Vulnerabilities > Nextcloud > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-07-10 CVE-2020-8181 Unrestricted Upload of File with Dangerous Type vulnerability in Nextcloud Contacts
A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.
network
low complexity
nextcloud CWE-434
4.3
2020-07-02 CVE-2020-8179 Improper Privilege Management vulnerability in Nextcloud Deck
Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.
network
low complexity
nextcloud CWE-269
4.1
2020-05-12 CVE-2020-8155 Cross-site Scripting vulnerability in Nextcloud Server
An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerability when opening a malicious PDF.
network
low complexity
nextcloud CWE-79
5.4
2020-03-20 CVE-2020-8140 Code Injection vulnerability in Nextcloud Desktop
A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the environment.
local
low complexity
nextcloud CWE-94
6.7
2020-03-20 CVE-2020-8139 Missing Authorization vulnerability in multiple products
A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.
network
low complexity
nextcloud fedoraproject CWE-862
6.5
2020-03-20 CVE-2020-8138 Server-Side Request Forgery (SSRF) vulnerability in Nextcloud Server
A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.
network
low complexity
nextcloud CWE-918
6.5
2020-02-04 CVE-2020-8122 Improper Input Validation vulnerability in Nextcloud Server
A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received.
network
low complexity
nextcloud CWE-20
4.3
2020-02-04 CVE-2020-8120 Cross-site Scripting vulnerability in Nextcloud Server 16.0.1
A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.
network
low complexity
nextcloud CWE-79
6.1
2020-02-04 CVE-2020-8119 Incorrect Authorization vulnerability in Nextcloud Server
Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is opened via the gallery app.
network
low complexity
nextcloud CWE-863
4.3
2020-02-04 CVE-2020-8118 Server-Side Request Forgery (SSRF) vulnerability in multiple products
An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.
network
low complexity
nextcloud novell opensuse CWE-918
5.0