Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.36% | — | Nextcloud Calendar | 14/6/2024 | 17/6/2026 | Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clicked. It is recommended that the Nextcloud Calendar App is upgraded to 4.6.8 or 4.7.2. | |
| Modificada | Media (4.3) | 0.43% | — | Nextcloud Server | 14/6/2024 | 17/6/2026 | Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file is able to restore older versions of a document when the files_versions app is enabled. It is recommended that the Nextcloud Server is upgraded to 26.0.12, 27.1.7 or 28.0.3 and that the Nextcloud Enterprise Server is… | |
| Modificada | Baja (3.5) | 0.41% | — | Nextcloud Server | 14/6/2024 | 17/6/2026 | Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2. | |
| Analizada | Alta (7.5) | 0.40% | — | Nextcloud Server | 14/6/2024 | 17/6/2026 | Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfully providing the user credentials. It is recommended that the Nextcloud Server is upgraded to 26.0.13, 27.1.8 or 28.0.4 and Nextcloud Enterprise Server is upgraded to… | |
| Analizada | Media (6.3) | 0.64% | — | Nextcloud User Oidc | 14/6/2024 | 17/6/2026 | user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account eventually getting access to data that is available to all registered users. It is recommended that the OpenID Connect user backend is upgraded to 3.0.0 (Nextcloud… | |
| Aplazada | Alta (8.8) | 0.45% | — | TCL 30ZAITCL A3XAITCL 20xeAITCL 10LAI | 22/4/2024 | 17/6/2026 | Various software builds for the following TCL devices (30Z, A3X, 20XE, 10L) leak the device IMEI to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining non-resettable device identifiers in… | |
| Aplazada | Alta (8) | 0.26% | — | TCL 30ZAITCL A3XAI | 22/4/2024 | 17/6/2026 | Various software builds for the following TCL 30Z and TCL A3X devices leak the ICCID to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining non-resettable device identifiers in Android 10 and… | |
| Aplazada | Alta (7.8) | 0.18% | — | TCL 30ZAITCL 10AITCL 10LAI | 22/4/2024 | 17/6/2026 | Certain software builds for the TCL 30Z and TCL 10 Android devices contain a vulnerable, pre-installed app that relies on a missing permission that provides no protection at runtime. The missing permission is required as an access permission by components in various pre-installed apps. On the TCL 30Z device, the… | |
| Aplazada | Alta (8.7) | 0.36% | — | TCL 20xeAI | 22/4/2024 | 17/6/2026 | Certain software builds for the TCL 20XE Android device contain a vulnerable, pre-installed app with a package name of com.tct.gcs.hiddenmenuproxy (versionCode='2', versionName='v11.0.1.0.0201.0') that allows local third-party apps to programmatically perform a factory reset due to inadequate access control. No… | |
| Aplazada | Alta (7.1) | 0.15% | — | TCL A3XAITCL 10LAIMotorola Moto G PureAIMotorola Moto G PowerAI | 22/4/2024 | 17/6/2026 | An issue was discovered in a third-party component related to ro.boot.wifimacaddr, shipped on devices from multiple device manufacturers. Various software builds for the following TCL devices (30Z and 10L) and Motorola devices (Moto G Pure and Moto G Power) leak the Wi-Fi MAC address to a system property that can be… | |
| Analizada | Crítica (9.8) | 2.1% | — | Nextcloudpi | 29/3/2024 | 17/6/2026 | NextcloudPi is a ready to use image for Virtual Machines, Raspberry Pi, Odroid HC1, Rock64 and other boards. A command injection vulnerability in NextCloudPi allows command execution as the root user via the NextCloudPi web-panel. Due to a security misconfiguration this can be used by anyone with access to NextCloudPi… | |
| Analizada | Media (6.1) | 0.43% | — | Dotclear | 21/3/2024 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of the Admin Panel. | |
| Modificada | Media (4.3) | 0.52% | — | Nextcloud Zipper | 18/1/2024 | 17/6/2026 | Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download "view-only" files by zipping the complete folder. It is recommended that the Files ZIP app is upgraded to 1.2.1, 1.4.1, or 1.5.0. Users unable to upgrade should disable the… | |
