Vulnerabilities > Owncloud > High

DATE CVE VULNERABILITY TITLE RISK
2023-11-21 CVE-2023-49103 Unspecified vulnerability in Owncloud Graph API 0.2.0/0.3.0
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1.
network
low complexity
owncloud
7.5
2022-06-09 CVE-2022-31649 Exposure of Resource to Wrong Sphere vulnerability in Owncloud
ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.
network
low complexity
owncloud CWE-668
7.5
2022-01-15 CVE-2021-33827 OS Command Injection vulnerability in Owncloud Files Antivirus
The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.
network
low complexity
owncloud CWE-78
7.2
2022-01-15 CVE-2021-33828 Unrestricted Upload of File with Dangerous Type vulnerability in Owncloud Files Antivirus
The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detection.
network
low complexity
owncloud CWE-434
8.8
2022-01-15 CVE-2021-44537 Injection vulnerability in multiple products
ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.
local
low complexity
owncloud fedoraproject CWE-74
7.8
2021-02-26 CVE-2020-28646 Uncontrolled Search Path Element vulnerability in Owncloud Desktop Client
ownCloud owncloud/client before 2.7 allows DLL Injection.
local
low complexity
owncloud CWE-427
7.8
2021-02-19 CVE-2020-36249 Unspecified vulnerability in Owncloud File Firewall
The File Firewall before 2.8.0 for ownCloud Server does not properly enforce file-type restrictions for public shares.
network
low complexity
owncloud
7.5
2021-02-19 CVE-2020-10252 Server-Side Request Forgery (SSRF) vulnerability in Owncloud
An issue was discovered in ownCloud before 10.4.
network
low complexity
owncloud CWE-918
8.3
2017-03-28 CVE-2016-9463 Improper Authentication vulnerability in multiple products
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass.
network
high complexity
owncloud nextcloud CWE-287
8.1
2017-01-23 CVE-2016-7102 Code Injection vulnerability in Owncloud Desktop Client
ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special path" in the C: drive.
local
low complexity
owncloud CWE-94
8.4