Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.2% | — | Nextcloud Server | 25/10/2021 | 17/6/2026 | Nextcloud is an open-source, self-hosted productivity platform. Prior to Nextcloud Server versions 20.0.13, 21.0.5, and 22.2.0, the Two-Factor Authentication wasn't enforced for pages marked as public. Any page marked as `@PublicPage` could thus be accessed with a valid user session that isn't authenticated. This… | |
| Modificada | Media (6.5) | 1.8% | — | Nextcloud Server | 25/10/2021 | 17/6/2026 | Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file traversal vulnerability makes an attacker able to download arbitrary SVG images from the host system, including user provided files. This could also be leveraged into a XSS/phishing attack, an attacker… | |
| Modificada | Alta (8.1) | 1.6% | — | Nextcloud Server | 25/10/2021 | 17/6/2026 | Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, Nextcloud Server did not implement a database backend for rate-limiting purposes. Any component of Nextcloud using rate-limits (as as `AnonRateThrottle` or `UserRateThrottle`) was thus not rate limited on… | |
| Modificada | Alta (8.1) | 1.3% | — | Nextcloud Deck | 25/10/2021 | 17/6/2026 | Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows another authenticated users to access Deck cards of another user. It is recommended that the Nextcloud Deck App is upgraded to 1.2.9, 1.4.5 or 1.5.3. There are no known… | |
| Modificada | Media (5.3) | 0.88% | — | Nextcloud Officeonline | 25/10/2021 | 17/6/2026 | Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud OfficeOnline application prior to version 1.1.1 returned verbatim exception messages to the user. This could result in a full path disclosure on shared files. (e.g. an attacker could see that the file `shared.txt` is located within… | |
| Modificada | Media (5.3) | 1.1% | — | Nextcloud Richdocuments | 25/10/2021 | 17/6/2026 | Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Richdocuments application prior to versions 3.8.6 and 4.2.3 returned verbatim exception messages to the user. This could result in a full path disclosure on shared files. (e.g. an attacker could see that the file `shared.txt` is located… | |
| Modificada | Media (5.4) | 0.52% | — | Nextcloud Contacts | 25/10/2021 | 17/6/2026 | Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Contacts application prior to version 4.0.3 was vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, a user would need to right-click on a malicious file and open the file in a new tab. Due the strict… | |
| Modificada | Baja (3.5) | 0.78% | — | Nextcloud Mail | 25/10/2021 | 17/6/2026 | Nextcloud is an open-source, self-hosted productivity platform The Nextcloud Mail application prior to versions 1.10.4 and 1.11.0 does by default not render images in emails to not leak the read state or user IP. The privacy filter failed to filter images with a relative protocol. It is recommended that the Nextcloud… | |
| Modificada | Crítica (9.8) | 2.0% | 💥 PoC | Ptcl Hg150-ub Firmware | 4/10/2021 | 17/6/2026 | An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via modification of the cookie value and Response Path. | |
| Modificada | Crítica (9.8) | 2.6% | — | Nextcloud Server | 7/9/2021 | 17/6/2026 | Nextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user provided file content. For some image types, the Nextcloud server was invoking a third-party library that wasn't suited for untrusted user-supplied content. There are several security concerns with… | |
| Modificada | Media (5.5) | 0.24% | — | Nextcloud Server | 7/9/2021 | 17/6/2026 | Nextcloud server is an open source, self hosted personal cloud. In affected versions logging of exceptions may have resulted in logging potentially sensitive key material for the Nextcloud Encryption-at-Rest functionality. It is recommended that the Nextcloud Server is upgraded to 20.0.12, 21.0.4 or 22.1.0. If… | |
| Modificada | Alta (8.1) | 1.8% | — | Nextcloud Server | 7/9/2021 | 17/6/2026 | Nextcloud server is an open source, self hosted personal cloud. In affected versions an attacker is able to bypass Two Factor Authentication in Nextcloud. Thus knowledge of a password, or access to a WebAuthN trusted device of a user was sufficient to gain access to an account. It is recommended that the Nextcloud… | |
