ownCloud records
169 published records for vendor owncloud.
Researcher profile
- Entered KEV
- 2 · 1.2%
- Weaponized
- 2 · 1.2%
- Pre-auth RCE
- 5
- With a fix record
- 11.8%
- Median publish → KEV
- 510 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')40
- CWE-264 Permissions, Privileges, and Access Controls16
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor13
- CWE-352 Cross-Site Request Forgery (CSRF)11
- CWE-20 Improper Input Validation8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
The weakness classes this vendor ships most often: where to look.
CWEAll records
169 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
84Now | CVE-2023-49103Weaponized | An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1.owncloud · graph api · CWE-200 | High7.5 | KEV | 78.4% | Nov 21, 2023 |
82Now | CVE-2023-49105Weaponized | An issue was discovered in ownCloud owncloud/core before 10.13.1.owncloud · owncloud server · CWE-287 | Critical9.8 | KEV | 42.9% | Nov 21, 2023 |
47Plan | CVE-2015-4716No exploit | Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, owncloud · owncloud · CWE-22 | Critical10.0 | — | 24.8% | Oct 21, 2015 |
40Plan | CVE-2014-2048No exploit | The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementatioowncloud · owncloud · CWE-284 | Critical9.8 | — | 2.6% | Mar 26, 2018 |
40Plan | CVE-2014-2052No exploit | Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a deowncloud · owncloud · CWE-611 | Critical9.8 | — | 2.5% | Feb 11, 2020 |
39Monitor | CVE-2021-35946No exploit | A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore eleowncloud · owncloud · CWE-269 | Critical9.8 | — | 1.5% | Sep 7, 2021 |
37Monitor | CVE-2015-7699No exploit | The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to instowncloud · owncloud server · CWE-20 | Critical9.0 | — | 4.0% | Oct 26, 2015 |
37Monitor | CVE-2015-4718No exploit | The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated userowncloud · owncloud · CWE-78 | Critical9.0 | — | 3.0% | Oct 21, 2015 |
37Monitor | CVE-2015-7698No exploit | icewind1991 SMB before 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argumeowncloud · smb · CWE-78 | Critical9.0 | — | 2.5% | Oct 21, 2015 |
36Monitor | CVE-2020-28645No exploit | Deleting users with certain names caused system files to be deleted.owncloud · owncloud · CWE-20 | Critical9.1 | — | 1.2% | Feb 9, 2021 |
35Monitor | CVE-2016-1499No exploit | ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information fowncloud · owncloud · CWE-200 | High8.5 | — | 3.5% | Jan 8, 2016 |
35Monitor | CVE-2021-33828No exploit | The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploadeowncloud · files antivirus · CWE-434 | High8.8 | — | 1.2% | Jan 15, 2022 |
34Monitor | CVE-2014-2044Proof of concept | Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to owncloud · owncloud · CWE-94 | High7.5 | — | 12.4% | Oct 6, 2014 |
33Monitor | CVE-2016-9463No exploit | Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass.nextcloud · nextcloud server · CWE-303 | High8.1 | — | 4.1% | Mar 27, 2017 |
33Monitor | CVE-2020-10252No exploit | An issue was discovered in ownCloud before 10.4.owncloud · owncloud · CWE-918 | High8.3 | — | 1.2% | Feb 19, 2021 |
33Monitor | CVE-2016-7102No exploit | ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special powncloud · owncloud desktop client · CWE-94 | High8.4 | — | 0.5% | Jan 23, 2017 |
32Monitor | CVE-2015-4717No exploit | The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_Gowncloud · owncloud · CWE-399 | High7.8 | — | 2.8% | Oct 21, 2015 |
32Monitor | CVE-2021-44537No exploit | ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code executowncloud · owncloud desktop client · CWE-74 | High7.8 | — | 2.7% | Jan 15, 2022 |
31Monitor | CVE-2014-2053No exploit | getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, caugetid3 · getid3 | High7.5 | — | 4.7% | Jun 4, 2014 |
31Monitor | CVE-2012-4392No exploit | index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a craowncloud · owncloud server · CWE-287 | High7.5 | — | 2.8% | Sep 5, 2012 |
31Monitor | CVE-2015-6500No exploit | Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated users to list directoryowncloud · owncloud server · CWE-22 | High7.5 | — | 2.6% | Oct 26, 2015 |
31Monitor | CVE-2014-2056No exploit | PHPDocX, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial ofowncloud · owncloud server | High7.5 | — | 2.3% | Jun 4, 2014 |
31Monitor | CVE-2014-2055No exploit | SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, caowncloud · owncloud server | High7.5 | — | 2.2% | Jun 4, 2014 |
31Monitor | CVE-2020-28646No exploit | ownCloud owncloud/client before 2.7 allows DLL Injection.owncloud · owncloud desktop client · CWE-427 | High7.8 | — | 0.8% | Feb 26, 2021 |
30Monitor | CVE-2014-2054No exploit | PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, owncloud · owncloud server | High7.5 | — | 1.5% | Jun 4, 2014 |
- CVE-2023-4910384Now
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1.
