Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
315 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.44% | — | Nextcloud Server | 1/6/2026 | 22/7/2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticated users with access to any file comment, to read the content of all comments. It is recommended that the Nextcloud… | |
| Analizada | Media (5.9) | 0.43% | — | Nextcloud Server | 1/6/2026 | 22/7/2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a pre-2FA session cookie (created after successful password authentication but before TOTP completion) could be reused as a Bearer token to authenticate against DAV… | |
| Analizada | Media (5.9) | 0.43% | — | Nextcloud Server | 1/6/2026 | 22/7/2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authentication bypass vulnerability allowed attackers with knowledge of a user's password to circumvent two-factor authentication (2FA) protections. When a user… | |
| Analizada | Media (6.4) | 0.49% | — | Nextcloud Server | 1/6/2026 | 22/7/2026 | Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextcloud Team that includes an external member (a person added via email address who does not have a Nextcloud account), the system automatically… | |
| Analizada | Media (4.3) | 0.36% | — | Nextcloud Server | 1/6/2026 | 22/7/2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.2, and 33.0.0 to before 33.0.1, the files_lock app did not properly validate the ownership of files when processing DAV lock and unlock requests. An authenticated user could lock or unlock files… | |
| Analizada | Media (6.5) | 0.48% | — | Nextcloud Server | 1/6/2026 | 22/7/2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authenticated attacker can access attachments of link shares when knowing the share token, circumventing password protection or download restrictions. It is applicable… | |
| Analizada | Alta (8.1) | 0.50% | — | Nextcloud Server | 1/6/2026 | 22/7/2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, with the knowledge of other users’ principal URL an attacker could possibly send a request to gain full access to their calendar. Therefore, the attacker must be an… | |
| Analizada | Media (6.5) | 0.57% | — | Nextcloud Server | 1/6/2026 | 22/7/2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14, and 32.0.0 to before 32.0.4, if {lang} is used in the template directory config value, non-admin users can in some cases copy arbitrary files (depending on unix permissions) into their own Nextcloud… | |
| Aplazada | Media (6.3) | 0.39% | — | Nextcloud ServerAINextcloud Enterprise ServerAI | 1/6/2026 | 22/7/2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a malicious user has access to a file share of a user, they could use this share token to also access the chunking upload directly and see temporary part files during… | |
| Aplazada | Baja (2.6) | 0.31% | — | Nextcloud ServerAINextcloud Enterprise ServerAI | 1/6/2026 | 22/7/2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.7 and 33.0.0 to before 33.0.1, a missing access check on API level allowed to add unknown circles by their ID directly to other circles. Since circle IDs have 62^15 complexity by default this is still… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Gladinet Triofox Cloud Server Agent Access ServiceAI | 27/5/2026 | 17/6/2026 | Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo, /woshome, /Settings, /schedule, or /DavCache. | |
| Analizada | Alta (7.1) | 0.64% | — | Sparxsystems PRO Cloud Server | 19/5/2026 | 17/6/2026 | Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an specially crafted SQL query. This causes the Pro Cloud Server service to terminate unexpectedly. The vendor was notified early about this vulnerability, but didn't respond… | |
| Analizada | Alta (7.7) | 0.66% | — | Sparxsystems PRO Cloud Server | 19/5/2026 | 17/6/2026 | Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The application downloads the properties of the object pointed by guid parameter and saves loaded content in current location (__DIR__) under the specified name. An attacker with repository access can control… | |
| Analizada | Crítica (9.3) | 0.91% | — | Sparxsystems PRO Cloud Server | 19/5/2026 | 17/6/2026 | Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter and send the model name only in the binary blob in POST request allowing SQL query execution without authentication. The vendor was notified early about this vulnerability, but didn't respond with… | |
| Analizada | Alta (8.7) | 0.59% | — | Sparxsystems PRO Cloud Server | 19/5/2026 | 17/6/2026 | Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of permission checks, any low privileged user can run arbitrary SQL queries within database user context. The vendor was notified early about this vulnerability, but didn't respond with the details of… | |
| Analizada | Crítica (9.5) | 0.42% | — | Sparxsystems PRO Cloud Server | 17/4/2026 | 30/9/2026 | Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases. | |
| Analizada | Crítica (9.3) | 0.38% | — | Sparxsystems PRO Cloud Server | 17/4/2026 | 30/9/2026 | Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. In a setup where OpenID is used as the primary method of authentication to authenticate to Sparx EA, Pro Cloud Server creates local passwords to the users and stores them in plaintext. | |
| Analizada | Crítica (9.3) | 0.26% | — | Sparxsystems PRO Cloud Server | 17/4/2026 | 30/9/2026 | Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. Unauthenticated user can retrieve database password in plaintext in certain situations | |
| Analizada | Media (4.3) | 0.27% | — | Nextcloud Server | 12/12/2025 | 17/6/2026 | Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews of arbitrary files belonging to other users by manipulating the fileId parameter. This allows unauthorized disclosure of sensitive data, such as text files or… | |
| Analizada | Media (4.3) | 0.31% | — | Nextcloud Server | 5/12/2025 | 17/6/2026 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server… | |
| Analizada | Media (4.3) | 0.28% | — | Nextcloud Server | 5/12/2025 | 17/6/2026 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This vulnerability is fixed in 31.0.1. | |
| Analizada | Media (6.1) | 0.28% | — | Nextcloud Server | 5/12/2025 | 17/6/2026 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to trick a user it viewing an uploaded SVG outside of the Nextcloud… | |
| Analizada | Media (4.9) | 0.36% | — | Nextcloud Server | 5/12/2025 | 17/6/2026 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10, contacts search allowed to retrieve personal data of other users (emails, names, identifiers) without proper access control.… | |
| Analizada | Media (5.4) | 0.30% | — | Nextcloud Server | 4/12/2025 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a… | |
| Analizada | Media (4.3) | 0.47% | — | Nextcloud Server | 16/5/2025 | 17/6/2026 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1, an attacker on a multi-user system may read temporary files from Nextcloud running with a different… |