Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.2) | 0.37% | — | Nextcloud Server | 2/11/2020 | 17/6/2026 | A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended. | |
| Modificada | Media (4.3) | 0.78% | — | Nextcloud Deck | 5/10/2020 | 17/6/2026 | Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments. | |
| Modificada | Media (5.3) | 1.9% | — | Nextcloud Preferred ProvidersOpensuse Backports SLEOpensuse Leap | 5/10/2020 | 17/6/2026 | A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times. | |
| Modificada | Media (6.5) | 1.5% | — | Nextcloud ServerFedoraproject Fedora | 5/10/2020 | 17/6/2026 | A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves. | |
| Modificada | Alta (8) | 1.0% | — | Nextcloud Deck | 5/10/2020 | 17/6/2026 | Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves. | |
| Modificada | Alta (7.5) | 0.91% | — | Nextcloud Desktop | 18/9/2020 | 17/6/2026 | A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials. | |
| Modificada | Media (6.8) | 26% | — | Nextcloud Desktop | 21/8/2020 | 17/6/2026 | Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory. | |
| Modificada | Media (5.4) | 1.4% | — | Nextcloud Desktop | 21/8/2020 | 17/6/2026 | A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt. | |
| Modificada | Media (5.5) | 0.35% | — | Nextcloud Desktop | 17/8/2020 | 17/6/2026 | A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory. | |
| Modificada | Media (5.5) | 0.47% | — | Nextcloud Desktop | 10/8/2020 | 17/6/2026 | A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system. | |
| Modificada | Alta (7.8) | 0.66% | — | Nextcloud Desktop | 10/8/2020 | 17/6/2026 | A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory. | |
| Modificada | Media (5.3) | 1.3% | — | Nextcloud Preferred Providers | 30/7/2020 | 17/6/2026 | Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when using a very long password. | |
| Modificada | Media (4.3) | 0.79% | — | Nextcloud Contacts | 10/7/2020 | 17/6/2026 | A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars. | |
| Modificada | Media (4.1) | 0.64% | — | Nextcloud Deck | 2/7/2020 | 17/6/2026 | Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks. | |
| Modificada | Crítica (9.9) | 1.7% | — | Nextcloud Talk | 8/6/2020 | 17/6/2026 | A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator. | |
| Modificada | Media (5.5) | 0.34% | — | Targetcli-fb Project Targetcli-fbFedoraproject Fedora | 5/6/2020 | 17/6/2026 | Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files). | |
| Modificada | Alta (7) | 0.96% | — | Nextcloud MailFedoraproject Fedora | 12/5/2020 | 17/6/2026 | A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack. | |
| Modificada | Media (5.4) | 1.1% | — | Nextcloud Server | 12/5/2020 | 17/6/2026 | An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerability when opening a malicious PDF. | |
| Modificada | Alta (7.7) | 1.8% | — | Nextcloud Server | 12/5/2020 | 17/6/2026 | An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint. | |
| Modificada | Alta (8.1) | 1.9% | — | Nextcloud Group FoldersFedoraproject Fedora | 12/5/2020 | 17/6/2026 | Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name. | |
| Modificada | Alta (7.8) | 0.35% | — | Targetcli-fb Project Targetcli-fb | 15/4/2020 | 17/6/2026 | A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the socket used by targetclid was world-writable. If a system enables the targetclid socket, a local attacker can use this flaw to modify the iSCSI configuration and escalate their privileges to root. | |
| Modificada | Media (6.7) | 0.69% | — | Nextcloud Desktop | 20/3/2020 | 17/6/2026 | A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the environment. | |
| Modificada | Media (6.5) | 1.5% | — | Nextcloud ServerFedoraproject Fedora | 20/3/2020 | 17/6/2026 | A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL. | |
| Modificada | Media (6.5) | 1.4% | — | Nextcloud Server | 20/3/2020 | 17/6/2026 | A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL. | |
| Modificada | Alta (7.5) | 1.2% | — | Smartclient | 23/2/2020 | 17/6/2026 | An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL allows an unauthenticated attacker to overwrite files via vectors involving an XML comment and /.. path traversal. |