Vulnerabilities > Nextcloud

DATE CVE VULNERABILITY TITLE RISK
2021-06-01 CVE-2021-32654 Unspecified vulnerability in Nextcloud Server
Nextcloud Server is a Nextcloud package that handles data storage.
network
low complexity
nextcloud
critical
9.1
2021-06-01 CVE-2021-32655 Unspecified vulnerability in Nextcloud Server
Nextcloud Server is a Nextcloud package that handles data storage.
network
low complexity
nextcloud
3.5
2021-06-01 CVE-2021-32653 Unspecified vulnerability in Nextcloud Server
Nextcloud Server is a Nextcloud package that handles data storage.
network
low complexity
nextcloud
2.7
2021-06-01 CVE-2021-32652 Missing Authorization vulnerability in Nextcloud Mail
Nextcloud Mail is a mail app for the Nextcloud platform.
network
low complexity
nextcloud CWE-862
4.3
2021-04-14 CVE-2021-22879 Injection vulnerability in multiple products
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands.
network
low complexity
nextcloud fedoraproject CWE-74
8.8
2021-03-03 CVE-2021-22878 Cross-site Scripting vulnerability in multiple products
Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`.
network
low complexity
nextcloud fedoraproject CWE-79
4.8
2021-03-03 CVE-2021-22877 Missing Authorization vulnerability in multiple products
A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet.
network
low complexity
nextcloud fedoraproject CWE-862
6.5
2021-03-03 CVE-2020-8296 Weak Password Requirements vulnerability in multiple products
Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
local
low complexity
nextcloud fedoraproject CWE-521
6.7
2021-02-23 CVE-2020-8297 Authorization Bypass Through User-Controlled Key vulnerability in Nextcloud Deck
Nextcloud Deck before 1.0.2 suffers from an insecure direct object reference (IDOR) vulnerability that permits users with a duplicate user identifier to access deck data of a previous deleted user.
network
low complexity
nextcloud CWE-639
4.3
2021-02-03 CVE-2020-8294 Cross-site Scripting vulnerability in Nextcloud Server
A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when saving a 'javascript:' URL in markdown format.
network
low complexity
nextcloud CWE-79
5.4