Vulnerabilities > Nextcloud > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-12-22 CVE-2023-49790 Improper Authentication vulnerability in Nextcloud
The Nextcloud iOS Files app allows users of iOS to interact with Nextcloud, a self-hosted productivity platform.
low complexity
nextcloud CWE-287
4.3
2023-12-22 CVE-2023-49791 Improper Access Control vulnerability in Nextcloud Server
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform.
network
low complexity
nextcloud CWE-284
5.4
2023-12-22 CVE-2023-48308 Improper Cross-boundary Removal of Sensitive Data vulnerability in Nextcloud Calendar
Nextcloud/Cloud is a calendar app for Nextcloud.
network
low complexity
nextcloud CWE-212
6.5
2023-11-21 CVE-2023-48305 Cleartext Storage of Sensitive Information vulnerability in Nextcloud Server
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform.
local
low complexity
nextcloud CWE-312
4.4
2023-11-21 CVE-2023-48301 Cross-site Scripting vulnerability in Nextcloud Server
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform.
network
low complexity
nextcloud CWE-79
5.4
2023-11-21 CVE-2023-48302 Cross-site Scripting vulnerability in Nextcloud Server
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform.
network
low complexity
nextcloud CWE-79
5.4
2023-11-21 CVE-2023-48304 Authorization Bypass Through User-Controlled Key vulnerability in Nextcloud Server
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform.
network
low complexity
nextcloud CWE-639
4.3
2023-10-16 CVE-2023-45149 Improper Restriction of Excessive Authentication Attempts vulnerability in Nextcloud Talk
Nextcloud talk is a chat module for the Nextcloud server platform.
network
low complexity
nextcloud CWE-307
4.3
2023-10-16 CVE-2023-45150 Improper Validation of Integrity Check Value vulnerability in Nextcloud Calendar
Nextcloud calendar is a calendar app for the Nextcloud server platform.
network
low complexity
nextcloud CWE-354
4.3
2023-10-16 CVE-2023-45148 Improper Restriction of Excessive Authentication Attempts vulnerability in Nextcloud Server
Nextcloud is an open source home cloud server.
network
low complexity
nextcloud CWE-307
4.3