Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.4) | 0.52% | — | Owncloud Client | 13/2/2023 | 17/6/2026 | The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Prior to version 3.0, the app has an incomplete fix for a path traversal issue and is vulnerable to two bypass methods. The bypasses may lead to information disclosure when uploading the app’s internal files, and to arbitrary… | |
| Modificada | Media (5.5) | 0.46% | — | Owncloud Client | 13/2/2023 | 17/6/2026 | The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCloud Android app is vulnerable to SQL injection in `FileContentProvider.kt`. This issue can lead to information disclosure. Two databases, `filelist` and `owncloud_database`, are affected. In version… | |
| Analizada | Media (5.5) | 0.22% | — | Owncloud Client | 7/4/2022 | 17/6/2026 | ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers. | |
| Analizada | Media (6.8) | 0.24% | — | Owncloud Client | 7/4/2022 | 17/6/2026 | ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers. | |
| Modificada | Media (4.6) | 0.14% | — | Owncloud Client | 19/2/2021 | 17/6/2026 | The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a backup archive, and consequently bypass the PIN lock feature by restoring from this archive. | |
| Modificada | Media (4.6) | 0.27% | — | Owncloud Client | 19/2/2021 | 17/6/2026 | In the ownCloud application before 2.15 for Android, the lock protection mechanism can be bypassed by moving the system date/time into the past. | |
| Modificada | Media (5) | 1.1% | — | Owncloud Client | 29/10/2015 | 17/6/2026 | ownCloud iOS app before 3.4.4 does not properly switch state between multiple instances, which might allow remote instance administrators to obtain sensitive credential and cookie information by reading authentication headers. |