nextcloud records
372 published records for vendor nextcloud.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 0.3%
- Pre-auth RCE
- 3
- With a fix record
- 22.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-284 Improper Access Control52
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')34
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor27
- CWE-639 Authorization Bypass Through User-Controlled Key25
- CWE-287 Improper Authentication18
- CWE-307 Improper Restriction of Excessive Authentication Attempts14
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
372 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
49Plan | CVE-2022-24838No exploit | Command Injection in Appointment Emails for Nextcloud Calendarnextcloud · calendar · CWE-74 | Critical9.8 | — | 33.0% | Apr 11, 2022 |
40Plan | CVE-2021-32802No exploit | Preview generation used third-party library not suited for user-generated content in Nextcloud servernextcloud · nextcloud server · CWE-829 | Critical9.8 | — | 2.6% | Sep 7, 2021 |
40Plan | CVE-2024-30247No exploit | Command Injection as root in NextCloudPi web panelnextcloud · nextcloudpi · CWE-78 | Critical9.8 | — | 2.1% | Mar 29, 2024 |
40Plan | CVE-2019-5454Proof of concept | SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiringnextcloud · nextcloud · CWE-89 | Critical9.8 | — | 2.0% | Jul 30, 2019 |
40Plan | CVE-2019-5476No exploit | An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able tnextcloud · lookup-server · CWE-89 | Critical9.8 | — | 1.8% | Aug 7, 2019 |
40Plan | CVE-2021-32726No exploit | Webauthn tokens not removed after user has been deletednextcloud · nextcloud server · CWE-708 | Critical9.8 | — | 1.8% | Jul 12, 2021 |
40Plan | CVE-2021-22915No exploit | Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limitnextcloud · nextcloud server · CWE-307 | Critical9.8 | — | 1.7% | Jun 11, 2021 |
40Plan | CVE-2020-8180No exploit | A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by anextcloud · talk · CWE-94 | Critical9.9 | — | 1.7% | Jun 8, 2020 |
39Monitor | CVE-2023-49792Proof of concept | Bruteforce protection can be bypassed with misconfigured proxynextcloud · nextcloud server · CWE-307 | Critical9.8 | — | 1.0% | Dec 22, 2023 |
39Monitor | CVE-2023-48307No exploit | Nextcloud Mail app vulnerable to Server-Side Request Forgerynextcloud · mail · CWE-918 | Critical9.8 | — | 0.9% | Nov 21, 2023 |
39Monitor | CVE-2023-32074No exploit | Nextcloud user_oidc app is missing brute force protectionnextcloud · user oidc · CWE-307 | Critical9.8 | — | 0.9% | May 25, 2023 |
39Monitor | CVE-2023-48306No exploit | Nextcloud Server DNS pin middleware can be tricked into DNS rebinding allowing SSRFnextcloud · nextcloud server · CWE-918 | Critical9.8 | — | 0.8% | Nov 21, 2023 |
39Monitor | CVE-2024-22212No exploit | Nextcloud global site selector authentication bypassnextcloud · global site selector · CWE-306 | Critical9.8 | — | 0.8% | Jan 18, 2024 |
39Monitor | CVE-2022-31132No exploit | Unauthenticated SSRF in 3rd party module "cerdic/csstidy"nextcloud · mail · CWE-918 | Critical9.8 | — | 0.7% | Aug 4, 2022 |
37Monitor | CVE-2021-32654No exploit | Attacker can obtain write access to any federated share/public linknextcloud · nextcloud server · CWE-639 | Critical9.1 | — | 1.8% | Jun 1, 2021 |
36Monitor | CVE-2021-22879No exploit | Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious servenextcloud · desktop · CWE-99 | High8.8 | — | 4.7% | Apr 14, 2021 |
36Monitor | CVE-2023-26482Weaponized | Scope of workflow operations is not validated in nextcloud servernextcloud · nextcloud server · CWE-78 | High8.8 | — | 4.2% | Mar 30, 2023 |
36Monitor | CVE-2023-31128No exploit | NextCloud Cookbook's pull-checks.yml workflow is vulnerable to OS Command Injectionnextcloud · cookbook · CWE-78 | High8.8 | — | 3.3% | May 26, 2023 |
36Monitor | CVE-2019-12739No exploit | lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharactenextcloud · extract · CWE-78 | High8.8 | — | 2.5% | Jun 5, 2019 |
36Monitor | CVE-2021-32688No exploit | Application specific tokens can change their own scopenextcloud · nextcloud server · CWE-285 | High8.8 | — | 2.3% | Jul 12, 2021 |
36Monitor | CVE-2023-35172No exploit | Nextcloud Server password reset endpoint is not brute force protectednextcloud · nextcloud server · CWE-307 | Critical9.1 | — | 0.9% | Jun 23, 2023 |
36Monitor | CVE-2024-46958No exploit | In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or nextcloud · desktop | Critical9.1 | — | 0.6% | Sep 15, 2024 |
