Vulnerability index

Browse CVEs

94 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2025-59716 ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient… Guests after 0.12.4 Fix from $1,6002025-11-05 CRITICAL 9.8 CVE-2023-49105EPSS 11% An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the us… Owncloud Server 10.13.1+ Fix from $2,3002023-11-21 HIGH 7.5 CVE-2023-49103 KEVEPSS 78% An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.… Graph Api Mitigation only Fix from $1,9502023-11-21 MEDIUM 6.1 CVE-2023-49104 An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able to pass in a crafted redirect… Oauth2 0.6.1+ Fix from $1,6002023-11-21 MEDIUM 5.5 CVE-2023-23948 The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCloud Android app is vulnerable… Owncloud Client after 3.0 Fix from $1,6002023-02-13 MEDIUM 5.3 CVE-2022-43679 The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config useless. This could be abused t… Owncloud after 10.11.0 Fix from $1,6002022-11-10 HIGH 7.5 CVE-2022-31649 ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer. Owncloud 10.10.0+ Fix from $1,9502022-06-09 MEDIUM 5.5 CVE-2022-25339 ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers. Owncloud Client 2.20.0+ Fix from $1,6002022-04-07 MEDIUM 6.8 CVE-2022-25338 ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers. Owncloud Client 2.20.0+ Fix from $1,6002022-04-07 HIGH 7.8 CVE-2021-44537 ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution. Owncloud Desktop Client 2.9.2+ Fix from $1,9502022-01-15 HIGH 8.8 CVE-2021-33828 The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a pu… Files Antivirus 1.0.0+ Fix from $1,9502022-01-15 HIGH 7.2 CVE-2021-33827 The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings. Files Antivirus 1.0.0+ Fix from $1,9502022-01-15 CRITICAL 9.8 CVE-2021-35946 A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate thei… Owncloud 10.8.0+ Fix from $2,3002021-09-07 MEDIUM 5.4 CVE-2021-35948 Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when th… Owncloud 10.8.0+ Fix from $1,6002021-09-07 MEDIUM 5.3 CVE-2021-35947 The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a publ… Owncloud 10.8.0+ Fix from $1,6002021-09-07 MEDIUM 5.3 CVE-2021-35949 The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list meta… Owncloud 10.8.0+ Fix from $1,6002021-09-07 MEDIUM 6.5 CVE-2021-29659 ownCloud 10.7 has an incorrect access control vulnerability, leading to remote information disclosure. Due to a bug in the related API endpoint, the … Owncloud Server Mitigation only Fix from $1,6002021-05-20 HIGH 7.8 CVE-2020-28646 ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were prese… Owncloud Desktop Client 2.7+ Fix from $1,9502021-02-26 HIGH 8.3 CVE-2020-10252 An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated at… Owncloud 10.4.0+ Fix from $1,9502021-02-19 HIGH 7.5 CVE-2020-36249 The File Firewall before 2.8.0 for ownCloud Server does not properly enforce file-type restrictions for public shares. File Firewall 2.8.0+ Fix from $1,9502021-02-19 MEDIUM 5.9 CVE-2020-10254 An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview. Owncloud 10.4.0+ Fix from $1,6002021-02-19 MEDIUM 5.7 CVE-2020-36252 ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version of any file by sending a reque… Owncloud Server 10.3.1+ Fix from $1,6002021-02-19 CRITICAL 9.1 CVE-2020-28645 Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the… Owncloud 10.6.0+ Fix from $2,3002021-02-09 MEDIUM 5.7 CVE-2020-16144 When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and ano… Files Antivirus 0.15.2+ Fix from $1,6002021-02-09 MEDIUM 6.1 CVE-2020-16255 ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.' Owncloud 10.5+ Fix from $1,6002021-01-15 CRITICAL 9.8 CVE-2014-2052 Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of s… Owncloud 5.0.15 / 6.0.2+ Fix from $2,3002020-02-11 MEDIUM 6.5 CVE-2014-2050 Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authent… Owncloud 5.0.15 / 6.0.2+ Fix from $1,6002020-01-23 MEDIUM 6.1 CVE-2013-0202 Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via th… Owncloud Server 4.0.11 / 4.5.6+ Fix from $1,6002019-12-17 MEDIUM 5.4 CVE-2013-0203 Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or H… Owncloud after 4.5.5 Fix from $1,6002019-11-22 CRITICAL 9.8 CVE-2014-2048 The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementation. Owncloud 5.0.15+ Fix from $2,3002018-03-26