Vulnerabilidades em nextcloud

297 resultados
Análise Vexday

O ecossistema Nextcloud acumula 266 CVEs catalogadas, com volume de novas vulnerabilidades ainda ativo — 27 surgiram nos últimos 90 dias —, mas apresenta taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. O tipo de falha predominante é CWE-284 (controle de acesso inadequado), o que indica fragilidades estruturais na gestão de permissões que tendem a ampliar a superfície de ataque em ambientes colaborativos. A CVE mais relevante no momento é CVE-2022-24838, com escore EPSS de 0,3155 — o mais alto observado no conjunto —, sinalizando probabilidade não negligenciável de exploração e merecendo atenção prioritária em qualquer plano de remediação. A existência de 2 CVEs com PoC pública, combinada a 4 falhas críticas, reforça a necessidade de monitoramento contínuo mesmo em um cenário onde a exploração confirmada ainda é ausente.

CVE-2026-45159LOWNextcloud: Files drop share links for end-to-end encrypted folders allowed to drop files into other folders of the share ownerEPSS 0.2%CVE-2026-45266LOWNextcloud: Unauthorized force-mute from missing permission check when using internal signalingEPSS 0.2%CVE-2026-82985MEDIUMThe Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewiEPSS 0.2%CVE-2026-45155LOWNextcloud: Private circle can be added to another circle via APIEPSS 0.2%CVE-2026-45284MEDIUMNextcloud: Wrong condition in the User OIDC app's LdapService allowed deleted LDAP users to authenticateEPSS 0.2%CVE-2026-45154LOWNextcloud: Improper Access Control in CollectivesEPSS 0.2%CVE-2026-77166LOWThe emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebarEPSS 0.2%CVE-2026-82982MEDIUMThe Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from appEPSS 0.2%CVE-2026-44515LOWNextcloud News: Authenticated blind SSRF via feed URLEPSS 0.2%CVE-2025-47792MEDIUMNextcloud Desktop 3rdparty applications can create share links via socket APIEPSS 0.2%CVE-2025-66548LOWNextcloud Deck app allows to spoof file extensions by using RTLO charactersEPSS 0.2%CVE-2026-77170MEDIUMThe Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether theEPSS 0.2%CVE-2026-45153MEDIUMNextcloud: PIN bypass in PassCodeActivity via back buttonEPSS 0.2%CVE-2026-68493LOWAfter guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they arEPSS 0.1%CVE-2025-66546LOWNextcloud Calendar app allowed booking appointments without the generated tokenEPSS 0.1%CVE-2026-45277LOWNextcloud: Information disclosure in Nextcloud Approval app via fileId parameter reveals workflow associationsEPSS 0.1%CVE-2026-77164MEDIUMCircles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, EPSS 0.1%