ownCloud / Owncloud Server
108 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-49105 KEV | An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of… | CRITICAL | 9.8 | Nov 21, 2023 |
| CVE-2021-29659 | ownCloud 10.7 has an incorrect access control vulnerability, leading to remote information disclosure. Due to a bug in the related API endpoint, the attacker c… | MEDIUM | 6.5 | May 20, 2021 |
| CVE-2020-36252 | ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version of any file by sending a request for a p… | MEDIUM | 6.8 | Feb 19, 2021 |
| CVE-2015-4715 | The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox s… | MEDIUM | 4.9 | Feb 17, 2020 |
| CVE-2014-2052 | Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or… | CRITICAL | 9.8 | Feb 11, 2020 |
| CVE-2014-2050 | Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of… | MEDIUM | 6.5 | Jan 23, 2020 |
| CVE-2013-0203 | Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via th… | MEDIUM | 5.4 | Nov 22, 2019 |
| CVE-2013-0202 | Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via the action p… | MEDIUM | 6.1 | Nov 22, 2019 |
| CVE-2016-1501 | ownCloud Server before 8.0.9 and 8.1.x before 8.1.4 allow remote authenticated users to obtain sensitive information via unspecified vectors, which reveals the… | MEDIUM | 4.3 | Jan 8, 2016 |
| CVE-2016-1500 | ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not prope… | LOW | 3.1 | Jan 8, 2016 |
| CVE-2016-1499 | ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information from a directory lis… | HIGH | 8.5 | Jan 8, 2016 |
| CVE-2016-1498 | Cross-site scripting (XSS) vulnerability in the OCS discovery provider component in ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and… | MEDIUM | 6.1 | Jan 8, 2016 |
| CVE-2015-7699 | The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to instantiate arbitrary c… | HIGH | 9.0 | Oct 26, 2015 |
| CVE-2015-6670 | ownCloud Server before 7.0.8, 8.0.x before 8.0.6, and 8.1.x before 8.1.1 does not properly check ownership of calendars, which allows remote authenticated user… | MEDIUM | 4.0 | Oct 26, 2015 |
| CVE-2015-6500 | Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated users to list directory contents and possi… | HIGH | 7.5 | Oct 26, 2015 |
| CVE-2015-5954 | The virtual filesystem in ownCloud Server before 6.0.9, 7.0.x before 7.0.7, and 8.0.x before 8.0.5 does not consider that NULL is a valid getPath return value,… | MEDIUM | 4.0 | Oct 21, 2015 |
| CVE-2015-4718 | The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated users to execute arbitr… | HIGH | 9.0 | Oct 21, 2015 |
| CVE-2015-4717 | The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_GET parameters cast… | HIGH | 7.8 | Oct 21, 2015 |
| CVE-2015-4716 | Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows remote attac… | HIGH | 10.0 | Oct 21, 2015 |
| CVE-2015-5953 | Cross-site scripting (XSS) vulnerability in the activity application in ownCloud Server before 7.0.5 and 8.0.x before 8.0.4 allows remote authenticated users t… | LOW | 3.5 | Oct 21, 2015 |
| CVE-2015-3013 | ownCloud Server before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allows remote authenticated users to bypass the file blacklist and upload arbitrary files… | MEDIUM | 6.0 | May 8, 2015 |
| CVE-2014-9049 | The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote authenticated users to obtain all valid session IDs via an uns… | MEDIUM | 4.0 | Feb 4, 2015 |
| CVE-2014-9048 | The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote attackers to bypass the password-protection for shared files v… | MEDIUM | 5.0 | Feb 4, 2015 |
| CVE-2014-9047 | Multiple unspecified vulnerabilities in the preview system in ownCloud 6.x before 6.0.6 and 7.x before 7.0.3 allow remote attackers to read arbitrary files via… | MEDIUM | 4.3 | Feb 4, 2015 |
| CVE-2014-9046 | The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to read arbitrary files vi… | MEDIUM | 5.0 | Feb 4, 2015 |
Showing 1 to 25 of 108 CVEs