Vulnerabilidades em nextcloud

297 resultados
Análise Vexday

O ecossistema Nextcloud acumula 266 CVEs catalogadas, com volume de novas vulnerabilidades ainda ativo — 27 surgiram nos últimos 90 dias —, mas apresenta taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. O tipo de falha predominante é CWE-284 (controle de acesso inadequado), o que indica fragilidades estruturais na gestão de permissões que tendem a ampliar a superfície de ataque em ambientes colaborativos. A CVE mais relevante no momento é CVE-2022-24838, com escore EPSS de 0,3155 — o mais alto observado no conjunto —, sinalizando probabilidade não negligenciável de exploração e merecendo atenção prioritária em qualquer plano de remediação. A existência de 2 CVEs com PoC pública, combinada a 4 falhas críticas, reforça a necessidade de monitoramento contínuo mesmo em um cenário onde a exploração confirmada ainda é ausente.

CVE-2022-29160LOWSensitive files/data exist after deletion of user account in Nextcloud AndroidEPSS 0.4%CVE-2024-37316MEDIUMNextcloud Calendar's event create can create attachments that link to other websitesEPSS 0.4%CVE-2026-45275MEDIUMNextcloud: Authorization bypass in approval feature allows unauthorized file sharing with approversEPSS 0.4%CVE-2025-66510MEDIUMNextcloud Server Contacts Search allowed users to retrieve contact information of other users beyond their contact listEPSS 0.4%CVE-2021-32680LOWAudit log is not properly logging unsetting of share expiration dateEPSS 0.4%CVE-2024-52525LOWNextcloud Server User password is available in memory of the PHP processEPSS 0.3%CVE-2025-66550MEDIUMNextcloud Calendar attachments of local files are offered to downloadedEPSS 0.3%CVE-2023-28848MEDIUMCSRF protection on user_oidc login returned the expected token in case of an errorEPSS 0.3%CVE-2024-37885LOWCode injection in Nextcloud Desktop Client for macOSEPSS 0.3%CVE-2026-45545HIGHNextcloud: SQL Injection in Column Type Parameter Allows Arbitrary SQL ExecutionEPSS 0.3%CVE-2025-66515LOWNextcloud Approval app allows users to request approval for other users fileEPSS 0.3%CVE-2024-37317MEDIUMNextcloud Notes app can be tricked into using a received share created before the user logged inEPSS 0.3%CVE-2022-39210LOWAccess to internal files of the Nextcloud Android appEPSS 0.3%CVE-2025-66552MEDIUMNextcloud Server admin_audit does not log all actions on files in groupfoldersEPSS 0.3%CVE-2021-41181LOWNextcloud Talk app exposes chat messages on lockscreenEPSS 0.3%CVE-2021-32658MEDIUMSensitive data may not be removed from storage on account removalEPSS 0.3%CVE-2025-59788MEDIUMCross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0EPSS 0.3%CVE-2026-45722HIGHNextcloud: Tables app allows limited SQLi in ORDER BY with malicious sort order argument for Table ViewsEPSS 0.3%CVE-2025-66549LOWNextcloud Desktop discloses information when attempting to lock a file inside a end-to-end encrypted directoryEPSS 0.3%CVE-2025-66513MEDIUMNextcloud Tables app share information not limited to relevant usersEPSS 0.3%