Known vulnerabilities in nextcloud
Vendor:
Nextcloud
Software:
nextcloud
Software CPE:
cpe:2.3:a:nextcloud:nextcloud:*:*:*:*:*:*:*:*
Website:
https://nextcloud.com/
Total vulnerabilities:
7
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
20.0.9
21.0.1
20.0.8
20.0.7
21.0.0
18.0.13
20.0.5
20.0.4
18.0.12
20.0.3
20.0.2
20.0.1
10.0.1
10.0.0
9.0.53
9.0.52
9.0.51
9.0.50
11.0.3
10.0.5
11.0.2
11.0.1
11.0.0
13.0.11
13.0.10
12.0.12
12.0.11
12.0.6
12.0.10
12.0.8
12.0.7
12.0.5
12.0.3
12.0.2
12.0.1
12.0.0
20.0.0
16.0.11
17.0.10
18.0.10
19.0.4
13.0.1
14.0.1
16.0.1
18.0.9
19.0.3
17.0.9
18.0.8
19.0.2
2.6.4
10.0.2
3.6.0
3.0.0
2.0.1
2.0.0
1.4.3
1.4.2
1.4.1
1.4.0
1.3.1
1.3.0
1.2.0
1.1.0
1.0.1
1.0.0
14.0.13
14.0.11
14.0.10
14.0.8
14.0.7
14.0.6
13.0.8
13.0.7
13.0.3
13.0.2
12.0.4
15.0.13
15.0.12
15.0.11
15.0.10
15.0.8
15.0.0
14.0.4
14.0.3
14.0.2
14.0.0
13.0.6
13.0.5
13.0.4
16.0.7
16.0.6
16.0.0
15.0.7
15.0.5
15.0.4
15.0.2
17.0.5
17.0.1
17.0.0
16.0.5
16.0.4
16.0.3
18.0.4
18.0.3
18.0.2
18.0.1
18.0.0
17.0.2
19.0.0
19.0.1
16.0.10
17.0.7
18.0.6
17.0.6
16.0.9
11.0.7
12.0.13
13.0.12
15.0.14
14.0.14
Vulnerabilities (7)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU35648 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2019-5454 |
CWE-89 | High | - | 30.07.2019 |
SB2019073025 |
||
| #VU35649 - Improper Authentication CVE-2019-5455 |
CWE-287 | Medium | - | 30.07.2019 |
SB2019073026 |
||
| #VU39272 - Incorrect Permission Assignment for Critical Resource CVE-2017-0884 |
CWE-732 | Low | - | 05.04.2017 |
SB2017040510 |
||
| #VU39273 - Exposure of sensitive information to an unauthorized actor CVE-2017-0885 |
CWE-200 | Low | - | 05.04.2017 |
SB2017040510 |
||
| #VU39274 - Resource exhaustion CVE-2017-0886 |
CWE-400 | Medium | - | 05.04.2017 |
SB2017040510 |
||
| #VU39275 - Improper input validation CVE-2017-0887 |
CWE-20 | Low | - | 05.04.2017 |
SB2017040510 |
||
| #VU39276 - Improper input validation CVE-2017-0888 |
CWE-20 | Low | - | 05.04.2017 |
SB2017040510 |