Known vulnerabilities in Nextcloud Server - page 3

Vendor: Nextcloud
Software CPE: cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 136
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Nextcloud Server Nextcloud Server is affected by 136 known vulnerabilities: 12 high, 51 medium, 73 low Critical High Medium Low

Vulnerabilities (136)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU132318 - Cleartext Storage of Sensitive Information
CVE-2022-39364
CWE-312 Low
No
No
23.0.9, 24.0.5 26.05.2026 SB2022102756
#VU74351 - Use of Incorrectly-Resolved Name or Reference
CVE-2023-28643
CWE-706 Medium
No
No
24.0.9, 25.0.3 04.04.2023 SB2023040412
#VU74118 - Improper preservation of permissions
CVE-2023-25817
CWE-281 Low
No
No
24.0.9 28.03.2023 SB2023032809
#VU74117 - Improper Restriction of Excessive Authentication Attempts
CVE-2023-25818
CWE-307 Medium
No
No
24.0.10, 25.0.4 28.03.2023 SB2023032204
#VU73916 - Improper Restriction of Excessive Authentication Attempts
CVE-2023-25820
CWE-307 Low
No
No
24.0.10, 25.0.4 22.03.2023 SB2023032204
#VU72577 - Improper Access Control
CVE-2023-25821
CWE-284 Medium
No
No
24.0.7, 25.0.1 27.02.2023 SB2023022705
#VU72576 - Resource exhaustion
CVE-2023-25816
CWE-400 Low
No
No
25.0.3 27.02.2023 SB2023022706
#VU72495 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-25579
CWE-22 Medium
No
No
23.0.12, 24.0.8, 25.0.2 22.02.2023 SB2023022223
#VU72493 - Improper Access Control
CVE-2023-25161
CWE-284 Low
No
No
23.0.12, 24.0.8, 25.0.1 22.02.2023 SB2023022222
#VU72490 - Server-Side Request Forgery (SSRF)
CVE-2023-25162
CWE-918 Medium
No
No
23.0.12, 24.0.8 22.02.2023 SB2023022222
#VU72489 - Improper Access Control
CVE-2023-25159
CWE-284 Low
No
No
24.0.8, 25.0.1 22.02.2023 SB2023022212
SB2023022213
SB2023022214
#VU69806 - Resource exhaustion
CVE-2022-41968
CWE-400 Low
No
No
23.0.10, 24.0.5 01.12.2022 SB2022120138
#VU69804 - Resource exhaustion
CVE-2022-41969
CWE-400 Low
No
No
23.0.11, 24.0.7, 25.0.0 01.12.2022 SB2022120137
#VU69802 - Improper Access Control
CVE-2022-41970
CWE-284 Low
No
No
24.0.7, 25.0.1 01.12.2022 SB2022120136
#VU67419 - Server-Side Request Forgery (SSRF)
CVE-2022-39211
CWE-918 Low
No
No
23.0.8, 24.0.4 16.09.2022 SB2022091606
#VU67395 - Exposure of sensitive information to an unauthorized actor
CVE-2022-36074
CWE-200 Low
No
No
23.0.7, 24.0.3 15.09.2022 SB2022091518
#VU66130 - Improper input validation
CVE-2022-31120
CWE-20 Low
No
No
22.2.7, 23.0.4, 24.0.0 05.08.2022 SB2022080526
#VU66128 - Exposure of sensitive information to an unauthorized actor
CVE-2022-31118
CWE-200 Low
No
No
22.2.9, 23.0.6, 24.0.2 05.08.2022 SB2022080525
#VU65375 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2022-31014
CWE-93 Low
No
No
22.2.8, 23.0.5, 24.0.1 18.07.2022 SB2022071803
SB2022071804
#VU63825 - Resource exhaustion
CVE-2022-29243
CWE-400 Low
No
No
22.2.7, 23.0.4 31.05.2022 SB2022053101


Showing elements 41 - 60 out of 136