Vulnerabilities > Nextcloud > High

DATE CVE VULNERABILITY TITLE RISK
2022-09-15 CVE-2022-36074 Incorrect Authorization vulnerability in Nextcloud Enterprise Server and Nextcloud Server
Nextcloud server is an open source personal cloud product.
network
low complexity
nextcloud CWE-863
7.5
2021-10-25 CVE-2021-41177 Improper Control of Interaction Frequency vulnerability in Nextcloud Server
Nextcloud is an open-source, self-hosted productivity platform.
network
low complexity
nextcloud CWE-799
8.1
2021-08-18 CVE-2021-37617 Uncontrolled Search Path Element vulnerability in Nextcloud Desktop
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer.
local
low complexity
nextcloud CWE-427
7.3
2021-07-12 CVE-2021-32705 Improper Control of Interaction Frequency vulnerability in multiple products
Nextcloud Server is a Nextcloud package that handles data storage.
network
low complexity
nextcloud fedoraproject CWE-799
7.5
2021-07-12 CVE-2021-32688 Improper Authorization vulnerability in multiple products
Nextcloud Server is a Nextcloud package that handles data storage.
network
low complexity
nextcloud fedoraproject CWE-285
8.8
2021-07-12 CVE-2021-32679 Improper Encoding or Escaping of Output vulnerability in multiple products
Nextcloud Server is a Nextcloud package that handles data storage.
network
low complexity
nextcloud fedoraproject CWE-116
8.8
2021-06-01 CVE-2021-32656 Improper Access Control vulnerability in Nextcloud Server
Nextcloud Server is a Nextcloud package that handles data storage.
network
low complexity
nextcloud CWE-284
8.6
2021-04-14 CVE-2021-22879 Injection vulnerability in multiple products
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands.
network
low complexity
nextcloud fedoraproject CWE-74
8.8
2020-09-18 CVE-2020-8225 Cleartext Storage of Sensitive Information vulnerability in Nextcloud Desktop
A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.
network
low complexity
nextcloud CWE-312
7.5
2020-08-21 CVE-2020-8227 Path Traversal vulnerability in Nextcloud Desktop
Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.
network
high complexity
nextcloud CWE-22
7.1