Vulnerabilidades em nextcloud

297 resultados
Análise Vexday

O ecossistema Nextcloud acumula 266 CVEs catalogadas, com volume de novas vulnerabilidades ainda ativo — 27 surgiram nos últimos 90 dias —, mas apresenta taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. O tipo de falha predominante é CWE-284 (controle de acesso inadequado), o que indica fragilidades estruturais na gestão de permissões que tendem a ampliar a superfície de ataque em ambientes colaborativos. A CVE mais relevante no momento é CVE-2022-24838, com escore EPSS de 0,3155 — o mais alto observado no conjunto —, sinalizando probabilidade não negligenciável de exploração e merecendo atenção prioritária em qualquer plano de remediação. A existência de 2 CVEs com PoC pública, combinada a 4 falhas críticas, reforça a necessidade de monitoramento contínuo mesmo em um cenário onde a exploração confirmada ainda é ausente.

CVE-2025-66511MEDIUMNextcloud Calendar app used predictable proposal participant tokensEPSS 0.3%CVE-2026-45282MEDIUMNextcloud: Logged-in user bypasses share password and download restrictions on Text attachments via documentId leads to unauthorized file accessEPSS 0.3%CVE-2026-45285MEDIUMNextcloud: Hidden Public Link creation when sharing to a Team External MemberEPSS 0.3%CVE-2026-45267MEDIUMNextcloud: Missing permission check for from submissionsEPSS 0.3%CVE-2026-45690MEDIUMNextcloud: Two-Factor Authentication Bypass via Pending Session Token ReplayEPSS 0.3%CVE-2026-45691MEDIUMNextcloud: Bypass of second factor authentication on DAV endpointsEPSS 0.3%CVE-2023-49790MEDIUMApp PIN code can be bypassed in Nextcloud Files iOSEPSS 0.3%CVE-2026-45281HIGHNextcloud: Cross-Account Calendar Takeover via Unauthorized Group-Member-Set UpdateEPSS 0.3%CVE-2025-66545LOWNextcloud Groupfolders users with read-only permissions for team folder can restore deleted files from trash binEPSS 0.3%CVE-2025-66512MEDIUMNextcloud Server vulnerable to XSS in SVG images when opened outside of NextcloudEPSS 0.3%CVE-2026-45286MEDIUMNextcloud: Calendar app leaked user identifiers via attendee suggestion endpointEPSS 0.3%CVE-2025-66547MEDIUMNextcloud Server users can modify tags on files that do not belong to themEPSS 0.3%CVE-2025-66557MEDIUMNextcloud Deck app allowed user with "Can share" permission to modify permissions of other non-ownersEPSS 0.3%CVE-2022-41926LOWNextcloud Talk Android broadcast incorrect permission handlingEPSS 0.3%CVE-2023-28647MEDIUMApp pin of the iOS app can be bypassed in Nextcloud iOSEPSS 0.3%CVE-2025-66558LOWNextcloud Twofactor WebAuthn app was updated based on public keyEPSS 0.3%CVE-2025-66553MEDIUMNextcloud Tables app allowed users to view columns metadata information of any tableEPSS 0.3%CVE-2023-39963HIGHMissing password confirmation when creating app passwordsEPSS 0.3%CVE-2026-45543MEDIUMNextcloud: Deleting a Forms collaborator share leaves uploaded response files accessible through a lingering Files shareEPSS 0.3%CVE-2026-77165MEDIUMFile owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of EPSS 0.3%