Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.80% | — | Nextcloud Server | 23/6/2023 | 17/6/2026 | NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 21.0.0 until 21.0.9.12, 22.0.0 until 22.2.10.12, 23.0.0 until 23.0.12.7, 24.0.0… | |
| Modificada | Media (6.5) | 0.49% | — | Nextcloud End-to-end Encryption | 23/6/2023 | 17/6/2026 | Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid meta data file, an attacker can make previously dropped files inaccessible. It is recommended that the Nextcloud End-to-end encryption app is upgraded to version 1.12.4… | |
| Modificada | Crítica (9.1) | 0.92% | — | Nextcloud Server | 23/6/2023 | 17/6/2026 | NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 21.0.0 until 21.0.9.12, 22.0.0 until 22.2.10.12, 23.0.0 until 23.0.12.7, 24.0.0… | |
| Modificada | Media (6.1) | 0.59% | — | Nextcloud Server | 23/6/2023 | 17/6/2026 | NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. Starting in version 26.0.0 and prior to version 26.0.2, an attacker could supply a URL that redirects an unsuspecting victim from a legitimate domain to an attacker's site. Nextcloud Server and… | |
| Modificada | Alta (7.5) | 0.87% | — | Nextcloud Server | 22/6/2023 | 17/6/2026 | Nextcloud Server is a data storage system for Nextcloud, a self-hosted productivity platform. When multiple requests are sent in parallel, all of them were executed even if the amount of faulty requests succeeded the limit by the time the response was sent to the client. This allowed someone to send as many requests… | |
| Modificada | Media (4.3) | 0.44% | — | Nextcloud Calendar | 30/5/2023 | 17/6/2026 | Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is updated to 3.5.5 or 4.2.3 | |
| Modificada | Media (4.3) | 0.85% | — | Nextcloud Contacts | 30/5/2023 | 17/6/2026 | Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsanitized SVG is converted to a JavaScript blob (in memory data) that the Avatar can't render. Due to this constellation the missing sanitization does not seem to be exploitable. It is recommended that… | |
| Modificada | Media (5.3) | 0.53% | — | Nextcloud Mail | 27/5/2023 | 17/6/2026 | Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recommended that the Mail app is update to version 3.02, 2.2.5 or 1.15.3. | |
| Modificada | Media (6.5) | 0.70% | — | Nextcloud Server | 26/5/2023 | 17/6/2026 | Nextcloud server is an open source personal cloud implementation. Missing brute-force protection on the WebDAV endpoints via the basic auth header allowed to brute-force user credentials when the provided user name was not an email address. Users from version 24.0.0 onward are affected. This issue has been addressed… | |
| Modificada | Alta (8.8) | 3.3% | — | Nextcloud Cookbook | 26/5/2023 | 17/6/2026 | NextCloud Cookbook is a recipe library app. Prior to commit a46d9855 on the `master` branch and commit 489bb744 on the `main-0.9.x` branch, the `pull-checks.yml` workflow is vulnerable to command injection attacks because of using an untrusted `github.head_ref` field. The `github.head_ref` value is an… | |
| Modificada | Media (6.7) | 0.21% | — | Nextcloud Server | 26/5/2023 | 17/6/2026 | Nextcloud server provides a home for data. A regression in the session handling between Nextcloud Server and the Nextcloud Text app prevented a correct destruction of the session on logout if cookies were not cleared manually. After successfully authenticating with any other account the previous session would be… | |
| Modificada | Crítica (9.8) | 0.85% | — | Nextcloud User Oidc | 25/5/2023 | 17/6/2026 | user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.2 | |
| Modificada | Alta (7.5) | 0.77% | — | Nextcloud Server | 25/4/2023 | 17/6/2026 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server 24.0.0 prior to 24.0.11 and 25.0.0 prior to 25.0.5; as well as Nextcloud Server Enterprise 23.0.0 prior to 23.0.12.6, 24.0.0 prior to 24.0.11, and 25.0.0 prior to 25.0.5; an attacker is not restricted… | |
