Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.3
CVE-2021-32766
Nextcloud Text is an open source plaintext editing application which ships with the nextcloud server. In affected versions the Nextcloud Text applica…
Nextcloud Server
20.0.12 / 21.0.4+
MEDIUM 5.3
CVE-2021-37629
Nextcloud Richdocuments is an open source collaborative office suite. In affected versions there is a lack of rate limiting on the Richdocuments OCS …
Richdocuments
3.8.4 / 4.2.1+
MEDIUM 6.5
CVE-2021-37630
Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application allowed …
Circles
0.19.5 / 0.20.11+
MEDIUM 6.5
CVE-2021-37631
Deck is an open source kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In aff…
Deck
1.2.9 / 1.4.4+
MEDIUM 5.4
CVE-2021-32782
Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application is vulne…
Circles
0.19.14 / 0.20.10+
HIGH 7.3
CVE-2021-37617
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop Client invokes its uninstall…
Desktop
3.3.0+
MEDIUM 6.5
CVE-2021-32728
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. Clients using the Nextcloud end-to-end encryption …
Desktop
3.3.0+
MEDIUM 5.3
CVE-2021-32734
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the Nextcloud Text application s…
Nextcloud Server
19.0.13 / 20.0.11+
MEDIUM 5.3
CVE-2021-32741
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting…
Nextcloud Server
19.0.13 / 20.0.11+
HIGH 7.5
CVE-2021-32727
Nextcloud Android Client is the Android client for Nextcloud. Clients using the Nextcloud end-to-end encryption feature download the public and priva…
Nextcloud
3.16.1+
MEDIUM 6.1
CVE-2021-32733
Nextcloud Text is a collaborative document editing application that uses Markdown. A cross-site scripting vulnerability is present in versions prior …
Nextcloud Server
19.0.13 / 20.0.11+
CRITICAL 9.8
CVE-2021-32726
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted…
Nextcloud Server
19.0.13 / 20.0.11+
MEDIUM 5.3
CVE-2021-32725
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, default share permissions were n…
Nextcloud Server
19.0.13 / 20.0.11+
MEDIUM 6.5
CVE-2021-32689
Nextcloud Talk is a fully on-premises audio/video and chat communication service. In versions prior to 11.2.2, if a user was able to reuse an earlier…
Talk
11.2.2+
HIGH 7.5
CVE-2021-32705
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting…
Nextcloud Server
19.0.13 / 20.0.11+
MEDIUM 5.3
CVE-2021-32703
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting…
Nextcloud Server
19.0.13 / 20.0.11+
HIGH 8.8
CVE-2021-32688
Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes.…
Nextcloud Server
19.0.13 / 20.0.11+
HIGH 8.8
CVE-2021-32679
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, filenames where not escaped by …
Nextcloud Server
19.0.13 / 20.0.11+
MEDIUM 5.3
CVE-2021-32678
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, ratelimits are not applied to O…
Nextcloud Server
19.0.13 / 20.0.11+
MEDIUM 5.5
CVE-2021-32694
Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.15.1, a malicious application on the same device is possible to cra…
Nextcloud
3.15.1+
MEDIUM 6.5
CVE-2021-32676
Nextcloud Talk is a fully on-premises audio/video and chat communication service. Password protected shared chats in Talk before version 9.0.10, 10.0…
Talk
9.0.10 / 10.0.8+
CRITICAL 9.8
CVE-2021-22915
Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting consi…
Nextcloud Server
19.0.11 / 20.0.10+
MEDIUM 6.5
CVE-2021-22905
Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for sharees being performed by de…
Nextcloud
3.16.0+
MEDIUM 6.5
CVE-2021-22906
Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to permitting any authenticated user…
End To End Encryption
1.5.3 / 1.6.3+
MEDIUM 6.5
CVE-2021-22912
Nextcloud iOS before 3.4.2 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instea…
Nextcloud
3.4.2+
MEDIUM 6.5
CVE-2021-22913
Nextcloud Deck before 1.2.7, 1.4.1 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by defaul…
Deck
1.2.7 / 1.4.1+
MEDIUM 5.9
CVE-2021-22895
Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Re…
Desktop
3.1.3+
HIGH 8.6
CVE-2021-32656
Nextcloud Server is a Nextcloud package that handles data storage. A vulnerability in federated share exists in versions prior to 19.0.11, 20.0.10, a…
Nextcloud Server
19.0.11 / 20.0.10+
CRITICAL 9.1
CVE-2021-32654
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an attacker is able to receive …
Nextcloud Server
19.0.11 / 20.0.10+
HIGH 8.8
CVE-2021-22879
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to exec…
Desktop
3.1.3+