Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
owncloud owncloud vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2023-49105
An issue exists in ownCloud owncloud/core prior to 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when ...
Owncloud Owncloud
1 Github repository
1 Article
9.8
CVSSv3
CVE-2021-35946
A receiver of a federated share with access to the database with ownCloud version prior to 10.8 could update the permissions and therefore elevate their own permissions.
Owncloud Owncloud
9.8
CVSSv3
CVE-2014-2052
Zend Framework, as used in ownCloud Server prior to 5.0.15 and 6.0.x prior to 6.0.2, allows remote malicious users to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
Owncloud Owncloud
9.8
CVSSv3
CVE-2014-2048
The user_openid app in ownCloud Server prior to 5.0.15 allows remote malicious users to obtain access by leveraging an insecure OpenID implementation.
Owncloud Owncloud
9.1
CVSSv3
CVE-2020-28645
Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the data directory in the web root. This affects ownCloud/core versions < 10.6.
Owncloud Owncloud
8.8
CVSSv3
CVE-2021-33828
The files_antivirus component prior to 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detection.
Owncloud Files Antivirus
8.5
CVSSv3
CVE-2016-1499
ownCloud Server prior to 8.0.10, 8.1.x prior to 8.1.5, and 8.2.x prior to 8.2.2 allow remote authenticated users to obtain sensitive information from a directory listing and possibly cause a denial of service (CPU consumption) via the force parameter to index.php/apps/files/ajax/...
Owncloud Owncloud 8.1.1
Owncloud Owncloud 8.1.3
Owncloud Owncloud 8.1.4
Owncloud Owncloud 8.2.0
Owncloud Owncloud
Owncloud Owncloud 8.1.0
Owncloud Owncloud 8.2.1
8.4
CVSSv3
CVE-2016-7102
ownCloud Desktop prior to 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special path" in the C: drive.
Owncloud Owncloud Desktop Client
8.3
CVSSv3
CVE-2020-10252
An issue exists in ownCloud prior to 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated attacker can interact with local services blindly (aka Blind SSRF) or conduct a Denial Of Service attack.
Owncloud Owncloud
8.1
CVSSv3
CVE-2016-9463
Nextcloud Server prior to 9.0.54 and 10.0.1 & ownCloud Server prior to 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass. Nextcloud/ownCloud include an optional and not by default enabled SMB authentication component that allows authenticating users against a...
Owncloud Owncloud
Nextcloud Nextcloud Server
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »