Vulnerability index

Browse CVEs

250 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nextcloud Server MEDIUM 6.5
CVE-2020-8139

A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /do…

Fix: 16.0.9 / 17.0.4+
Fix from $1,600 2020-03-20
Nextcloud Server HIGH 8.1
CVE-2020-8121

A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.

Fix: 13.0.9 / 14.0.5+
Fix from $1,950 2020-02-04
Nextcloud Server MEDIUM 6.1
CVE-2020-8120

A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.

No fix yet
Fix from $1,600 2020-02-04
Nextcloud Server MEDIUM 5.0
CVE-2020-8118

An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in…

Fix: 15.0.9 / 16.0.2+
Fix from $1,600 2020-02-04
Nextcloud Server MEDIUM 6.5
CVE-2019-15621

Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point…

Fix: 14.0.13 / 15.0.9+
Fix from $1,600 2020-02-04
Nextcloud MEDIUM 6.1
CVE-2019-15615

A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past.

Fix: after 3.9.0
Fix from $1,600 2020-02-04
Nextcloud Server MEDIUM 5.4
CVE-2019-15617

A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login.

Fix: 17.0.1+
Fix from $1,600 2020-02-04
Nextcloud Server MEDIUM 5.3
CVE-2019-15623

Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without …

Fix: 14.0.13 / 15.0.9+
Fix from $1,600 2020-02-04
Nextcloud Server HIGH 8.0
CVE-2019-15613

A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.

Fix: 15.0.14 / 16.0.7+
Fix from $1,950 2020-02-04
Nextcloud Server MEDIUM 5.9
CVE-2019-15612

A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.

Fix: 13.0.11 / 14.0.7+
Fix from $1,600 2020-02-04
Nextcloud MEDIUM 5.4
CVE-2019-15614

Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files.

Fix: 2.25.0+
Fix from $1,600 2020-02-04
Lookup Server CRITICAL 9.8
CVE-2019-5476

An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able to execute…

Fix: 0.3.0+
Fix from $2,300 2019-08-07
Nextcloud CRITICAL 9.8
CVE-2019-5454

SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to reset…

Patch available
Fix from $2,300 2019-07-30
Nextcloud MEDIUM 6.8
CVE-2019-5450

Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style the directory name in the heade…

Fix: 3.7.0+
Fix from $1,600 2019-07-30
Nextcloud MEDIUM 6.8
CVE-2019-5455

Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.

No fix yet
Fix from $1,600 2019-07-30
Nextcloud MEDIUM 6.1
CVE-2019-5453

Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and sw…

Fix: after 3.2.4
Fix from $1,600 2019-07-30
Extract HIGH 8.8
CVE-2019-12739

lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacters in a R…

Fix: 1.2.0+
Fix from $1,950 2019-06-05
Nextcloud Server HIGH 8.1
CVE-2018-16466

Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess token…

Fix: 12.0.11 / 13.0.6+
Fix from $1,950 2018-10-30
Nextcloud Server MEDIUM 5.7
CVE-2018-16464

A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had change…

Fix: 14.0.0+
Fix from $1,600 2018-10-30
Nextcloud Server MEDIUM 5.3
CVE-2018-16465

Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provider of the second factor fail…

Fix: 14.0.0+
Fix from $1,600 2018-10-30
Nextcloud Server MEDIUM 5.3
CVE-2018-16467

A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares.

Fix: 14.0.0+
Fix from $1,600 2018-10-30
Talk MEDIUM 5.4
CVE-2018-3781

A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2.5 could lead to a stored XSS requiring user-interaction. Th…

Fix: 3.2.5+
Fix from $1,600 2018-08-13
Nextcloud Server MEDIUM 5.4
CVE-2018-3780

A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction.…

Fix: 13.0.5+
Fix from $1,600 2018-08-13
Nextcloud Server HIGH 8.8
CVE-2018-3775

Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Aut…

Fix: 12.0.3+
Fix from $1,950 2018-08-12
Nextcloud Server MEDIUM 5.3
CVE-2018-3776

Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.

Fix: 11.0.5 / 12.0.3+
Fix from $1,600 2018-08-12
Nextcloud Server HIGH 8.1
CVE-2018-3761

Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handin…

Fix: 12.0.8 / 13.0.3+
Fix from $1,950 2018-07-05
Nextcloud Server MEDIUM 5.7
CVE-2017-0936

Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check a…

Fix: 11.0.7+
Fix from $1,600 2018-03-28
Nextcloud Server MEDIUM 5.4
CVE-2017-0890

Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user …

Fix: 11.0.3+
Fix from $1,600 2017-05-08
Nextcloud Server MEDIUM 5.4
CVE-2017-0891

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilities in mul…

Fix: 9.0.58 / 10.0.5+
Fix from $1,600 2017-05-08
Nextcloud Server MEDIUM 5.4
CVE-2017-0893

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered …

Fix: 9.0.58 / 10.0.5+
Fix from $1,600 2017-05-08