Skip to main content

Vendor/product archive

nextcloud / nextcloud_server CVEs

Beta · best-effort

189 CVEs tagged to nextcloud / nextcloud_server3 Critical, 28 High, 114 Medium, 44 Low, 0 Unrated.

CVE-2020-8295

Published Jan 26, 2021

A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password for a user.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8293

Published Jan 26, 2021

A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later inter…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8259

Published Nov 16, 2020

Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8152

Published Nov 16, 2020

Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the public key to decrypt them later on.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8150

Published Nov 9, 2020

A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8236

Published Nov 2, 2020

A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordle…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8155

Published May 12, 2020

An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerability when opening a malicious PDF.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8154

Published May 12, 2020

An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8138

Published Mar 20, 2020

A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8120

Published Feb 4, 2020

A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8119

Published Feb 4, 2020

Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is opened via the gallery app.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15621

Published Feb 4, 2020

Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15618

Published Feb 4, 2020

Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 126-150 of 189 CVEsPage 6 of 8