Vulnerabilidades em nextcloud

297 resultados
Análise Vexday

O ecossistema Nextcloud acumula 266 CVEs catalogadas, com volume de novas vulnerabilidades ainda ativo — 27 surgiram nos últimos 90 dias —, mas apresenta taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. O tipo de falha predominante é CWE-284 (controle de acesso inadequado), o que indica fragilidades estruturais na gestão de permissões que tendem a ampliar a superfície de ataque em ambientes colaborativos. A CVE mais relevante no momento é CVE-2022-24838, com escore EPSS de 0,3155 — o mais alto observado no conjunto —, sinalizando probabilidade não negligenciável de exploração e merecendo atenção prioritária em qualquer plano de remediação. A existência de 2 CVEs com PoC pública, combinada a 4 falhas críticas, reforça a necessidade de monitoramento contínuo mesmo em um cenário onde a exploração confirmada ainda é ausente.

CVE-2025-47793MEDIUMNextcloud Server and Groupfolders app vulnerable to bypass of group folder quota limit using attachment in text fileEPSS 0.8%CVE-2021-39220LOWBypass of image blocking in Nextcloud MailEPSS 0.8%CVE-2022-31131MEDIUMOwnership check missing when updating or deleting mail attachments in Nextcloud mailEPSS 0.8%CVE-2023-28847LOWNextcloud Server missing brute force protection for passwords of password protected share linksEPSS 0.8%CVE-2023-28833LOWUnrestricted filenames for logo or favicon as admin in the theming settings in nextcloud serverEPSS 0.8%CVE-2024-22212CRITICALNextcloud global site selector authentication bypassEPSS 0.8%CVE-2017-0936Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownershiEPSS 0.8%CVE-2022-36074MEDIUMAuthentication headers exposed on by Nextcloud ServerEPSS 0.8%CVE-2023-28645MEDIUMSecure view can be bypassed by using internal API endpoint in Nextcloud richdocumentsEPSS 0.7%CVE-2018-3781A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2.5 could lead to a stored XSS requiring user-interaEPSS 0.7%CVE-2017-0890Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitablEPSS 0.7%CVE-2024-52510MEDIUMNextcloud Desktop client behaves incorrectly if the initial end-to-end-encryption signature is emptyEPSS 0.7%CVE-2023-25150MEDIUMDocument content of files can be obtained through Collabora for files of other usersEPSS 0.7%CVE-2021-32727MEDIUMEnd-to-end encryption device setup did not verify public keyEPSS 0.7%CVE-2022-31118MEDIUMMissing brute force protection on cloud federation sharing in Nextcloud ServerEPSS 0.7%CVE-2023-25161LOWNextcloud Server's missing rate limiting on password reset functionality allows sending lots of emailsEPSS 0.7%CVE-2017-0895Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note thatEPSS 0.7%CVE-2023-39958MEDIUMMissing brute force protection on password reset token OAuth2 API controllerEPSS 0.7%CVE-2024-52508HIGHNextcloud Mail auto configurator can be tricked into sending account information to wrong serversEPSS 0.7%CVE-2021-29438MEDIUMImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in @nextcloud/dialogsEPSS 0.7%