35Monitor | CVE-2020-8227No exploit | Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files ounextcloud · desktop · CWE-22 | Medium6.8 | — | 25.8% | Aug 21, 2020 |
35Monitor | CVE-2026-22683Proof of concept | Windmill < 1.615.0 Operator Role Missing Authorization Checks RCEwindmill · windmill · CWE-862 | High8.7 | — | 2.6% | Apr 7, 2026 |
35Monitor | CVE-2021-32656No exploit | Trusted servers exchange can be triggered by attackernextcloud · nextcloud server · CWE-284 | High8.6 | — | 1.8% | Jun 1, 2021 |
- CVE-2022-2483849Plan
Command Injection in Appointment Emails for Nextcloud Calendar
CriticalCVSS 9.8No exploitEPSS 33%nextcloud · calendarApr 11, 2022
- CVE-2021-3280240Plan
Preview generation used third-party library not suited for user-generated content in Nextcloud server
CriticalCVSS 9.8No exploitEPSS 3%nextcloud · nextcloud serverSep 7, 2021
- CVE-2024-3024740Plan
Command Injection as root in NextCloudPi web panel
CriticalCVSS 9.8No exploitEPSS 2%nextcloud · nextcloudpiMar 29, 2024
- CVE-2019-545440Plan
SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring
CriticalCVSS 9.8Proof of conceptEPSS 2%nextcloud · nextcloudJul 30, 2019
- CVE-2019-547640Plan
An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able t
CriticalCVSS 9.8No exploitEPSS 2%nextcloud · lookup-serverAug 7, 2019
- CVE-2021-3272640Plan
Webauthn tokens not removed after user has been deleted
CriticalCVSS 9.8No exploitEPSS 2%nextcloud · nextcloud serverJul 12, 2021
- CVE-2021-2291540Plan
Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limit
CriticalCVSS 9.8No exploitEPSS 2%nextcloud · nextcloud serverJun 11, 2021
- CVE-2020-818040Plan
A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by a
CriticalCVSS 9.9No exploitEPSS 2%nextcloud · talkJun 8, 2020
- CVE-2023-4979239Monitor
Bruteforce protection can be bypassed with misconfigured proxy
CriticalCVSS 9.8Proof of conceptEPSS 1%nextcloud · nextcloud serverDec 22, 2023
- CVE-2023-4830739Monitor
Nextcloud Mail app vulnerable to Server-Side Request Forgery
CriticalCVSS 9.8No exploitEPSS 1%nextcloud · mailNov 21, 2023
- CVE-2023-3207439Monitor
Nextcloud user_oidc app is missing brute force protection
CriticalCVSS 9.8No exploitEPSS 1%nextcloud · user oidcMay 25, 2023
- CVE-2023-4830639Monitor
Nextcloud Server DNS pin middleware can be tricked into DNS rebinding allowing SSRF
CriticalCVSS 9.8No exploitEPSS 1%nextcloud · nextcloud serverNov 21, 2023
- CVE-2024-2221239Monitor
Nextcloud global site selector authentication bypass
CriticalCVSS 9.8No exploitEPSS 1%nextcloud · global site selectorJan 18, 2024
- CVE-2022-3113239Monitor
Unauthenticated SSRF in 3rd party module "cerdic/csstidy"
CriticalCVSS 9.8No exploitEPSS 1%nextcloud · mailAug 4, 2022
- CVE-2021-3265437Monitor
Attacker can obtain write access to any federated share/public link
CriticalCVSS 9.1No exploitEPSS 2%nextcloud · nextcloud serverJun 1, 2021
- CVE-2021-2287936Monitor
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious serve
HighCVSS 8.8No exploitEPSS 5%nextcloud · desktopApr 14, 2021
- CVE-2023-2648236Monitor
Scope of workflow operations is not validated in nextcloud server
HighCVSS 8.8WeaponizedEPSS 4%nextcloud · nextcloud serverMar 30, 2023
- CVE-2023-3112836Monitor
NextCloud Cookbook's pull-checks.yml workflow is vulnerable to OS Command Injection
HighCVSS 8.8No exploitEPSS 3%nextcloud · cookbookMay 26, 2023
- CVE-2019-1273936Monitor
lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacte
HighCVSS 8.8No exploitEPSS 3%nextcloud · extractJun 5, 2019
- CVE-2021-3268836Monitor
Application specific tokens can change their own scope
HighCVSS 8.8No exploitEPSS 2%nextcloud · nextcloud serverJul 12, 2021
- CVE-2023-3517236Monitor
Nextcloud Server password reset endpoint is not brute force protected
CriticalCVSS 9.1No exploitEPSS 1%nextcloud · nextcloud serverJun 23, 2023
- CVE-2024-4695836Monitor
In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or
CriticalCVSS 9.1No exploitEPSS 1%nextcloud · desktopSep 15, 2024
- CVE-2020-822735Monitor
Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files ou
MediumCVSS 6.8No exploitEPSS 26%nextcloud · desktopAug 21, 2020
- CVE-2026-2268335Monitor
Windmill < 1.615.0 Operator Role Missing Authorization Checks RCE
HighCVSS 8.7Proof of conceptEPSS 3%windmill · windmillApr 7, 2026
- CVE-2021-3265635Monitor
Trusted servers exchange can be triggered by attacker
HighCVSS 8.6No exploitEPSS 2%nextcloud · nextcloud serverJun 1, 2021