Vulnerabilities > Nextcloud > Desktop

DATE CVE VULNERABILITY TITLE RISK
2024-09-16 CVE-2024-46958 Unspecified vulnerability in Nextcloud Desktop 3.13.1/3.13.2/3.13.3
In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable.
network
low complexity
nextcloud
critical
9.1
2024-06-14 CVE-2024-37885 Code Injection vulnerability in Nextcloud Desktop
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer.
local
low complexity
nextcloud CWE-94
7.8
2023-04-04 CVE-2023-28998 Missing Required Cryptographic Step vulnerability in Nextcloud Desktop
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server.
network
low complexity
nextcloud CWE-325
6.1
2023-04-04 CVE-2023-28999 Missing Encryption of Sensitive Data vulnerability in Nextcloud Desktop
Nextcloud is an open-source productivity platform.
network
low complexity
nextcloud CWE-311
6.4
2023-02-06 CVE-2023-23942 Cross-site Scripting vulnerability in Nextcloud Desktop
The Nextcloud Desktop Client is a tool to synchronize files from a Nextcloud Server with your computer.
network
low complexity
nextcloud CWE-79
6.1
2023-01-09 CVE-2023-22472 Cross-Site Request Forgery (CSRF) vulnerability in Nextcloud Desktop 3.6.1
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud.
network
low complexity
nextcloud CWE-352
8.8
2022-11-25 CVE-2022-39332 Cross-site Scripting vulnerability in Nextcloud Desktop
Nexcloud desktop is the Desktop sync client for Nextcloud.
network
low complexity
nextcloud CWE-79
5.4
2022-11-25 CVE-2022-39333 Cross-site Scripting vulnerability in Nextcloud Desktop
Nexcloud desktop is the Desktop sync client for Nextcloud.
network
low complexity
nextcloud CWE-79
6.1
2022-11-25 CVE-2022-39331 Cross-site Scripting vulnerability in Nextcloud Desktop
Nexcloud desktop is the Desktop sync client for Nextcloud.
network
low complexity
nextcloud CWE-79
5.4
2022-11-25 CVE-2022-39334 Improper Certificate Validation vulnerability in Nextcloud Desktop
Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless servers.
local
high complexity
nextcloud CWE-295
4.7