Vulnerabilidades em nextcloud

297 resultados
Análise Vexday

O ecossistema Nextcloud acumula 266 CVEs catalogadas, com volume de novas vulnerabilidades ainda ativo — 27 surgiram nos últimos 90 dias —, mas apresenta taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. O tipo de falha predominante é CWE-284 (controle de acesso inadequado), o que indica fragilidades estruturais na gestão de permissões que tendem a ampliar a superfície de ataque em ambientes colaborativos. A CVE mais relevante no momento é CVE-2022-24838, com escore EPSS de 0,3155 — o mais alto observado no conjunto —, sinalizando probabilidade não negligenciável de exploração e merecendo atenção prioritária em qualquer plano de remediação. A existência de 2 CVEs com PoC pública, combinada a 4 falhas críticas, reforça a necessidade de monitoramento contínuo mesmo em um cenário onde a exploração confirmada ainda é ausente.

CVE-2023-32320HIGHNextcloud Server's brute force protection allows someone to send more requests than intendedEPSS 0.9%CVE-2023-48307LOWNextcloud Mail app vulnerable to Server-Side Request ForgeryEPSS 0.9%CVE-2022-31120LOWFederated share accepting/declining is not logged in audit log in Nextcloud ServerEPSS 0.9%CVE-2023-32074HIGHNextcloud user_oidc app is missing brute force protectionEPSS 0.9%CVE-2021-32728MEDIUMEnd-to-end encryption device setup did not verify public keyEPSS 0.9%CVE-2021-41241MEDIUMAdvanced permissions is not respected for subfolders in Nextcloud serverEPSS 0.9%CVE-2023-33182NONENextcloud Contacts photos only sanitized if mime type is all lower caseEPSS 0.8%CVE-2022-41969LOWNextcloud Server has no password length limit when creating a user as an administratorEPSS 0.8%CVE-2021-32782MEDIUMCross-Site Scripting in Nextcloud CirclesEPSS 0.8%CVE-2023-25162MEDIUMNextcloud Server vulnerable to SSRF via filter bypass due to lax checking on IPsEPSS 0.8%CVE-2023-28834LOWFull path of data directory exposed to Nextcloud server usersEPSS 0.8%CVE-2023-39952MEDIUMAdvanced permissions not respected when copying entire group foldersEPSS 0.8%CVE-2023-35927HIGHNextcloud system addressbooks can be modified by malicious trusted serverEPSS 0.8%CVE-2023-26041LOWNextcloud Talk messages can still be seen on conversation after expiring when cron is misconfiguredEPSS 0.8%CVE-2023-48306MEDIUMNextcloud Server DNS pin middleware can be tricked into DNS rebinding allowing SSRFEPSS 0.8%CVE-2023-28643MEDIUMPotential share collision for recipients when caching is enabled in nextcloud serverEPSS 0.8%CVE-2022-41971MEDIUMNextcloud Talk guests can continue to receive video streams from call after being removed from a conversationEPSS 0.8%CVE-2022-31119LOWPassword disclosure in log file in Nextcloud Mail AppEPSS 0.8%CVE-2024-52520MEDIUMNextcloud Server's link reference provider can be tricked into downloading bigger files than intendedEPSS 0.8%CVE-2021-41233MEDIUMMissing authorization in Nextcloud textEPSS 0.8%