Where
-Infinity
0

Nextcloud NextCloud ServerNextcloud Server vulnerable to insecure temporary file creation, race with write access and permission

Risk 16
Severity
4.3
EPSS
0.02%
First published (updated )

Nextcloud NextCloud ServerNextcloud Server and Groupfolders app vulnerable to bypass of group folder quota limit using attachment in text file

Risk 27
Severity
6.5
EPSS
0.02%
First published (updated )

Nextcloud NextCloud ServerNextcloud Server's test remote endpoint is not rate limited

Risk 19
Severity
5.3
EPSS
0.03%
First published (updated )

Nextcloud NextCloud ServerNextcloud Server's Attachments folder for Text app is accessible on "Files drop" and "Password protected" shares

Risk 22
Severity
4.3
First published (updated )

Nextcloud NextCloud ServerNextcloud Server allows users to copy folder that contain files that are blocked by the files access control

Risk 21
Severity
4.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Nextcloud NextCloud ServerNextcloud Server has incomplete sanitization of SVG files allows to embed other images into previews

Risk 38
Severity
6.5
First published (updated )

Nextcloud ServerNextcloud Server's OAuth2 client secrets were stored in a recoverable way

Risk 54
Severity
8.2
First published (updated )

Nextcloud NextCloud ServerNextcloud Server's link reference provider can be tricked into downloading bigger files than intended

Risk 37
Severity
6.5
First published (updated )

Nextcloud NextCloud ServerNextcloud Server Custom defined credentials of external storages are sent back to the frontend

Risk 38
Severity
6.5
First published (updated )

Nextcloud NextCloud ServerNextcloud server allows the by-pass the second factor

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Nextcloud Nextcloud Enterprise ServerMissing length validation of user displayname in nextcloud server

Risk 38
Severity
6.5
First published (updated )

Nextcloud Nextcloud Enterprise ServerDatabase resource exhaustion for logged-in users via sharee recommendations with circles

Risk 29
Severity
4.8
First published (updated )

Nextcloud Nextcloud Enterprise ServerException logging in Sharepoint app reveals clear-text connection details

Risk 38
Severity
6.5
First published (updated )

Nextcloud Nextcloud Enterprise ServerProfile of disabled user stays accessible

Risk 27
Severity
5.3
First published (updated )

Nextcloud Nextcloud Enterprise ServerServer-Side Request Forgery (SSRF) via potential filter bypass in Nextcloud Server

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Nextcloud Nextcloud Enterprise ServerAuthentication headers exposed on by Nextcloud Server

Risk 43
Severity
7.5
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203