Vulnerability index

Browse CVEs

94 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Guests MEDIUM 5.3
CVE-2025-59716

ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient…

Fix: after 0.12.4
Fix from $1,600 2025-11-05
Owncloud Server CRITICAL 9.8
CVE-2023-49105EPSS 11%

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the us…

Fix: 10.13.1+
Fix from $2,300 2023-11-21
Graph Api HIGH 7.5
CVE-2023-49103 KEVEPSS 78%

An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.…

Mitigation only
Fix from $1,950 2023-11-21
Oauth2 MEDIUM 6.1
CVE-2023-49104

An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able to pass in a crafted redirect…

Fix: 0.6.1+
Fix from $1,600 2023-11-21
Owncloud Client MEDIUM 5.5
CVE-2023-23948

The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCloud Android app is vulnerable…

Fix: after 3.0
Fix from $1,600 2023-02-13
Owncloud MEDIUM 5.3
CVE-2022-43679

The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config useless. This could be abused t…

Fix: after 10.11.0
Fix from $1,600 2022-11-10
Owncloud HIGH 7.5
CVE-2022-31649

ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.

Fix: 10.10.0+
Fix from $1,950 2022-06-09
Owncloud Client MEDIUM 5.5
CVE-2022-25339

ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers.

Fix: 2.20.0+
Fix from $1,600 2022-04-07
Owncloud Client MEDIUM 6.8
CVE-2022-25338

ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers.

Fix: 2.20.0+
Fix from $1,600 2022-04-07
Owncloud Desktop Client HIGH 7.8
CVE-2021-44537

ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.

Fix: 2.9.2+
Fix from $1,950 2022-01-15
Files Antivirus HIGH 8.8
CVE-2021-33828

The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a pu…

Fix: 1.0.0+
Fix from $1,950 2022-01-15
Files Antivirus HIGH 7.2
CVE-2021-33827

The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.

Fix: 1.0.0+
Fix from $1,950 2022-01-15
Owncloud CRITICAL 9.8
CVE-2021-35946

A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate thei…

Fix: 10.8.0+
Fix from $2,300 2021-09-07
Owncloud MEDIUM 5.4
CVE-2021-35948

Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when th…

Fix: 10.8.0+
Fix from $1,600 2021-09-07
Owncloud MEDIUM 5.3
CVE-2021-35947

The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a publ…

Fix: 10.8.0+
Fix from $1,600 2021-09-07
Owncloud MEDIUM 5.3
CVE-2021-35949

The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list meta…

Fix: 10.8.0+
Fix from $1,600 2021-09-07
Owncloud Server MEDIUM 6.5
CVE-2021-29659

ownCloud 10.7 has an incorrect access control vulnerability, leading to remote information disclosure. Due to a bug in the related API endpoint, the …

Mitigation only
Fix from $1,600 2021-05-20
Owncloud Desktop Client HIGH 7.8
CVE-2020-28646

ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were prese…

Fix: 2.7+
Fix from $1,950 2021-02-26
Owncloud HIGH 8.3
CVE-2020-10252

An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated at…

Fix: 10.4.0+
Fix from $1,950 2021-02-19
File Firewall HIGH 7.5
CVE-2020-36249

The File Firewall before 2.8.0 for ownCloud Server does not properly enforce file-type restrictions for public shares.

Fix: 2.8.0+
Fix from $1,950 2021-02-19
Owncloud MEDIUM 5.9
CVE-2020-10254

An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview.

Fix: 10.4.0+
Fix from $1,600 2021-02-19
Owncloud Server MEDIUM 5.7
CVE-2020-36252

ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version of any file by sending a reque…

Fix: 10.3.1+
Fix from $1,600 2021-02-19
Owncloud CRITICAL 9.1
CVE-2020-28645

Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the…

Fix: 10.6.0+
Fix from $2,300 2021-02-09
Files Antivirus MEDIUM 5.7
CVE-2020-16144

When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and ano…

Fix: 0.15.2+
Fix from $1,600 2021-02-09
Owncloud MEDIUM 6.1
CVE-2020-16255

ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'

Fix: 10.5+
Fix from $1,600 2021-01-15
Owncloud CRITICAL 9.8
CVE-2014-2052

Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of s…

Fix: 5.0.15 / 6.0.2+
Fix from $2,300 2020-02-11
Owncloud MEDIUM 6.5
CVE-2014-2050

Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authent…

Fix: 5.0.15 / 6.0.2+
Fix from $1,600 2020-01-23
Owncloud Server MEDIUM 6.1
CVE-2013-0202

Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via th…

Fix: 4.0.11 / 4.5.6+
Fix from $1,600 2019-12-17
Owncloud MEDIUM 5.4
CVE-2013-0203

Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or H…

Fix: after 4.5.5
Fix from $1,600 2019-11-22
Owncloud CRITICAL 9.8
CVE-2014-2048

The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementation.

Fix: 5.0.15+
Fix from $2,300 2018-03-26