CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-77165 MEDIUM

File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.

CVSS 6.5 EPSS 0.41% Sep 21, 2026
CVE-2026-77166 LOW

The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes bro…

CVSS 2.4 EPSS 0.28% Sep 21, 2026
CVE-2026-68493 LOW

After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.

CVSS 3.1 EPSS 0.23% Sep 18, 2026
CVE-2026-82985 MEDIUM

The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rathe…

CVSS 6.5 EPSS 0.38% Sep 18, 2026
CVE-2026-77164 MEDIUM

Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allo…

CVSS 6.2 EPSS 0.19% Sep 18, 2026
CVE-2026-77170 MEDIUM

The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has p…

CVSS 4.3 EPSS 0.27% Sep 18, 2026
CVE-2026-82982 MEDIUM

The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting…

CVSS 4.3 EPSS 0.33% Sep 18, 2026
CVE-2026-77169 MEDIUM

A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators…

CVSS 6.5 EPSS 0.47% Sep 18, 2026
CVE-2026-82980 MEDIUM

Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from the absol…

CVSS 6.3 EPSS 0.30% Sep 18, 2026
CVE-2026-45810 MEDIUM

Nextcloud: Propfind requests for file comments allowed to load comments for other files

CVSS 6.8 EPSS 0.44% Jun 1, 2026
CVE-2026-45722 HIGH

Nextcloud: Tables app allows limited SQLi in ORDER BY with malicious sort order argument for Table Views

CVSS 7.1 EPSS 0.49% Jun 1, 2026
CVE-2026-45691 MEDIUM

Nextcloud: Bypass of second factor authentication on DAV endpoints

CVSS 5.9 EPSS 0.43% Jun 1, 2026
CVE-2026-45690 MEDIUM

Nextcloud: Two-Factor Authentication Bypass via Pending Session Token Replay

CVSS 5.9 EPSS 0.43% Jun 1, 2026
CVE-2026-45545 HIGH

Nextcloud: SQL Injection in Column Type Parameter Allows Arbitrary SQL Execution

CVSS 8.2 EPSS 0.52% Jun 1, 2026
CVE-2026-45544 MEDIUM

Nextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewService

CVSS 4.3 EPSS 0.37% Jun 1, 2026
CVE-2026-45543 MEDIUM

Nextcloud: Deleting a Forms collaborator share leaves uploaded response files accessible through a lingering Files share

CVSS 5.3 EPSS 0.46% Jun 1, 2026
CVE-2026-45286 MEDIUM

Nextcloud: Calendar app leaked user identifiers via attendee suggestion endpoint

CVSS 4.3 EPSS 0.46% Jun 1, 2026
CVE-2026-45284 HIGH

Nextcloud: Wrong condition in the User OIDC app's LdapService allowed deleted LDAP users to authenticate

CVSS 8.8 EPSS 0.36% Jun 1, 2026
CVE-2026-45285 MEDIUM

Nextcloud: Hidden Public Link creation when sharing to a Team External Member

CVSS 6.4 EPSS 0.49% Jun 1, 2026
CVE-2026-45283 MEDIUM

Nextcloud: Files Lock app allows users to lock and unlock files of other users

CVSS 6.3 EPSS 0.36% Jun 1, 2026
CVE-2026-45282 MEDIUM

Nextcloud: Logged-in user bypasses share password and download restrictions on Text attachments via documentId leads to unauthorized file access

CVSS 6.5 EPSS 0.48% Jun 1, 2026
CVE-2026-45281 HIGH

Nextcloud: Cross-Account Calendar Takeover via Unauthorized Group-Member-Set Update

CVSS 8.1 EPSS 0.50% Jun 1, 2026
CVE-2026-45279 MEDIUM

Nextcloud: Limited path traversal via template API if using `{lang}` in config

CVSS 6.5 EPSS 0.57% Jun 1, 2026
CVE-2026-45278 MEDIUM

Nextcloud: Open Redirect in user_oidc login flow via protocol-relative URL bypass

CVSS 6.1 EPSS 0.32% Jun 1, 2026
CVE-2026-45277 LOW

Nextcloud: Information disclosure in Nextcloud Approval app via fileId parameter reveals workflow associations

CVSS 3.3 EPSS 0.17% Jun 1, 2026

Showing 1 to 25 CVEs · page 1 (more available)