HighCVSS 7.5KEVWeaponizedEPSS 78%owncloud · graph apiNov 21, 2023
- CVE-2023-4910582Now
An issue was discovered in ownCloud owncloud/core before 10.13.1.
CriticalCVSS 9.8KEVWeaponizedEPSS 43%owncloud · owncloud serverNov 21, 2023
- CVE-2015-471647Plan
Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows,
CriticalCVSS 10.0No exploitEPSS 25%owncloud · owncloudOct 21, 2015
- CVE-2014-204840Plan
The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementatio
CriticalCVSS 9.8No exploitEPSS 3%owncloud · owncloudMar 26, 2018
- CVE-2014-205240Plan
Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a de
CriticalCVSS 9.8No exploitEPSS 2%owncloud · owncloudFeb 11, 2020
- CVE-2021-3594639Monitor
A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore ele
CriticalCVSS 9.8No exploitEPSS 1%owncloud · owncloudSep 7, 2021
- CVE-2015-769937Monitor
The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to inst
CriticalCVSS 9.0No exploitEPSS 4%owncloud · owncloud serverOct 26, 2015
- CVE-2015-471837Monitor
The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated user
CriticalCVSS 9.0No exploitEPSS 3%owncloud · owncloudOct 21, 2015
- CVE-2015-769837Monitor
icewind1991 SMB before 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argume
CriticalCVSS 9.0No exploitEPSS 2%owncloud · smbOct 21, 2015
- CVE-2020-2864536Monitor
Deleting users with certain names caused system files to be deleted.
CriticalCVSS 9.1No exploitEPSS 1%owncloud · owncloudFeb 9, 2021
- CVE-2016-149935Monitor
ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information f
HighCVSS 8.5No exploitEPSS 3%owncloud · owncloudJan 8, 2016
- CVE-2021-3382835Monitor
The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploade
HighCVSS 8.8No exploitEPSS 1%owncloud · files antivirusJan 15, 2022
- CVE-2014-204434Monitor
Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to
HighCVSS 7.5Proof of conceptEPSS 12%owncloud · owncloudOct 6, 2014
- CVE-2016-946333Monitor
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass.
HighCVSS 8.1No exploitEPSS 4%nextcloud · nextcloud serverMar 27, 2017
- CVE-2020-1025233Monitor
An issue was discovered in ownCloud before 10.4.
HighCVSS 8.3No exploitEPSS 1%owncloud · owncloudFeb 19, 2021
- CVE-2016-710233Monitor
ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special p
HighCVSS 8.4No exploitEPSS 1%owncloud · owncloud desktop clientJan 23, 2017
- CVE-2015-471732Monitor
The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_G
HighCVSS 7.8No exploitEPSS 3%owncloud · owncloudOct 21, 2015
- CVE-2021-4453732Monitor
ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execut
HighCVSS 7.8No exploitEPSS 3%owncloud · owncloud desktop clientJan 15, 2022
- CVE-2014-205331Monitor
getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cau
HighCVSS 7.5No exploitEPSS 5%getid3 · getid3Jun 4, 2014
- CVE-2012-439231Monitor
index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a cra
HighCVSS 7.5No exploitEPSS 3%owncloud · owncloud serverSep 5, 2012
- CVE-2015-650031Monitor
Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated users to list directory
HighCVSS 7.5No exploitEPSS 3%owncloud · owncloud serverOct 26, 2015
- CVE-2014-205631Monitor
PHPDocX, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of
HighCVSS 7.5No exploitEPSS 2%owncloud · owncloud serverJun 4, 2014
- CVE-2014-205531Monitor
SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, ca
HighCVSS 7.5No exploitEPSS 2%owncloud · owncloud serverJun 4, 2014
- CVE-2020-2864631Monitor
ownCloud owncloud/client before 2.7 allows DLL Injection.
HighCVSS 7.8No exploitEPSS 1%owncloud · owncloud desktop clientFeb 26, 2021
- CVE-2014-205430Monitor
PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml,
HighCVSS 7.5No exploitEPSS 2%owncloud · owncloud serverJun 4, 2014