Vulnerabilities > Nextcloud > Nextcloud Server > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-02-04 CVE-2019-15623 Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.
network
low complexity
nextcloud opensuse suse
5.0
2020-02-04 CVE-2019-15621 Improper Preservation of Permissions vulnerability in Nextcloud Server
Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as a public link.
network
low complexity
nextcloud CWE-281
4.0
2020-02-04 CVE-2019-15617 Improper Authentication vulnerability in Nextcloud Server
A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login.
network
low complexity
nextcloud CWE-287
5.5
2020-02-04 CVE-2019-15616 Injection vulnerability in Nextcloud Server
Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.
network
low complexity
nextcloud CWE-74
4.0
2019-07-30 CVE-2019-5449 Missing Authorization vulnerability in Nextcloud Server
A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.
network
low complexity
nextcloud CWE-862
4.0
2018-10-30 CVE-2018-16467 Improper Authentication vulnerability in Nextcloud Server
A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares.
network
low complexity
nextcloud CWE-287
5.0
2018-10-30 CVE-2018-16466 Improper Check for Dropped Privileges vulnerability in Nextcloud Server
Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens.
network
low complexity
nextcloud CWE-273
5.5
2018-10-30 CVE-2018-16465 Improper Authentication vulnerability in Nextcloud Server
Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provider of the second factor failed to load.
network
nextcloud CWE-287
4.3
2018-08-12 CVE-2018-3776 Information Exposure Through Log Files vulnerability in Nextcloud Server
Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.
network
low complexity
nextcloud CWE-532
5.3
2018-07-05 CVE-2018-3762 Improper Preservation of Permissions vulnerability in Nextcloud Server
Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to.
network
low complexity
nextcloud CWE-281
4.3