CVE-2025-47792
- EPSS 0.01%
- Veröffentlicht 16.05.2025 14:13:53
- Zuletzt bearbeitet 08.09.2025 21:22:39
Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then...
CVE-2024-52510
- EPSS 0.47%
- Veröffentlicht 15.11.2024 18:15:29
- Zuletzt bearbeitet 28.08.2025 14:21:08
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signat...
CVE-2024-46958
- EPSS 0.14%
- Veröffentlicht 16.09.2024 02:15:01
- Zuletzt bearbeitet 13.03.2025 18:15:44
In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4.
CVE-2024-37885
- EPSS 0.09%
- Veröffentlicht 14.06.2024 16:15:13
- Zuletzt bearbeitet 21.11.2024 09:24:28
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the...
CVE-2023-29000
- EPSS 0.48%
- Veröffentlicht 04.04.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 07:56:22
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.7.0, by trusting that the server will return a certificate that belongs to the keypair of the user, a malicious serv...
CVE-2023-28999
- EPSS 0.24%
- Veröffentlicht 04.04.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 07:56:22
Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0, a malicious server administrator can gain full access to an end-to-e...
CVE-2023-28998
- EPSS 0.54%
- Veröffentlicht 04.04.2023 13:15:08
- Zuletzt bearbeitet 21.11.2024 07:56:21
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can decrypt files...
CVE-2023-28997
- EPSS 0.89%
- Veröffentlicht 04.04.2023 13:15:08
- Zuletzt bearbeitet 21.11.2024 07:56:21
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can recover and modify the contents of end-to-end encrypted files. Users shoul...
CVE-2023-23942
- EPSS 0.68%
- Veröffentlicht 06.02.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 07:47:09
The Nextcloud Desktop Client is a tool to synchronize files from a Nextcloud Server with your computer. Versions prior to 3.6.3 are missing sanitisation on qml labels which are used for basic HTML elements such as `strong`, `em` and `head` lines in t...
CVE-2023-22472
- EPSS 0.16%
- Veröffentlicht 09.01.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 07:44:52
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. It is possible to make a user send any POST request with an arbitrary body given they click on a malicious deep link on ...