Known vulnerabilities in Nextcloud Server - page 4

Vendor: Nextcloud
Software CPE: cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 136
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Nextcloud Server Nextcloud Server is affected by 136 known vulnerabilities: 12 high, 51 medium, 73 low Critical High Medium Low

Vulnerabilities (136)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU63484 - Security Features
CVE-2022-29163
CWE-254 Low
No
No
22.2.6, 23.0.3 20.05.2022 SB2022052013
#VU62648 - Cross-Site Request Forgery (CSRF)
CVE-2022-24889
CWE-352 Low
No
No
21.0.8, 22.2.4, 23.0.1 27.04.2022 SB2022042711
#VU62646 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2022-24888
CWE-93 Low
No
No
20.0.14.4, 21.0.8, 22.2.4, 23.0.1 27.04.2022 SB2022042711
#VU62596 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2021-43608
CWE-89 High
No
No
21.0.7, 22.2.3, 23.0.0 26.04.2022 SB2021120924
SB2022042616
#VU61277 - Exposure of sensitive information to an unauthorized actor
CVE-2021-41239
CWE-200 Medium
No
No
20.0.14, 21.0.6, 22.2.1 14.03.2022 SB2022031412
#VU61276 - Improper Authorization
CVE-2021-41241
CWE-285 Medium
No
No
20.0.14, 21.0.6, 22.2.1 14.03.2022 SB2022031412
#VU61275 - Resource exhaustion
CVE-2022-24741
CWE-400 Low
No
No
21.0.8, 22.2.4, 23.0.1 14.03.2022 SB2022031411
#VU61274 - Exposure of sensitive information to an unauthorized actor
CVE-2021-41233
CWE-200 Low
No
No
20.0.14, 21.0.6, 22.2.1 14.03.2022 SB2022031412
#VU57655 - Improper Authentication
CVE-2021-41179
CWE-287 Medium
No
No
20.0.13, 21.0.5, 22.2.0 26.10.2021 SB2021102620
#VU57654 - Improper Control of Interaction Frequency
CVE-2021-41177
CWE-799 Medium
No
No
20.0.13, 21.0.5, 22.2.0 26.10.2021 SB2021102620
#VU57653 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-41178
CWE-22 Medium
No
No
20.0.13, 21.0.5, 22.2.0 26.10.2021 SB2021102620
#VU57649 - Improper Access Control
CVE-2021-38299
CWE-284 High
No
No
20.0.13, 21.0.5, 22.2.0 26.10.2021 SB2021102614
SB2021102615
#VU56366 - Exposure of sensitive information to an unauthorized actor
CVE-2021-32766
CWE-200 Medium
No
No
20.0.12, 21.0.4, 22.1.0 07.09.2021 SB2021090707
#VU56365 - Improper Authentication
CVE-2021-32800
CWE-287 Medium
No
No
20.0.12, 21.0.4, 22.1.0 07.09.2021 SB2021090707
#VU56363 - Inclusion of Functionality from Untrusted Control Sphere
CVE-2021-32802
CWE-829 High
No
No
20.0.12, 21.0.4, 22.1.0 07.09.2021 SB2021090707
#VU56362 - Information Exposure Through Log Files
CVE-2021-32801
CWE-532 Medium
No
No
20.0.12, 21.0.4, 22.1.0 07.09.2021 SB2021090707
#VU55101 - Improper Link Resolution Before File Access ('Link Following')
CVE-2021-32610
CWE-59 High
No
No
20.0.13, 21.0.5, 22.2.0 20.07.2021 SB2021072062
SB2021072221
SB2021102617
and 12 more
#VU54673 - Improper Control of Interaction Frequency
CVE-2021-32703
CWE-799 Medium
No
No
19.0.13, 20.0.11, 21.0.3 12.07.2021 SB2021071213
#VU54671 - Permissions, Privileges, and Access Controls
CVE-2021-32725
CWE-264 Medium
No
No
19.0.13, 20.0.11, 21.0.3 12.07.2021 SB2021071213
#VU54665 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-32733
CWE-79 Low
No
No
19.0.13, 20.0.11, 21.0.3 12.07.2021 SB2021071213


Showing elements 61 - 80 out of 136