Known vulnerabilities in Nextcloud Server - page 2

Vendor: Nextcloud
Software CPE: cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 136
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Nextcloud Server Nextcloud Server is affected by 136 known vulnerabilities: 12 high, 51 medium, 73 low Critical High Medium Low

Vulnerabilities (136)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU83358 - Cleartext Storage of Sensitive Information
CVE-2023-48305
CWE-312 Low
No
No
25.0.11, 26.0.6, 27.1.0 21.11.2023 SB2023112135
#VU83357 - Improper Access Control
CVE-2023-48303
CWE-284 Low
No
No
25.0.11, 26.0.6, 27.1.0 21.11.2023 SB2023112135
#VU83350 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-48301
CWE-79 Low
No
No
25.0.13, 26.0.8, 27.1.3 21.11.2023 SB2023112134
#VU83345 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-48302
CWE-79 Low
No
No
25.0.13, 26.0.8, 27.1.3 21.11.2023 SB2023112134
#VU82082 - Improper Restriction of Excessive Authentication Attempts
CVE-2023-39960
CWE-307 Medium
No
No
25.0.9, 26.0.4 17.10.2023 SB2023101719
#VU82080 - Cleartext Storage of Sensitive Information
CVE-2023-45151
CWE-312 Low
No
No
25.0.8, 26.0.3, 27.0.1 17.10.2023 SB2023101720
#VU82071 - Improper Restriction of Excessive Authentication Attempts
CVE-2023-45148
CWE-307 Low
No
No
25.0.11, 26.0.6, 27.1.0 17.10.2023 SB2023101718
#VU77663 - Improper Access Control
CVE-2023-35927
CWE-284 Medium
No
No
25.0.7, 26.0.2 23.06.2023 SB2023062328
#VU77662 - Improper Restriction of Excessive Authentication Attempts
CVE-2023-35172
CWE-307 High
No
No
25.0.7, 26.0.2 23.06.2023 SB2023062328
#VU77661 - Unprotected Storage of Credentials
CVE-2023-35928
CWE-256 Low
No
No
25.0.7, 26.0.2 23.06.2023 SB2023062328
#VU77660 - Improper Restriction of Excessive Authentication Attempts
CVE-2023-32320
CWE-307 High
No
No
25.0.7, 26.0.2 23.06.2023 SB2023062328
#VU77659 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2023-35171
CWE-601 Low
No
No
26.0.2 23.06.2023 SB2023062328
#VU76591 - Improper Restriction of Excessive Authentication Attempts
CVE-2023-32319
CWE-307 Medium
No
No
24.0.11, 25.0.5, 26.0.0 29.05.2023 SB2023052911
#VU76588 - Insufficient Session Expiration
CVE-2023-32318
CWE-613 Medium
No
No
25.0.6, 26.0.1 29.05.2023 SB2023052910
#VU75399 - Improper Access Control
CVE-2023-30539
CWE-284 Medium
No
No
24.0.11, 25.0.5 21.04.2023 SB2023042113
SB2023042117
#VU74599 - Exposure of sensitive information to an unauthorized actor
CVE-2023-28834
CWE-200 Low
No
No
24.0.10, 25.0.4 07.04.2023 SB2023040724
#VU74598 - Improper Access Control
CVE-2023-28844
CWE-284 Low
No
No
24.0.10, 25.0.4 07.04.2023 SB2023040724
#VU74350 - Resource exhaustion
CVE-2023-28644
CWE-400 Medium
No
No
25.0.3 04.04.2023 SB2023040414
#VU74347 - Violation of Secure Design Principles
CVE-2023-28833
CWE-657 Low
No
No
24.0.10, 25.0.4 04.04.2023 SB2023040415
#VU74345 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2023-28835
CWE-338 Low
No
No
24.0.10, 25.0.4 04.04.2023 SB2023040413


Showing elements 21 - 40 out of 136