Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

644 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.2)0.37%—Nextcloud Server2/11/202017/6/2026
A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.
ModificadaMedia (4.3)0.78%—Nextcloud Deck5/10/202017/6/2026
Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.
ModificadaMedia (5.3)1.9%—Nextcloud Preferred ProvidersOpensuse Backports SLEOpensuse Leap5/10/202017/6/2026
A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.
ModificadaMedia (6.5)1.5%—Nextcloud ServerFedoraproject Fedora5/10/202017/6/2026
A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves.
ModificadaAlta (8)1.0%—Nextcloud Deck5/10/202017/6/2026
Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves.
ModificadaAlta (7.5)0.91%—Nextcloud Desktop18/9/202017/6/2026
A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.
ModificadaMedia (6.8)26%—Nextcloud Desktop21/8/202017/6/2026
Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.
ModificadaMedia (5.4)1.4%—Nextcloud Desktop21/8/202017/6/2026
A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.
ModificadaMedia (5.5)0.35%—Nextcloud Desktop17/8/202017/6/2026
A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory.
ModificadaMedia (5.5)0.47%—Nextcloud Desktop10/8/202017/6/2026
A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system.
ModificadaAlta (7.8)0.66%—Nextcloud Desktop10/8/202017/6/2026
A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory.
ModificadaMedia (5.3)1.3%—Nextcloud Preferred Providers30/7/202017/6/2026
Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when using a very long password.
ModificadaMedia (4.3)0.79%—Nextcloud Contacts10/7/202017/6/2026
A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.
ModificadaMedia (4.1)0.64%—Nextcloud Deck2/7/202017/6/2026
Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.
ModificadaCrítica (9.9)1.7%—Nextcloud Talk8/6/202017/6/2026
A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator.
ModificadaMedia (5.5)0.34%—Targetcli-fb Project Targetcli-fbFedoraproject Fedora5/6/202017/6/2026
Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files).
ModificadaAlta (7)0.96%—Nextcloud MailFedoraproject Fedora12/5/202017/6/2026
A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.
ModificadaMedia (5.4)1.1%—Nextcloud Server12/5/202017/6/2026
An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerability when opening a malicious PDF.
ModificadaAlta (7.7)1.8%—Nextcloud Server12/5/202017/6/2026
An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.
ModificadaAlta (8.1)1.9%—Nextcloud Group FoldersFedoraproject Fedora12/5/202017/6/2026
Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name.
ModificadaAlta (7.8)0.35%—Targetcli-fb Project Targetcli-fb15/4/202017/6/2026
A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the socket used by targetclid was world-writable. If a system enables the targetclid socket, a local attacker can use this flaw to modify the iSCSI configuration and escalate their privileges to root.
ModificadaMedia (6.7)0.69%—Nextcloud Desktop20/3/202017/6/2026
A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the environment.
ModificadaMedia (6.5)1.5%—Nextcloud ServerFedoraproject Fedora20/3/202017/6/2026
A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.
ModificadaMedia (6.5)1.4%—Nextcloud Server20/3/202017/6/2026
A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.
ModificadaAlta (7.5)1.2%—Smartclient23/2/202017/6/2026
An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL allows an unauthenticated attacker to overwrite files via vectors involving an XML comment and /.. path traversal.