2023-33182NONENextcloud Contacts photos only sanitized if mime type is all lower caseEPSS 0.8%CVE-2022-41969LOWNextcloud Server has no password length limit when creating a user as an administratorEPSS 0.8%CVE-2021-32782MEDIUMCross-Site Scripting in Nextcloud CirclesEPSS 0.8%CVE-2023-25162MEDIUMNextcloud Server vulnerable to SSRF via filter bypass due to lax checking on IPsEPSS 0.8%CVE-2023-28834LOWFull path of data directory exposed to Nextcloud server usersEPSS 0.8%CVE-2023-39952MEDIUMAdvanced permissions not respected when copying entire group foldersEPSS 0.8%CVE-2023-35927HIGHNextcloud system addressbooks can be modified by malicious trusted serverEPSS 0.8%CVE-2023-26041LOWNextcloud Talk messages can still be seen on conversation after expiring when cron is misconfiguredEPSS 0.8%CVE-2023-48306MEDIUMNextcloud Server DNS pin middleware can be tricked into DNS rebinding allowing SSRFEPSS 0.8%CVE-2023-28643MEDIUMPotential share collision for recipients when caching is enabled in nextcloud serverEPSS 0.8%CVE-2022-41971MEDIUMNextcloud Talk guests can continue to receive video streams from call after being removed from a conversationEPSS 0.8%CVE-2022-31119LOWPassword disclosure in log file in Nextcloud Mail AppEPSS 0.8%CVE-2024-52520MEDIUMNextcloud Server's link reference provider can be tricked into downloading bigger files than intendedEPSS 0.8%CVE-2021-41233MEDIUMMissing authorization in Nextcloud textEPSS 0.8%