Known vulnerabilities in Nextcloud Enterprise Server - page 2

Vendor: Nextcloud
Software CPE: cpe:2.3:a:nextcloud:nextcloud_enterprise_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 55
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Nextcloud Enterprise Server Nextcloud Enterprise Server is affected by 55 known vulnerabilities: 2 high, 18 medium, 35 low Critical High Medium Low

Vulnerabilities (55)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU83357 - Improper Access Control
CVE-2023-48303
CWE-284 Low
No
No
25.0.11, 26.0.6, 27.1.0 21.11.2023 SB2023112135
#VU83350 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-48301
CWE-79 Low
No
No
25.0.13, 26.0.8, 27.1.3 21.11.2023 SB2023112134
#VU83345 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-48302
CWE-79 Low
No
No
25.0.13, 26.0.8, 27.1.3 21.11.2023 SB2023112134
#VU82082 - Improper Restriction of Excessive Authentication Attempts
CVE-2023-39960
CWE-307 Medium
No
No
22.2.10.14, 23.0.12.9, 24.0.12.5, 25.0.9, 26.0.4 17.10.2023 SB2023101719
#VU82080 - Cleartext Storage of Sensitive Information
CVE-2023-45151
CWE-312 Low
No
No
25.0.8, 26.0.3, 27.0.1 17.10.2023 SB2023101720
#VU82071 - Improper Restriction of Excessive Authentication Attempts
CVE-2023-45148
CWE-307 Low
No
No
22.2.10.16, 23.0.12.11, 24.0.12.7, 25.0.11, 26.0.6, 27.1.0 17.10.2023 SB2023101718
#VU77663 - Improper Access Control
CVE-2023-35927
CWE-284 Medium
No
No
19.0.13.9, 20.0.14.14, 21.0.9.12, 22.2.10.12, 23.0.12.7, 24.0.12.2, 25.0.7, 26.0.2 23.06.2023 SB2023062328
#VU77662 - Improper Restriction of Excessive Authentication Attempts
CVE-2023-35172
CWE-307 High
No
No
21.0.9.12, 22.2.10.12, 23.0.12.7, 24.0.12.2, 25.0.7, 26.0.2 23.06.2023 SB2023062328
#VU77661 - Unprotected Storage of Credentials
CVE-2023-35928
CWE-256 Low
No
No
19.0.13.9, 20.0.14.14, 21.0.9.12, 22.2.10.12, 23.0.12.7, 24.0.12.2, 25.0.7, 26.0.2 23.06.2023 SB2023062328
#VU77660 - Improper Restriction of Excessive Authentication Attempts
CVE-2023-32320
CWE-307 High
No
No
21.0.9.12, 22.2.10.12, 23.0.12.7, 24.0.12.2, 25.0.7, 26.0.2 23.06.2023 SB2023062328
#VU77659 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2023-35171
CWE-601 Low
No
No
26.0.2 23.06.2023 SB2023062328
#VU76591 - Improper Restriction of Excessive Authentication Attempts
CVE-2023-32319
CWE-307 Medium
No
No
23.0.12.6, 24.0.12, 25.0.5, 26.0.0 29.05.2023 SB2023052911
#VU76588 - Insufficient Session Expiration
CVE-2023-32318
CWE-613 Medium
No
No
25.0.6, 26.0.1 29.05.2023 SB2023052910
#VU75399 - Improper Access Control
CVE-2023-30539
CWE-284 Medium
No
No
21.0.9.11, 22.2.10.11, 23.0.12.6, 24.0.11, 25.0.5 21.04.2023 SB2023042113
SB2023042117
#VU74599 - Exposure of sensitive information to an unauthorized actor
CVE-2023-28834
CWE-200 Low
No
No
23.0.14, 24.0.10, 25.0.4 07.04.2023 SB2023040724
#VU74598 - Improper Access Control
CVE-2023-28844
CWE-284 Low
No
No
24.0.10, 25.0.4 07.04.2023 SB2023040724
#VU74351 - Use of Incorrectly-Resolved Name or Reference
CVE-2023-28643
CWE-706 Medium
No
No
24.0.9, 25.0.3 04.04.2023 SB2023040412
#VU74347 - Violation of Secure Design Principles
CVE-2023-28833
CWE-657 Low
No
No
23.0.14, 24.0.10, 25.0.4 04.04.2023 SB2023040415
#VU74345 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2023-28835
CWE-338 Low
No
No
23.0.14, 24.0.10, 25.0.4 04.04.2023 SB2023040413
#VU74118 - Improper preservation of permissions
CVE-2023-25817
CWE-281 Low
No
No
24.0.9 28.03.2023 SB2023032809


Showing elements 21 - 40 out of 55