Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

176 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.91%—Owncloud7/9/202117/6/2026
The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list metadata about the share.
ModificadaMedia (5.3)1.3%—Owncloud7/9/202117/6/2026
The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a public share by including invalid characters in the URL.
ModificadaMedia (6.5)1.3%—Owncloud Server20/5/202117/6/2026
ownCloud 10.7 has an incorrect access control vulnerability, leading to remote information disclosure. Due to a bug in the related API endpoint, the attacker can enumerate all users in a single request by entering three whitespaces. Secondary, the retrieval of all users on a large instance could cause higher than…
ModificadaAlta (7.8)0.77%—Owncloud Desktop Client26/2/202117/6/2026
ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were present.
ModificadaMedia (4.6)0.14%—Owncloud Client19/2/202117/6/2026
The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a backup archive, and consequently bypass the PIN lock feature by restoring from this archive.
ModificadaMedia (5.7)0.51%—Owncloud Server19/2/202117/6/2026
ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version of any file by sending a request for a predictable ID number.
ModificadaMedia (4.3)0.62%—Owncloud19/2/202117/6/2026
ownCloud Server before 10.3.0 allows an attacker, who has received non-administrative access to a group share, to remove everyone else's access to that share.
ModificadaMedia (4.6)0.27%—Owncloud Client19/2/202117/6/2026
In the ownCloud application before 2.15 for Android, the lock protection mechanism can be bypassed by moving the system date/time into the past.
ModificadaAlta (7.5)0.86%—Owncloud File Firewall19/2/202117/6/2026
The File Firewall before 2.8.0 for ownCloud Server does not properly enforce file-type restrictions for public shares.
ModificadaMedia (5.9)1.9%—Owncloud19/2/202117/6/2026
An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview.
ModificadaAlta (8.3)1.2%—Owncloud19/2/202117/6/2026
An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated attacker can interact with local services blindly (aka Blind SSRF) or conduct a Denial Of Service attack.
ModificadaCrítica (9.1)1.2%—Owncloud9/2/202117/6/2026
Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the data directory in the web root. This affects ownCloud/core versions < 10.6.
ModificadaMedia (4.3)0.46%—Owncloud9/2/202117/6/2026
The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6.
ModificadaMedia (5.7)0.80%—Owncloud Files Antivirus9/2/202117/6/2026
When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and another user uploads a virus the files antivirus app would detect the virus but fails to delete it due to permission issues. This affects the files_antivirus component…
ModificadaMedia (6.1)0.85%—Owncloud15/1/202117/6/2026
ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'
ModificadaMedia (4.9)1.4%—OwncloudOwncloud Server17/2/202017/6/2026
The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.
ModificadaCrítica (9.8)2.5%—OwncloudOwncloud Server11/2/202017/6/2026
Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
ModificadaMedia (6.5)1.5%—OwncloudOwncloud Server23/1/202017/6/2026
Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header.
ModificadaMedia (6.1)0.95%—Owncloud Server17/12/201916/6/2026
Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to core/ajax/sharing.php.
ModificadaMedia (5.4)0.72%—OwncloudOwncloud Server22/11/201916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) unspecified parameters to apps/calendar/ajax/event/new.php or (2) url parameter to apps/bookmarks/ajax/addBookmark.php.
ModificadaCrítica (9.8)2.6%—Owncloud26/3/201817/6/2026
The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementation.
ModificadaMedia (5.4)3.0%—Owncloud20/3/201817/6/2026
Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.
ModificadaMedia (6.5)1.00%—Owncloud17/7/201717/6/2026
An attacker is logged in as a normal user and can somehow make admin to delete shared folders in ownCloud Server before 10.0.2.
ModificadaMedia (5.3)1.0%—Owncloud17/7/201717/6/2026
A logical error in ownCloud Server before 10.0.2 caused disclosure of valid share tokens for public calendars. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.
ModificadaMedia (5.4)0.60%—Owncloud17/7/201717/6/2026
Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2. To be exploitable a user has to write or paste malicious content into the search dialogue.