Desktop
Vendor:
First CVE: Mar 20, 2020 · Active for 6 years
27
Total CVEs
More Total CVEs than 96% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Desktop over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 20, 2020
6 years ago
Most Recent CVE
Dec 5, 2025
231 days ago
CVE Severity & Scoring
Desktop27 CVEs
63%
30%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local9 (33.3%)
Network18 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (92.6%)
High2 (7.4%)
Unknown0 (0.0%)
User Interaction
None15 (55.6%)
Unknown0 (0.0%)
Required12 (44.4%)
Privileges Required
Low11 (40.7%)
High6 (22.2%)
None10 (37.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8227MEDIUM Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory. | Aug 21, 2020 | 6.8 | 34 | NO | NO |
CVE-2024-46958CRITICAL In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4. | Sep 16, 2024 | 9.1 | 28 | NO | NO |
CVE-2021-22879HIGH Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User inter | Apr 14, 2021 | 8.8 | 28 | NO | NO |
CVE-2023-22472HIGH Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. It is possible to make a user send any POST reques | Jan 9, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-41882HIGH The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. In version 3.6.0, if a user received a malicious file share and has it synced | Nov 11, 2022 | 7.8 | 26 | NO | NO |
CVE-2020-8225HIGH A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials. | Sep 18, 2020 | 7.5 | 25 | NO | NO |
CVE-2021-37617HIGH The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop Client invokes its uninstaller script when being installed | Aug 18, 2021 | 7.3 | 23 | NO | NO |
CVE-2021-32728MEDIUM The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. Clients using the Nextcloud end-to-end encryption feature download the public and | Aug 18, 2021 | 6.5 | 23 | NO | NO |
CVE-2024-37885HIGH The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS allowed to load arbitra | Jun 14, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-28999MEDIUM Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0 | Apr 4, 2023 | 6.4 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (27 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (27 CVEs).
Media Mentions
Signals from CVEs in this product scope (27 CVEs).
Top CNAs Publishing CVEs For Desktop
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.6.1 | 1 | 8.8 | 0.2% | 0 | 0 |
| 3.6.0 | 1 | 7.8 | 0.5% | 0 | 0 |