| Modificada | Media (5.3) | 1.4% | — | Nextcloud Richdocuments | 7/9/2021 | 17/6/2026 | Nextcloud Richdocuments is an open source collaborative office suite. In affected versions there is a lack of rate limiting on the Richdocuments OCS endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. It is recommended that the Nextcloud Richdocuments app is upgraded to either… | |
| Modificada | Alta (7.5) | 2.1% | — | Nextcloud Richdocuments | 7/9/2021 | 17/6/2026 | Nextcloud Richdocuments is an open source collaborative office suite. In affected versions the File Drop features ("Upload Only" public link shares in Nextcloud) can be bypassed using the Nextcloud Richdocuments app. An attacker was able to read arbitrary files in such a share. It is recommended that the Nextcloud… | |
| Modificada | Media (5.3) | 1.3% | — | Nextcloud Server | 7/9/2021 | 17/6/2026 | Nextcloud Text is an open source plaintext editing application which ships with the nextcloud server. In affected versions the Nextcloud Text application returned different error messages depending on whether a folder existed in a public link share. This is problematic in case the public link share has been created… | |
| Modificada | Media (6.5) | 1.3% | — | Nextcloud Deck | 7/9/2021 | 17/6/2026 | Deck is an open source kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions the Deck application didn't properly check membership of users in a Circle. This allowed other users in the instance to gain access to boards that have… | |
| Modificada | Media (6.5) | 1.2% | — | Nextcloud Circles | 7/9/2021 | 17/6/2026 | Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application allowed any user to join any "Secret Circle" without approval by the Circle owner leaking private information. It is recommended that Nextcloud Circles is upgraded to 0.19.15,… | |
| Modificada | Media (5.4) | 0.83% | — | Nextcloud Circles | 7/9/2021 | 17/6/2026 | Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. Due the strict Content-Security-Policy shipped with Nextcloud, this issue is not exploitable on modern… | |
| Modificada | Alta (7.3) | 0.46% | — | Nextcloud Desktop | 18/8/2021 | 17/6/2026 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop Client invokes its uninstaller script when being installed to make sure there are no remnants of previous installations. In versions 3.0.3 through 3.2.4, the Client searches the `Uninstall.exe` file… | |
| Modificada | Media (6.5) | 0.85% | — | Nextcloud DesktopDebian Linux | 18/8/2021 | 17/6/2026 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. Clients using the Nextcloud end-to-end encryption feature download the public and private key via an API endpoint. In versions prior to 3.3.0, the Nextcloud Desktop client fails to check if a private key belongs to… | |
| Modificada | Media (4.3) | 0.99% | — | Nextcloud Richdocuments | 27/7/2021 | 17/6/2026 | Nextcloud Richdocuments in an open source self hosted online office. Nextcloud uses the WOPI ("Web Application Open Platform Interface") protocol to communicate with the Collabora Editor, the communication between these two services was not protected by a credentials or IP check. Whilst this does not result in gaining… | |
| Modificada | Media (5.3) | 1.3% | — | Nextcloud Server | 12/7/2021 | 17/6/2026 | Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public share link mount endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. The issue was fixed in versions 19.0.13, 20.0.11,… | |
| Modificada | Media (5.3) | 1.4% | — | Nextcloud Server | 12/7/2021 | 17/6/2026 | Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the Nextcloud Text application shipped with Nextcloud Server returned verbatim exception messages to the user. This could result in a full path disclosure on shared files. The issue was fixed in… | |
| Modificada | Media (6.1) | 1.1% | — | Nextcloud Server | 12/7/2021 | 17/6/2026 | Nextcloud Text is a collaborative document editing application that uses Markdown. A cross-site scripting vulnerability is present in versions prior to 19.0.13, 20.0.11, and 21.0.3. The Nextcloud Text application shipped with Nextcloud server used a `text/html` Content-Type when serving files to users. Due the strict… | |
| Modificada | Alta (7.5) | 0.73% | — | Nextcloud | 12/7/2021 | 17/6/2026 | Nextcloud Android Client is the Android client for Nextcloud. Clients using the Nextcloud end-to-end encryption feature download the public and private key via an API endpoint. In versions prior to 3.16.1, the Nextcloud Android client skipped a step that involved the client checking if a private key belonged to a… |