Nextcloud / Desktop
27 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-66549 | Nextcloud Desktop discloses information when attempting to lock a file inside a end-to-end encrypted directory | LOW | 2.7 | Dec 5, 2025 |
| CVE-2025-47792 | Nextcloud Desktop 3rdparty applications can create share links via socket API | MEDIUM | 6.1 | May 16, 2025 |
| CVE-2024-52510 | Nextcloud Desktop client behaves incorrectly if the initial end-to-end-encryption signature is empty | HIGH | 7.5 | Nov 15, 2024 |
| CVE-2024-46958 | In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. Thi… | CRITICAL | 9.1 | Sep 16, 2024 |
| CVE-2024-37885 | Code injection in Nextcloud Desktop Client for macOS | HIGH | 7.8 | Jun 14, 2024 |
| CVE-2023-29000 | Nextcloud Desktop client does not verify received singed certificate in end-to-end encryption | MEDIUM | 6.5 | Apr 4, 2023 |
| CVE-2023-28999 | Nextcloud: Lack of authenticity of metadata keys allows a malicious server to gain access to E2EE folders | MEDIUM | 6.9 | Apr 4, 2023 |
| CVE-2023-28998 | Nextcloud Desktop client misbehaves with E2EE when the server returns empty list of metadata keys | MEDIUM | 6.7 | Apr 4, 2023 |
| CVE-2023-28997 | Nextcloud Desktop: Initialization vector reuse in E2EE allows malicious server admin to break, manipulate, access files | MEDIUM | 6.7 | Apr 4, 2023 |
| CVE-2023-23942 | Self reflected HTML injection in Desktop client | MEDIUM | 6.1 | Feb 6, 2023 |
| CVE-2023-22472 | Nextcloud Deck Desktop Client is vulnerable to Cross-Site Request Forgery (CSRF) via malicious link | HIGH | 8.8 | Jan 9, 2023 |
| CVE-2022-39334 | nextcloudcmd incorrectly trusts bad TLS certificates | MEDIUM | 4.7 | Nov 25, 2022 |
| CVE-2022-39333 | Cross-site scripting (XSS) in Nextcloud Desktop Client | MEDIUM | 6.1 | Nov 25, 2022 |
| CVE-2022-39332 | Cross-site scripting (XSS) in Nextcloud Desktop Client | MEDIUM | 5.4 | Nov 25, 2022 |
| CVE-2022-39331 | Cross-site Scripting (XSS) in Nexcloud Desktop Client | MEDIUM | 5.4 | Nov 25, 2022 |
| CVE-2022-41882 | Nextcloud Desktop vulnerable to code injection via malicious link | HIGH | 7.8 | Nov 11, 2022 |
| CVE-2021-37617 | Untrusted Search Path in Nextcloud Desktop Client | HIGH | 7.3 | Aug 18, 2021 |
| CVE-2021-32728 | End-to-end encryption device setup did not verify public key | MEDIUM | 6.5 | Aug 18, 2021 |
| CVE-2021-22895 | Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Register wit… | MEDIUM | 5.9 | Jun 11, 2021 |
| CVE-2021-22879 | Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote… | HIGH | 8.8 | Apr 14, 2021 |
| CVE-2020-8225 | A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials. | HIGH | 7.5 | Sep 18, 2020 |
| CVE-2020-8189 | A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the log… | MEDIUM | 5.4 | Aug 21, 2020 |
| CVE-2020-8227 | Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedica… | MEDIUM | 6.8 | Aug 21, 2020 |
| CVE-2020-8230 | A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory. | MEDIUM | 5.5 | Aug 17, 2020 |
| CVE-2020-8224 | A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory. | HIGH | 7.8 | Aug 10, 2020 |
Showing 1 to 25 of 27 CVEs