| Modificada | Media (4.3) | 0.66% | — | Nextcloud Talk | 17/4/2023 | 17/6/2026 | Nextcloud Talk is a chat, video & audio call extension for Nextcloud. In affected versions a user that was added later to a conversation can use this information to get access to data that was deleted before they were added to the conversation. This issue has been patched in version 15.0.5 and it is recommended that… | |
| Modificada | Alta (8.8) | 0.63% | — | Nextcloud Files Automated TaggingNextcloud Server | 17/4/2023 | 17/6/2026 | Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to limit access of others or being able to grant them access when there are system tag based files access control or files retention rules. It is recommended that the Nextcloud Server is upgraded to… | |
| Modificada | Media (6.5) | 0.39% | — | Nextcloud Desktop | 4/4/2023 | 17/6/2026 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.7.0, by trusting that the server will return a certificate that belongs to the keypair of the user, a malicious server could get the desktop client to encrypt files with a key known to… | |
| Modificada | Media (6.4) | 0.68% | — | Nextcloud DesktopNextcloud | 4/4/2023 | 17/6/2026 | Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can decrypt files, recover the folder… | |
| Modificada | Media (6.1) | 0.68% | — | Nextcloud Desktop | 4/4/2023 | 17/6/2026 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can decrypt files, recover the folder structure, and add new files. Users should… | |
| Modificada | Media (6.5) | 1.1% | — | Nextcloud Desktop | 4/4/2023 | 17/6/2026 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can recover and modify the contents of end-to-end encrypted files. Users should upgrade the Nextcloud Desktop client to 3.6.5 to receive a patch.… | |
| Modificada | Media (5.4) | 0.33% | — | Nextcloud User Oidc | 4/4/2023 | 17/6/2026 | user_oidc is the OIDC connect user backend for Nextcloud, an open source collaboration platform. A vulnerability in versions 1.0.0 until 1.3.0 effectively allowed an attacker to bypass the state protection as they could just copy the expected state token from the first request to their second request. Users should… | |
| Modificada | Media (4.3) | 0.81% | — | Nextcloud Server | 3/4/2023 | 17/6/2026 | Nextcloud Server is an open source personal cloud server. Nextcloud Server 24.0.0 until 24.0.6 and 25.0.0 until 25.0.4, as well as Nextcloud Enterprise Server 23.0.0 until 23.0.11, 24.0.0 until 24.0.6, and 25.0.0 until 25.0.4, have an information disclosure vulnerability. A user was able to get the full data directory… | |
| Modificada | Baja (3.5) | 0.45% | — | Nextcloud Talk | 31/3/2023 | 17/6/2026 | Nextcloud talk is a video & audio conferencing app for Nextcloud. In affected versions the talk app does not properly filter access to a conversations member list. As a result an attacker could use this vulnerability to gain information about the members of a Talk conversation, even if they themselves are not members.… | |
| Modificada | Media (6.5) | 0.62% | — | Nextcloud Server | 31/3/2023 | 17/6/2026 | Nextcloud server is an open source home cloud implementation. In affected versions users that should not be able to download a file can still download an older version and use that for uncontrolled distribution. This issue has been addressed in versions 24.0.10 and 25.0.4. Users are advised to upgrade. There are no… | |
| Modificada | Media (6.5) | 0.74% | — | Nextcloud Richdocuments | 31/3/2023 | 17/6/2026 | Nextcloud richdocuments is a Nextcloud app integrating the office suit Collabora Online. In affected versions the secure view feature of the rich documents app can be bypassed by using unprotected internal API endpoint of the rich documents app. It is recommended that the Nextcloud Office app (richdocuments) is… | |
| Modificada | Alta (7.5) | 0.54% | — | Nextcloud Server | 30/3/2023 | 17/6/2026 | Nextcloud server is an open source home cloud implementation. In affected versions the generated fallback password when creating a share was using a weak complexity random number generator, so when the sharer did not change it the password could be guessable to an attacker willing to brute force it. It is recommended… |