CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.
The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes bro…
After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.
The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rathe…
Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allo…
The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has p…
The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting…
A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators…
Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from the absol…
Nextcloud: Propfind requests for file comments allowed to load comments for other files
Nextcloud: Tables app allows limited SQLi in ORDER BY with malicious sort order argument for Table Views
Nextcloud: Bypass of second factor authentication on DAV endpoints
Nextcloud: Two-Factor Authentication Bypass via Pending Session Token Replay
Nextcloud: SQL Injection in Column Type Parameter Allows Arbitrary SQL Execution
Nextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewService
Nextcloud: Deleting a Forms collaborator share leaves uploaded response files accessible through a lingering Files share
Nextcloud: Calendar app leaked user identifiers via attendee suggestion endpoint
Nextcloud: Wrong condition in the User OIDC app's LdapService allowed deleted LDAP users to authenticate
Nextcloud: Hidden Public Link creation when sharing to a Team External Member
Nextcloud: Files Lock app allows users to lock and unlock files of other users
Nextcloud: Logged-in user bypasses share password and download restrictions on Text attachments via documentId leads to unauthorized file access
Nextcloud: Cross-Account Calendar Takeover via Unauthorized Group-Member-Set Update
Nextcloud: Limited path traversal via template API if using `{lang}` in config
Nextcloud: Open Redirect in user_oidc login flow via protocol-relative URL bypass
Nextcloud: Information disclosure in Nextcloud Approval app via fileId parameter reveals workflow associations
Showing 1 to 25 CVEs · page 1 (more available)