| Modificada | Media (5.4) | 0.51% | — | Nextcloud Guests | 18/1/2024 | 17/6/2026 | Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users were able to load the first page of apps they were actually not allowed to access. Depending on the selection of apps installed this may present a permissions bypass. It is recommended that the… | |
| Modificada | Media (4.3) | 0.46% | — | Nextcloud Guests | 18/1/2024 | 17/6/2026 | Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users could change the allowed list of apps, allowing them to use apps that were not intended to be used. It is recommended that the Guests app is upgraded to 2.4.1, 2.5.1 or 3.0.1. There are no… | |
| Modificada | Baja (3.7) | 0.45% | — | Nextcloud Server | 18/1/2024 | 17/6/2026 | Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attacker would get access to an authorization code they could authenticate at any time using the code. As of version 28.0.0 OAuth codes are invalidated after 10 minutes and will no longer be authenticated.… | |
| Modificada | Media (6.1) | 0.45% | — | Nextcloud SSO & Saml Authentication | 18/1/2024 | 17/6/2026 | Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server and end up on a uncontrolled thirdparty server. It is recommended that the User Saml app is upgraded to version 5.1.5, 5.2.5, or 6.0.1. There are no known workarounds for… | |
| Modificada | Media (5.4) | 0.51% | — | Nextcloud Deck | 18/1/2024 | 17/6/2026 | Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions users could be tricked into executing malicious code that would execute in their browser via HTML sent as a comment. It is recommended that the Nextcloud Deck is… | |
| Modificada | Crítica (9.8) | 0.76% | — | Nextcloud Global Site Selector | 18/1/2024 | 17/6/2026 | Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users to the right server. A problem in the password verification method allows an attacker to authenticate as another user. It is recommended that the Nextcloud Global Site Selector is upgraded to version… | |
| Modificada | Crítica (9.8) | 1.2% | — | Mehah Otclient | 2/1/2024 | 17/6/2026 | OTCLient is an alternative tibia client for otserv. Prior to commit db560de0b56476c87a2f967466407939196dd254, the /mehah/otclient "`Analysis - SonarCloud`" workflow is vulnerable to an expression injection in Actions, allowing an attacker to run commands remotely on the runner, leak secrets, and alter the repository… | |
| Modificada | Crítica (9.8) | 1.1% | 💥 PoC | TCL Browser TV WEB - Browsehere | 27/12/2023 | 17/6/2026 | An issue in Shenzhen TCL Browser TV Web BrowseHere (aka com.tcl.browser) 6.65.022_dab24cc6_231221_gp allows a remote attacker to execute arbitrary JavaScript code via the com.tcl.browser.portal.browse.activity.BrowsePageActivity component. | |
| Modificada | Crítica (9.8) | 1.0% | 💥 PoC | Nextcloud Server | 22/12/2023 | 17/6/2026 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, and 27.1.4; when a (reverse) proxy is configured as trusted proxy the server… | |
| Modificada | Media (5.4) | 0.61% | — | Nextcloud Server | 22/12/2023 | 17/6/2026 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, and 27.1.4; when an attacker manages to get access to an active session of… | |
| Modificada | Media (4.3) | 0.29% | — | Nextcloud | 22/12/2023 | 17/6/2026 | The Nextcloud iOS Files app allows users of iOS to interact with Nextcloud, a self-hosted productivity platform. Prior to version 4.9.2, the application can be used without providing the 4 digit PIN code. Nextcloud iOS Files app should be upgraded to 4.9.2 to receive the patch. No known workarounds are available. | |
| Modificada | Media (6.5) | 0.55% | — | Nextcloud Calendar | 22/12/2023 | 17/6/2026 | Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar appointment. It is recommended that the Nextcloud Calendar app is upgraded to 4.5.3 |