Skip to main content

Vendor/product archive

nextcloud / nextcloud_server CVEs

Beta · best-effort

189 CVEs tagged to nextcloud / nextcloud_server3 Critical, 28 High, 114 Medium, 44 Low, 0 Unrated.

CVE-2021-32802

Published Sep 7, 2021

Nextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user provided file content. For some image types, the Nextcloud ser…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-32801

Published Sep 7, 2021

Nextcloud server is an open source, self hosted personal cloud. In affected versions logging of exceptions may have resulted in logging potentially sensitive key material for the…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32800

Published Sep 7, 2021

Nextcloud server is an open source, self hosted personal cloud. In affected versions an attacker is able to bypass Two Factor Authentication in Nextcloud. Thus knowledge of a pass…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32766

Published Sep 7, 2021

Nextcloud Text is an open source plaintext editing application which ships with the nextcloud server. In affected versions the Nextcloud Text application returned different error…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32741

Published Jul 12, 2021

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public share link moun…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32734

Published Jul 12, 2021

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the Nextcloud Text application shipped with Nextcloud Server r…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-32733

Published Jul 12, 2021

Nextcloud Text is a collaborative document editing application that uses Markdown. A cross-site scripting vulnerability is present in versions prior to 19.0.13, 20.0.11, and 21.0.…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32726

Published Jul 12, 2021

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32725

Published Jul 12, 2021

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, default share permissions were not being respected for federat…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-32657

Published Jun 1, 2021

Nextcloud Server is a Nextcloud package that handles data storage. In versions of Nextcloud Server prior to 10.0.11, 20.0.10, and 21.0.2, a malicious user may be able to break the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32656

Published Jun 1, 2021

Nextcloud Server is a Nextcloud package that handles data storage. A vulnerability in federated share exists in versions prior to 19.0.11, 20.0.10, and 21.0.2. An attacker can gai…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32655

Published Jun 1, 2021

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an attacker is able to convert a Files Drop link to a federat…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-32654

Published Jun 1, 2021

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an attacker is able to receive write/read privileges on any F…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32653

Published Jun 1, 2021

Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server versions prior to 19.0.11, 20.0.10, or 21.0.2 send user IDs to the lookup server even if the us…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-8294

Published Feb 3, 2021

A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when saving a 'javascript:' URL in mar…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 101-125 of 189 CVEsPage 5 of 8