CVE-2023-49105
- EPSS 86.24%
- Published 21.11.2023 22:15:08
- Last modified 02.04.2025 14:17:25
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-si...
CVE-2021-29659
- EPSS 0.3%
- Published 20.05.2021 13:15:07
- Last modified 31.03.2025 11:54:18
ownCloud 10.7 has an incorrect access control vulnerability, leading to remote information disclosure. Due to a bug in the related API endpoint, the attacker can enumerate all users in a single request by entering three whitespaces. Secondary, the re...
CVE-2020-36252
- EPSS 0.09%
- Published 19.02.2021 07:15:13
- Last modified 31.03.2025 11:54:18
ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version of any file by sending a request for a predictable ID number.
CVE-2015-4715
- EPSS 1.36%
- Published 17.02.2020 19:15:11
- Last modified 31.03.2025 11:54:18
The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary file...
CVE-2014-2052
- EPSS 0.99%
- Published 11.02.2020 16:15:12
- Last modified 31.03.2025 11:54:18
Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
CVE-2014-2050
- EPSS 0.25%
- Published 23.01.2020 20:15:11
- Last modified 31.03.2025 11:54:18
Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header.
CVE-2013-0202
- EPSS 0.4%
- Published 17.12.2019 18:15:13
- Last modified 31.03.2025 11:54:18
Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to core/ajax/sharing.php.
CVE-2013-0203
- EPSS 0.24%
- Published 22.11.2019 19:15:11
- Last modified 31.03.2025 11:54:18
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) unspecified parameters to apps/calendar/ajax/event/new.php or (2) url parameter to ap...
CVE-2016-1501
- EPSS 0.11%
- Published 08.01.2016 21:59:09
- Last modified 12.04.2025 10:46:40
ownCloud Server before 8.0.9 and 8.1.x before 8.1.4 allow remote authenticated users to obtain sensitive information via unspecified vectors, which reveals the installation path in the resulting exception messages.
CVE-2016-1500
- EPSS 0.29%
- Published 08.01.2016 21:59:08
- Last modified 12.04.2025 10:46:40
ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote authenticated users to read the...