Vulnerability index

Browse CVEs

250 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2021-22877 A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration whe… Nextcloud Server 20.0.6+ Fix from $1,6002021-03-03 MEDIUM 6.7 CVE-2020-8296 Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured. Nextcloud Server 20.0.0+ Fix from $1,6002021-03-03 MEDIUM 5.4 CVE-2020-8294 A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when sav… Nextcloud Server 18.0.11 / 19.0.5+ Fix from $1,6002021-02-03 HIGH 7.5 CVE-2020-8295 A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password for a user. Nextcloud Server 20.0.0+ Fix from $1,9502021-01-26 MEDIUM 6.5 CVE-2020-8293 A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and… Nextcloud Server 18.0.11 / 19.0.5+ Fix from $1,6002021-01-26 MEDIUM 5.4 CVE-2020-8280 A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) … Contacts 3.4.1+ Fix from $1,6002021-01-06 MEDIUM 5.4 CVE-2020-8281 A missing file type check in Nextcloud Contacts 3.3.0 allows a malicious user to upload malicious SVG files to perform cross-site scripting (XSS) att… Contacts 3.4.0+ Fix from $1,6002021-01-06 HIGH 7.4 CVE-2020-8279 Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-middle attack. Social 0.4.0+ Fix from $1,9502020-11-19 MEDIUM 5.3 CVE-2020-8278 Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user. Social No fix yet Fix from $1,6002020-11-19 HIGH 8.1 CVE-2020-8259 Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys. Nextcloud Server 20.0.0+ Fix from $1,9502020-11-16 MEDIUM 5.3 CVE-2020-8133 A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file. Nextcloud Server No fix yet Fix from $1,6002020-11-09 HIGH 7.5 CVE-2020-8183 A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call. Nextcloud Server 18.0.6 / 19.0.1+ Fix from $1,9502020-11-02 MEDIUM 6.8 CVE-2020-8236 A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking… Nextcloud Server 19.0.2+ Fix from $1,6002020-11-02 HIGH 8.0 CVE-2020-8182 Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves. Deck No fix yet Fix from $1,9502020-10-05 MEDIUM 6.5 CVE-2020-8223 A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assi… Nextcloud Server No fix yet Fix from $1,6002020-10-05 MEDIUM 5.3 CVE-2020-8228 A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times. Preferred Providers No fix yet Fix from $1,6002020-10-05 HIGH 7.5 CVE-2020-8225 A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication cred… Desktop 2.6.5+ Fix from $1,9502020-09-18 MEDIUM 6.8 CVE-2020-8227EPSS 26% Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of … Desktop 2.6.5+ Fix from $1,6002020-08-21 MEDIUM 5.4 CVE-2020-8189 A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data … Desktop 2.6.5+ Fix from $1,6002020-08-21 MEDIUM 5.5 CVE-2020-8230 A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt … Desktop 2.6.5+ Fix from $1,6002020-08-17 HIGH 7.8 CVE-2020-8224 A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory. Desktop 2.6.5+ Fix from $1,9502020-08-10 MEDIUM 5.5 CVE-2020-8229 A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system. Desktop 2.6.5+ Fix from $1,6002020-08-10 MEDIUM 5.3 CVE-2020-8202 Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when using a very long password. Preferred Providers No fix yet Fix from $1,6002020-07-30 CRITICAL 9.9 CVE-2020-8180 A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an adminis… Talk 6.0.5 / 7.0.3+ Fix from $2,3002020-06-08 HIGH 7.7 CVE-2020-8154 An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a… Nextcloud Server 17.0.5 / 18.0.3+ Fix from $1,9502020-05-12 HIGH 7.0 CVE-2020-8156 A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack. Mail 1.1.4+ Fix from $1,9502020-05-12 MEDIUM 5.4 CVE-2020-8155 An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerability when opening a maliciou… Nextcloud Server 18.0.3+ Fix from $1,6002020-05-12 HIGH 8.1 CVE-2020-8153 Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name. Group Folders 4.0.4+ Fix from $1,9502020-05-12 MEDIUM 6.7 CVE-2020-8140 A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set i… Desktop 2.6.3+ Fix from $1,6002020-03-20 MEDIUM 6.5 CVE-2020-8138 A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulner… Nextcloud Server 15.0.14 / 16.0.7+ Fix from $1,6002020-03-20