Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
owncloud owncloud vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2020-16255
ownCloud (Core) prior to 10.5 allows XSS in login page 'forgot password.'
Owncloud Owncloud
4
CVSSv2
CVE-2015-4715
The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server prior to 6.0.8, 7.x prior to 7.0.6, and 8.x prior to 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) cha...
Owncloud Owncloud
7.5
CVSSv2
CVE-2014-2052
Zend Framework, as used in ownCloud Server prior to 5.0.15 and 6.0.x prior to 6.0.2, allows remote malicious users to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
Owncloud Owncloud
4.3
CVSSv2
CVE-2014-2050
Cross-site request forgery (CSRF) vulnerability in ownCloud Server prior to 5.0.15 and 6.0.x prior to 6.0.2 allows remote malicious users to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header.
Owncloud Owncloud
4.3
CVSSv2
CVE-2013-0202
Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and previous versions allows remote malicious users to inject arbitrary web script or HTML via the action parameter to core/ajax/sharing.php.
Owncloud Owncloud
3.5
CVSSv2
CVE-2013-0203
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) unspecified parameters to apps/calendar/ajax/event/new.php or (2) url parameter to apps/bookmarks/a...
Owncloud Owncloud
7.5
CVSSv2
CVE-2014-2048
The user_openid app in ownCloud Server prior to 5.0.15 allows remote malicious users to obtain access by leveraging an insecure OpenID implementation.
Owncloud Owncloud
3.5
CVSSv2
CVE-2014-1665
Cross-site scripting (XSS) vulnerability in ownCloud prior to 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.
Owncloud Owncloud
1 EDB exploit
3.5
CVSSv2
CVE-2017-9338
Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server prior to 8.2.12, 9.0.x prior to 9.0.10, 9.1.x prior to 9.1.6, and 10.0.x prior to 10.0.2. To be exploitable a user has to write or paste malicious content into the search dialogue.
Owncloud Owncloud
4.3
CVSSv2
CVE-2017-8896
ownCloud Server prior to 8.2.12, 9.0.x prior to 9.0.10, 9.1.x prior to 9.1.6, and 10.0.x prior to 10.0.2 are vulnerable to XSS on error pages by injecting code in url parameters.
Owncloud Owncloud
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4367
CVE-2024-35977
CVE-2023-49335
man-in-the-middle
CVE-2024-4947
CVE-2024-31714
memory leak
SQL
CVE-2024-35994
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »