Vulnerabilities > Nextcloud > Desktop

DATE CVE VULNERABILITY TITLE RISK
2023-04-04 CVE-2023-28998 Missing Required Cryptographic Step vulnerability in Nextcloud Desktop
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server.
network
low complexity
nextcloud CWE-325
6.1
2023-04-04 CVE-2023-28999 Missing Encryption of Sensitive Data vulnerability in Nextcloud Desktop
Nextcloud is an open-source productivity platform.
network
low complexity
nextcloud CWE-311
6.4
2023-02-06 CVE-2023-23942 Cross-site Scripting vulnerability in Nextcloud Desktop
The Nextcloud Desktop Client is a tool to synchronize files from a Nextcloud Server with your computer.
network
low complexity
nextcloud CWE-79
6.1
2023-01-09 CVE-2023-22472 Cross-Site Request Forgery (CSRF) vulnerability in Nextcloud Desktop 3.6.1
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud.
network
low complexity
nextcloud CWE-352
8.8
2022-11-25 CVE-2022-39332 Cross-site Scripting vulnerability in Nextcloud Desktop
Nexcloud desktop is the Desktop sync client for Nextcloud.
network
low complexity
nextcloud CWE-79
5.4
2022-11-25 CVE-2022-39333 Cross-site Scripting vulnerability in Nextcloud Desktop
Nexcloud desktop is the Desktop sync client for Nextcloud.
network
low complexity
nextcloud CWE-79
6.1
2022-11-25 CVE-2022-39331 Cross-site Scripting vulnerability in Nextcloud Desktop
Nexcloud desktop is the Desktop sync client for Nextcloud.
network
low complexity
nextcloud CWE-79
5.4
2022-11-25 CVE-2022-39334 Improper Certificate Validation vulnerability in Nextcloud Desktop
Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless servers.
local
high complexity
nextcloud CWE-295
4.7
2022-11-11 CVE-2022-41882 Code Injection vulnerability in Nextcloud Desktop 3.6.0
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer.
local
low complexity
nextcloud CWE-94
7.8
2021-08-18 CVE-2021-37617 Uncontrolled Search Path Element vulnerability in Nextcloud Desktop
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer.
local
low complexity
nextcloud CWE-427
7.3