Nextcloud / Server
4 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-77165 | File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database. | MEDIUM | 6.5 | Sep 21, 2026 |
| CVE-2026-68493 | After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of. | LOW | 3.1 | Sep 18, 2026 |
| CVE-2026-82985 | The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rathe… | MEDIUM | 6.5 | Sep 18, 2026 |
| CVE-2026-77164 | Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allo… | MEDIUM | 6.2 | Sep 18, 2026 |
| CVE-2024-37313 | Nextcloud server allows the by-pass the second factor | HIGH | 7.5 | Jun 14, 2024 |
| CVE-2023-39962 | Users can delete external storage mount points | HIGH | 7.7 | Aug 10, 2023 |
| CVE-2021-41179 | Two-Factor Authentication not enforced for pages marked as public | MEDIUM | 6.5 | Oct 25, 2021 |
| CVE-2021-41178 | File Traversal affecting SVG files on Nextcloud Server | HIGH | 8.8 | Oct 25, 2021 |
Showing 1 to 4 of 4 CVEs