Vulnerabilities > Nextcloud > Nextcloud Server > 13.0.6
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-02-04 | CVE-2019-15612 | Session Fixation vulnerability in Nextcloud Server A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset. | 5.9 |
2019-07-30 | CVE-2019-5449 | Missing Authorization vulnerability in Nextcloud Server A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events. | 4.3 |
2018-10-30 | CVE-2018-16467 | Improper Authentication vulnerability in Nextcloud Server A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares. | 5.3 |
2018-10-30 | CVE-2018-16465 | Improper Authentication vulnerability in Nextcloud Server Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provider of the second factor failed to load. | 5.3 |
2018-10-30 | CVE-2018-16464 | Improper Authentication vulnerability in Nextcloud Server A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had changed the password. | 5.7 |