Vulnerability index

Browse CVEs

250 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nextcloud Server MEDIUM 6.5
CVE-2021-22877

A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration whe…

Fix: 20.0.6+
Fix from $1,600 2021-03-03
Nextcloud Server MEDIUM 6.7
CVE-2020-8296

Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.

Fix: 20.0.0+
Fix from $1,600 2021-03-03
Nextcloud Server MEDIUM 5.4
CVE-2020-8294

A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when sav…

Fix: 18.0.11 / 19.0.5+
Fix from $1,600 2021-02-03
Nextcloud Server HIGH 7.5
CVE-2020-8295

A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password for a user.

Fix: 20.0.0+
Fix from $1,950 2021-01-26
Nextcloud Server MEDIUM 6.5
CVE-2020-8293

A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and…

Fix: 18.0.11 / 19.0.5+
Fix from $1,600 2021-01-26
Contacts MEDIUM 5.4
CVE-2020-8280

A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) …

Fix: 3.4.1+
Fix from $1,600 2021-01-06
Contacts MEDIUM 5.4
CVE-2020-8281

A missing file type check in Nextcloud Contacts 3.3.0 allows a malicious user to upload malicious SVG files to perform cross-site scripting (XSS) att…

Fix: 3.4.0+
Fix from $1,600 2021-01-06
Social HIGH 7.4
CVE-2020-8279

Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-middle attack.

Fix: 0.4.0+
Fix from $1,950 2020-11-19
Social MEDIUM 5.3
CVE-2020-8278

Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.

No fix yet
Fix from $1,600 2020-11-19
Nextcloud Server HIGH 8.1
CVE-2020-8259

Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys.

Fix: 20.0.0+
Fix from $1,950 2020-11-16
Nextcloud Server MEDIUM 5.3
CVE-2020-8133

A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.

No fix yet
Fix from $1,600 2020-11-09
Nextcloud Server HIGH 7.5
CVE-2020-8183

A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.

Fix: 18.0.6 / 19.0.1+
Fix from $1,950 2020-11-02
Nextcloud Server MEDIUM 6.8
CVE-2020-8236

A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking…

Fix: 19.0.2+
Fix from $1,600 2020-11-02
Deck HIGH 8.0
CVE-2020-8182

Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves.

No fix yet
Fix from $1,950 2020-10-05
Nextcloud Server MEDIUM 6.5
CVE-2020-8223

A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assi…

No fix yet
Fix from $1,600 2020-10-05
Preferred Providers MEDIUM 5.3
CVE-2020-8228

A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.

No fix yet
Fix from $1,600 2020-10-05
Desktop HIGH 7.5
CVE-2020-8225

A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication cred…

Fix: 2.6.5+
Fix from $1,950 2020-09-18
Desktop MEDIUM 6.8
CVE-2020-8227EPSS 26%

Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of …

Fix: 2.6.5+
Fix from $1,600 2020-08-21
Desktop MEDIUM 5.4
CVE-2020-8189

A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data …

Fix: 2.6.5+
Fix from $1,600 2020-08-21
Desktop MEDIUM 5.5
CVE-2020-8230

A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt …

Fix: 2.6.5+
Fix from $1,600 2020-08-17
Desktop HIGH 7.8
CVE-2020-8224

A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory.

Fix: 2.6.5+
Fix from $1,950 2020-08-10
Desktop MEDIUM 5.5
CVE-2020-8229

A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system.

Fix: 2.6.5+
Fix from $1,600 2020-08-10
Preferred Providers MEDIUM 5.3
CVE-2020-8202

Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when using a very long password.

No fix yet
Fix from $1,600 2020-07-30
Talk CRITICAL 9.9
CVE-2020-8180

A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an adminis…

Fix: 6.0.5 / 7.0.3+
Fix from $2,300 2020-06-08
Nextcloud Server HIGH 7.7
CVE-2020-8154

An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a…

Fix: 17.0.5 / 18.0.3+
Fix from $1,950 2020-05-12
Mail HIGH 7.0
CVE-2020-8156

A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.

Fix: 1.1.4+
Fix from $1,950 2020-05-12
Nextcloud Server MEDIUM 5.4
CVE-2020-8155

An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerability when opening a maliciou…

Fix: 18.0.3+
Fix from $1,600 2020-05-12
Group Folders HIGH 8.1
CVE-2020-8153

Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name.

Fix: 4.0.4+
Fix from $1,950 2020-05-12
Desktop MEDIUM 6.7
CVE-2020-8140

A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set i…

Fix: 2.6.3+
Fix from $1,600 2020-03-20
Nextcloud Server MEDIUM 6.5
CVE-2020-8138

A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulner…

Fix: 15.0.14 / 16.0.7+
Fix from $1,600 2020-03-20