Vulnerabilities > Nextcloud > Nextcloud Server > 17.0.10

DATE CVE VULNERABILITY TITLE RISK
2020-11-09 CVE-2020-8150 Missing Encryption of Sensitive Data vulnerability in Nextcloud Server
A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.
local
high complexity
nextcloud CWE-311
4.1
2020-11-02 CVE-2020-8236 Improper Authentication vulnerability in Nextcloud Server
A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it.
low complexity
nextcloud CWE-287
6.8
2020-11-02 CVE-2020-8183 Insufficiently Protected Credentials vulnerability in Nextcloud Server
A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.
network
low complexity
nextcloud CWE-522
7.5
2020-05-12 CVE-2020-8155 Cross-site Scripting vulnerability in Nextcloud Server
An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerability when opening a malicious PDF.
network
low complexity
nextcloud CWE-79
5.4