Vulnerabilities (CVE)

Filtered by vendor Nextcloud Subscribe
Filtered by product Nextcloud
Total 52 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-8183 1 Nextcloud 1 Nextcloud 2024-02-04 5.0 MEDIUM 7.5 HIGH
A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.
CVE-2020-8236 1 Nextcloud 1 Nextcloud 2024-02-04 4.6 MEDIUM 6.8 MEDIUM
A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it.
CVE-2020-8259 1 Nextcloud 1 Nextcloud 2024-02-04 5.5 MEDIUM 8.1 HIGH
Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys.
CVE-2021-22877 2 Fedoraproject, Nextcloud 2 Fedora, Nextcloud 2024-02-04 5.5 MEDIUM 6.5 MEDIUM
A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet.
CVE-2020-8225 1 Nextcloud 1 Nextcloud 2024-02-04 5.0 MEDIUM 7.5 HIGH
A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.
CVE-2020-8152 1 Nextcloud 1 Nextcloud 2024-02-04 2.1 LOW 4.4 MEDIUM
Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the public key to decrypt them later on.
CVE-2020-8293 1 Nextcloud 1 Nextcloud 2024-02-04 4.0 MEDIUM 6.5 MEDIUM
A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.
CVE-2020-8173 1 Nextcloud 1 Nextcloud 2024-02-04 3.5 LOW 2.2 LOW
A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.
CVE-2020-8230 1 Nextcloud 1 Nextcloud 2024-02-04 2.1 LOW 5.5 MEDIUM
A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory.
CVE-2020-8229 1 Nextcloud 1 Nextcloud 2024-02-04 4.9 MEDIUM 5.5 MEDIUM
A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system.
CVE-2020-8140 1 Nextcloud 1 Nextcloud 2024-02-04 4.6 MEDIUM 6.7 MEDIUM
A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the environment.
CVE-2020-8189 1 Nextcloud 1 Nextcloud 2024-02-04 3.5 LOW 5.4 MEDIUM
A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.
CVE-2020-8224 1 Nextcloud 1 Nextcloud 2024-02-04 4.6 MEDIUM 7.8 HIGH
A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory.
CVE-2020-8227 1 Nextcloud 1 Nextcloud 2024-02-04 7.1 HIGH 6.8 MEDIUM
Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.
CVE-2019-15611 1 Nextcloud 1 Nextcloud 2024-02-04 4.0 MEDIUM 4.9 MEDIUM
Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications.
CVE-2019-15622 1 Nextcloud 1 Nextcloud 2024-02-04 2.1 LOW 2.4 LOW
Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables when using custom queries.
CVE-2019-15615 1 Nextcloud 1 Nextcloud 2024-02-04 3.6 LOW 6.1 MEDIUM
A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past.
CVE-2019-15614 1 Nextcloud 1 Nextcloud 2024-02-04 3.5 LOW 5.4 MEDIUM
Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files.
CVE-2019-5453 1 Nextcloud 1 Nextcloud 2024-02-04 3.6 LOW 6.1 MEDIUM
Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider.
CVE-2019-5455 1 Nextcloud 1 Nextcloud 2024-02-04 4.6 MEDIUM 6.8 MEDIUM
Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.