Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.3
CVE-2025-59716
ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient…
Guests
after 0.12.4
CRITICAL 9.8
CVE-2023-49105EPSS 11%
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the us…
Owncloud Server
10.13.1+
HIGH 7.5
CVE-2023-49103 KEVEPSS 78%
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.…
Graph Api
Mitigation only
MEDIUM 6.1
CVE-2023-49104
An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able to pass in a crafted redirect…
Oauth2
0.6.1+
MEDIUM 5.5
CVE-2023-23948
The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCloud Android app is vulnerable…
Owncloud Client
after 3.0
MEDIUM 5.3
CVE-2022-43679
The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config useless. This could be abused t…
Owncloud
after 10.11.0
HIGH 7.5
CVE-2022-31649
ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.
Owncloud
10.10.0+
MEDIUM 5.5
CVE-2022-25339
ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers.
Owncloud Client
2.20.0+
MEDIUM 6.8
CVE-2022-25338
ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers.
Owncloud Client
2.20.0+
HIGH 7.8
CVE-2021-44537
ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.
Owncloud Desktop Client
2.9.2+
HIGH 8.8
CVE-2021-33828
The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a pu…
Files Antivirus
1.0.0+
HIGH 7.2
CVE-2021-33827
The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.
Files Antivirus
1.0.0+
CRITICAL 9.8
CVE-2021-35946
A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate thei…
Owncloud
10.8.0+
MEDIUM 5.4
CVE-2021-35948
Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when th…
Owncloud
10.8.0+
MEDIUM 5.3
CVE-2021-35947
The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a publ…
Owncloud
10.8.0+
MEDIUM 5.3
CVE-2021-35949
The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list meta…
Owncloud
10.8.0+
MEDIUM 6.5
CVE-2021-29659
ownCloud 10.7 has an incorrect access control vulnerability, leading to remote information disclosure. Due to a bug in the related API endpoint, the …
Owncloud Server
Mitigation only
HIGH 7.8
CVE-2020-28646
ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were prese…
Owncloud Desktop Client
2.7+
HIGH 8.3
CVE-2020-10252
An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated at…
Owncloud
10.4.0+
HIGH 7.5
CVE-2020-36249
The File Firewall before 2.8.0 for ownCloud Server does not properly enforce file-type restrictions for public shares.
File Firewall
2.8.0+
MEDIUM 5.9
CVE-2020-10254
An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview.
Owncloud
10.4.0+
MEDIUM 5.7
CVE-2020-36252
ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version of any file by sending a reque…
Owncloud Server
10.3.1+
CRITICAL 9.1
CVE-2020-28645
Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the…
Owncloud
10.6.0+
MEDIUM 5.7
CVE-2020-16144
When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and ano…
Files Antivirus
0.15.2+
MEDIUM 6.1
CVE-2020-16255
ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'
Owncloud
10.5+
CRITICAL 9.8
CVE-2014-2052
Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of s…
Owncloud
5.0.15 / 6.0.2+
MEDIUM 6.5
CVE-2014-2050
Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authent…
Owncloud
5.0.15 / 6.0.2+
MEDIUM 6.1
CVE-2013-0202
Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via th…
Owncloud Server
4.0.11 / 4.5.6+
MEDIUM 5.4
CVE-2013-0203
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or H…
Owncloud
after 4.5.5
CRITICAL 9.8
CVE-2014-2048
The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementation.
Owncloud
5.0.15+