Skip to content
Noroxi

nextcloud records

372 published records for vendor nextcloud.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

372 records
  • Command Injection in Appointment Emails for Nextcloud Calendar

    CriticalCVSS 9.8No exploitEPSS 33%

    nextcloud · calendarApr 11, 2022

  • Preview generation used third-party library not suited for user-generated content in Nextcloud server

    CriticalCVSS 9.8No exploitEPSS 3%

    nextcloud · nextcloud serverSep 7, 2021

  • Command Injection as root in NextCloudPi web panel

    CriticalCVSS 9.8No exploitEPSS 2%

    nextcloud · nextcloudpiMar 29, 2024

  • SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    nextcloud · nextcloudJul 30, 2019

  • An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able t

    CriticalCVSS 9.8No exploitEPSS 2%

    nextcloud · lookup-serverAug 7, 2019

  • Webauthn tokens not removed after user has been deleted

    CriticalCVSS 9.8No exploitEPSS 2%

    nextcloud · nextcloud serverJul 12, 2021

  • Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limit

    CriticalCVSS 9.8No exploitEPSS 2%

    nextcloud · nextcloud serverJun 11, 2021

  • A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by a

    CriticalCVSS 9.9No exploitEPSS 2%

    nextcloud · talkJun 8, 2020

  • Bruteforce protection can be bypassed with misconfigured proxy

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    nextcloud · nextcloud serverDec 22, 2023

  • Nextcloud Mail app vulnerable to Server-Side Request Forgery

    CriticalCVSS 9.8No exploitEPSS 1%

    nextcloud · mailNov 21, 2023

  • Nextcloud user_oidc app is missing brute force protection

    CriticalCVSS 9.8No exploitEPSS 1%

    nextcloud · user oidcMay 25, 2023

  • Nextcloud Server DNS pin middleware can be tricked into DNS rebinding allowing SSRF

    CriticalCVSS 9.8No exploitEPSS 1%

    nextcloud · nextcloud serverNov 21, 2023

  • Nextcloud global site selector authentication bypass

    CriticalCVSS 9.8No exploitEPSS 1%

    nextcloud · global site selectorJan 18, 2024

  • Unauthenticated SSRF in 3rd party module "cerdic/csstidy"

    CriticalCVSS 9.8No exploitEPSS 1%

    nextcloud · mailAug 4, 2022

  • Attacker can obtain write access to any federated share/public link

    CriticalCVSS 9.1No exploitEPSS 2%

    nextcloud · nextcloud serverJun 1, 2021

  • Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious serve

    HighCVSS 8.8No exploitEPSS 5%

    nextcloud · desktopApr 14, 2021

  • Scope of workflow operations is not validated in nextcloud server

    HighCVSS 8.8WeaponizedEPSS 4%

    nextcloud · nextcloud serverMar 30, 2023

  • NextCloud Cookbook's pull-checks.yml workflow is vulnerable to OS Command Injection

    HighCVSS 8.8No exploitEPSS 3%

    nextcloud · cookbookMay 26, 2023

  • lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacte

    HighCVSS 8.8No exploitEPSS 3%

    nextcloud · extractJun 5, 2019

  • Application specific tokens can change their own scope

    HighCVSS 8.8No exploitEPSS 2%

    nextcloud · nextcloud serverJul 12, 2021

  • Nextcloud Server password reset endpoint is not brute force protected

    CriticalCVSS 9.1No exploitEPSS 1%

    nextcloud · nextcloud serverJun 23, 2023

  • In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or

    CriticalCVSS 9.1No exploitEPSS 1%

    nextcloud · desktopSep 15, 2024

  • CVE-2020-8227
    35Monitor

    Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files ou

    MediumCVSS 6.8No exploitEPSS 26%

    nextcloud · desktopAug 21, 2020

  • Windmill < 1.615.0 Operator Role Missing Authorization Checks RCE

    HighCVSS 8.7Proof of conceptEPSS 3%

    windmill · windmillApr 7, 2026

  • Trusted servers exchange can be triggered by attacker

    HighCVSS 8.6No exploitEPSS 2%

    nextcloud · nextcloud serverJun 1, 2021