Vulnerabilidades em nextcloud

297 resultados
Análise Vexday

O ecossistema Nextcloud acumula 266 CVEs catalogadas, com volume de novas vulnerabilidades ainda ativo — 27 surgiram nos últimos 90 dias —, mas apresenta taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. O tipo de falha predominante é CWE-284 (controle de acesso inadequado), o que indica fragilidades estruturais na gestão de permissões que tendem a ampliar a superfície de ataque em ambientes colaborativos. A CVE mais relevante no momento é CVE-2022-24838, com escore EPSS de 0,3155 — o mais alto observado no conjunto —, sinalizando probabilidade não negligenciável de exploração e merecendo atenção prioritária em qualquer plano de remediação. A existência de 2 CVEs com PoC pública, combinada a 4 falhas críticas, reforça a necessidade de monitoramento contínuo mesmo em um cenário onde a exploração confirmada ainda é ausente.

CVE-2022-39211LOWServer-Side Request Forgery (SSRF) via potential filter bypass in Nextcloud ServerEPSS 1.0%CVE-2021-32676MEDIUMSession Fixation in Nextcloud TalkEPSS 1.0%CVE-2023-48239HIGHNextcloud Server users can make external storage mount points inaccessible for other usersEPSS 0.9%CVE-2021-41166MEDIUMPermission bypass in Nextcloud Android AppEPSS 0.9%CVE-2023-25821MEDIUMNextcloud download permissions can be changed by resharerEPSS 0.9%CVE-2022-39332MEDIUMCross-site scripting (XSS) in Nextcloud Desktop Client EPSS 0.9%CVE-2022-39333MEDIUMCross-site scripting (XSS) in Nextcloud Desktop ClientEPSS 0.9%CVE-2022-24887MEDIUMOpen Redirect in Nextcloud TalkEPSS 0.9%CVE-2022-24890LOWExposure of Private Personal Information to an Unauthorized Actor in Nextcloud TalkEPSS 0.9%CVE-2022-39331MEDIUMCross-site Scripting (XSS) in Nexcloud Desktop ClientEPSS 0.9%CVE-2023-23943MEDIUMBlind SSRF via server URL input in the Nextcloud Mail appEPSS 0.9%CVE-2023-35172HIGHNextcloud Server password reset endpoint is not brute force protectedEPSS 0.9%CVE-2017-0885Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in EPSS 0.9%CVE-2022-39330MEDIUMDatabase resource exhaustion for logged-in users via sharee recommendations with circlesEPSS 0.9%CVE-2017-0887Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by tEPSS 0.9%CVE-2018-3762Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still rEPSS 0.9%CVE-2018-3780A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-intEPSS 0.9%CVE-2022-41968LOWNextcloud Server's calendar name length not validated before writing to databaseEPSS 0.9%CVE-2021-32695LOWMalicious Android app could access Shared Preferences of the Nextcloud Android clientEPSS 0.9%CVE-2021-39224LOWFile path disclosure of shared files in OfficeOnline applicationEPSS 0.9%