VYPR

desktop

by Nextcloud

CVEs (7)

  • CVE-2025-66549LowDec 5, 2025
    risk 0.00cvss 2.4epss 0.00

    Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This…

  • CVE-2024-52510MedNov 15, 2024
    risk 0.00cvss 4.2epss 0.01

    The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that…

  • CVE-2024-46958CriSep 16, 2024
    risk 0.00cvss 9.1epss 0.01

    In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4.

  • CVE-2023-29000MedApr 4, 2023
    risk 0.00cvss 5.4epss 0.00

    The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.7.0, by trusting that the server will return a certificate that belongs to the keypair of the user, a malicious server could get the desktop…

  • CVE-2023-23942MedFeb 6, 2023
    risk 0.00cvss 5.4epss 0.01

    The Nextcloud Desktop Client is a tool to synchronize files from a Nextcloud Server with your computer. Versions prior to 3.6.3 are missing sanitisation on qml labels which are used for basic HTML elements such as `strong`, `em` and `head` lines in the UI of the desktop client.…

  • CVE-2022-39331MedNov 25, 2022
    risk 0.00cvss 4.6epss 0.01

    Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application in the notifications. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known…

  • CVE-2021-22895MedJun 11, 2021
    risk 0.00cvss 5.9epss 0.01

    Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Register with a Provider" flow.