Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.66% | — | Nextcloud Deck | 14/1/2023 | 17/6/2026 | Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A database error can be generated potentially causing a DoS when performed multiple times. There are currently no known workarounds. It is recommended that the Nextcloud Server is… | |
| Modificada | Baja (3.5) | 0.69% | — | Nextcloud Deck | 10/1/2023 | 17/6/2026 | Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. When getting the reference preview for Deck cards the user has no access to, unauthorized user could eventually get the cached data of a user that has access. There are currently no known… | |
| Modificada | Baja (2.1) | 0.56% | — | Nextcloud Talk | 9/1/2023 | 17/6/2026 | Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the user's Nextcloud files and view conversations. To exploit this the attacker needs to have physical access to the target's device. There are currently no known workarounds… | |
| Modificada | Alta (8.8) | 0.20% | — | Nextcloud Desktop | 9/1/2023 | 17/6/2026 | Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. It is possible to make a user send any POST request with an arbitrary body given they click on a malicious deep link on a Windows computer. (e.g. in an email, chat link, etc). There are… | |
| Modificada | Crítica (9.8) | 1.0% | — | Getcloudsms JOY OF Text Lite | 2/1/2023 | 17/6/2026 | The Joy Of Text Lite WordPress plugin before 2.3.1 does not properly sanitise and escape some parameters before using them in SQL statements accessible to unauthenticated users, leading to unauthenticated SQL injection | |
| Modificada | Media (6.5) | 0.82% | — | Nextcloud Talk | 1/12/2022 | 17/6/2026 | Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, and 15.0.0, guests can continue to receive video streams from a call after being removed from a conversation. An attacker would be able to see videos on a call in a public conversation after being… | |
| Modificada | Media (5.3) | 0.65% | — | Nextcloud Server | 1/12/2022 | 17/6/2026 | Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through preview images. Images could be downloaded and previews of documents (first page) can be downloaded without being watermarked. Versions 24.0.7 and 25.0.1 contain a fix… | |
| Modificada | Baja (2.7) | 0.87% | — | Nextcloud Server | 1/12/2022 | 17/6/2026 | Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.11, 24.0.7, and 25.0.0, there is no password length limit when creating a user as an administrator. An administrator can cause a limited DoS attack against their own server. Versions 23.0.11, 24.0.7, and 25.0.0 contain a fix for the… | |
| Modificada | Media (5.3) | 0.92% | — | Nextcloud Server | 1/12/2022 | 17/6/2026 | Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths are not validated before writing to a database. As a result, an attacker can send unnecessary amounts of data against the database. Version 23.0.10 and 24.0.5 contain patches for the issue. No known… | |
| Modificada | Media (6.1) | 0.94% | — | Nextcloud Desktop | 25/11/2022 | 17/6/2026 | Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue. | |
| Modificada | Media (5.4) | 0.98% | — | Nextcloud Desktop | 25/11/2022 | 17/6/2026 | Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application via user status and information. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue. | |
| Modificada | Media (5.5) | 0.28% | — | Nextcloud Talk | 25/11/2022 | 17/6/2026 | Nextcould talk android is the android OS implementation of the nextcloud talk chat system. In affected versions the receiver is not protected by broadcastPermission allowing malicious apps to monitor communication. It is recommended that the Nextcloud Talk Android is upgraded to 14.1.0. There are no known workarounds… | |
| Modificada | Media (6.5) | 1.1% | — | Nextcloud Enterprise ServerNextcloud ServerFedoraproject Fedora | 25/11/2022 | 17/6/2026 | Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a denial of service. It is recommended that the Nextcloud Server is upgraded to 22.2.10, 23.0.7 or… | |
| Modificada | Media (4.3) | 0.46% | — | Nextcloud Openid Connect User Backend | 25/11/2022 | 17/6/2026 | user_oidc is an OpenID Connect user backend for Nextcloud. In versions prior to 1.2.1 sensitive information such as the OIDC client credentials and tokens are sent in plain text of HTTP without TLS. Any malicious actor with access to monitor user traffic may have been able to compromise account security. This issue… | |
| Modificada | Media (5.4) | 0.63% | — | Nextcloud Openid Connect User Backend | 25/11/2022 | 17/6/2026 | user_oidc is an OpenID Connect user backend for Nextcloud. Versions prior to 1.2.1 did not properly validate discovery urls which may lead to a stored cross site scripting attack vector. The impact is limited due to the restrictive CSP that is applied on this endpoint. Additionally this vulnerability has only been… | |
| Modificada | Media (4.7) | 0.21% | — | Nextcloud Desktop | 25/11/2022 | 17/6/2026 | Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless servers. Versions of nextcloudcmd prior to 3.6.1 would incorrectly trust invalid TLS certificates, which may enable a Man-in-the-middle attack that exposes sensitive data or credentials to a network… | |
| Modificada | Media (5.4) | 0.96% | — | Nextcloud Desktop | 25/11/2022 | 17/6/2026 | Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application in the notifications. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue. | |
| Modificada | Alta (7.8) | 0.49% | — | Nextcloud Desktop | 11/11/2022 | 17/6/2026 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. In version 3.6.0, if a user received a malicious file share and has it synced locally or the virtual filesystem enabled and clicked a nc://open/ link it will open the default editor for the file type of the shared… | |
| Modificada | Media (6.5) | 0.50% | — | Nextcloud Enterprise ServerNextcloud Server | 27/10/2022 | 17/6/2026 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server prior to versions 23.0.9 and 24.0.5 and Nextcloud Enterprise Server prior to versions 22.2.10.5, 23.0.9, and 24.0.5 an attacker reading `nextcloud.log` may gain knowledge of credentials to connect to a… | |
| Modificada | Media (4.3) | 0.91% | — | Nextcloud Enterprise ServerNextcloud Server | 27/10/2022 | 17/6/2026 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior to versions 23.0.10 and 24.0.6 and Nextcloud Enterprise Server prior to versions 22.2.10, 23.0.10, and 24.0.6 are vulnerable to a logged-in attacker slowing down the system by generating a lot of… | |
| Modificada | Media (5.3) | 0.67% | — | Nextcloud Enterprise ServerNextcloud Server | 27/10/2022 | 17/6/2026 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without direct database access. Versions 23.0.9 and… | |
| Modificada | Media (5.4) | 0.61% | — | Dgiotcloud Dgiot | 29/9/2022 | 17/6/2026 | DGIOT Lightweight industrial IoT v4.5.4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities. | |
| Modificada | Media (5.3) | 0.68% | — | Nextcloud Talk | 17/9/2022 | 17/6/2026 | Nextcloud Talk is an open source chat, video & audio calls client for the Nextcloud platform. In affected versions an attacker could see the last video frame of any participant who has video disabled but a camera selected. It is recommended that the Nextcloud Talk app is upgraded to 13.0.8 or 14.0.4. Users unable to… | |
| Modificada | Media (5.5) | 0.31% | — | Nextcloud | 17/9/2022 | 17/6/2026 | Nextcloud android is the official Android client for the Nextcloud home server platform. Internal paths to the Nextcloud Android app files are not properly protected. As a result access to internal files of the from within the Nextcloud Android app is possible. This may lead to a leak of sensitive information in some… | |
| Modificada | Media (5.3) | 0.96% | — | Nextcloud Enterprise ServerNextcloud Server | 16/9/2022 | 17/6/2026 | Nextcloud server is an open source personal cloud platform. In affected versions it was found that locally running webservices can be found and requested erroneously. It is recommended that the Nextcloud Server is upgraded to 23.0.8 or 24.0.4. It is recommended that the Nextcloud Enterprise Server is upgraded to… |