Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2727▼ 85 respecto a la semana anterior
Críticas / altas1416▲ 186 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
176 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.27% | — | Onlyoffice Ownclouds IntegrationAIOwncloudsAI | 8/9/2026 | 10/9/2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server URL before initiating outbound connections. An authenticated administrator can… | |
| Aplazada | Alta (8.2) | 0.28% | — | Owncloud DrawioAIOwncloud ClassicAI | 6/7/2026 | 29/9/2026 | DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application ownCloud Classic. In DrawIO for ownCloud prior to version 1.0.2, which corresponds to ownCloud 10 prior to version 10.15.3, attackers with access to the DrawIO app can leverage improper neutralization… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Owncloud Anti-virusAIOwncloudAI | 6/7/2026 | 30/9/2026 | Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud. Versions of Anti-Virus for ownCloud before 1.2.3 are vulnerable to Server-Side Request Forgery (SSRF). This corresponds to versions of ownCloud 10 prior to 10.15.3. Upgrade ownCloud 10 to version… | |
| Aplazada | Alta (8) | 0.51% | — | OwncloudAI | 6/7/2026 | 30/9/2026 | ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attacker with administrative privileges can exploit a path traversal vulnerability in the system to execute arbitrary code. Upgrade ownCloud 10 to version 10.15.3 or later to receive a patch. | |
| Aplazada | Alta (8.5) | 0.39% | — | OwncloudAISharepoint FOR OwncloudAI | 6/7/2026 | 30/9/2026 | SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing application ownCloud Classic. In SharePoint for ownCloud prior to version 0.4.1, which corresponds to ownCloud 10 prior to 10.15.3, an attacker with administrative privileges can use a SSRF vulnerability… | |
| Aplazada | Crítica (9.1) | 0.61% | — | Owncloud CoreAIOwncloud UpdaterAI | 6/7/2026 | 30/9/2026 | ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions prior to 10.15.3, the Updater on ownCloud 10 before 10.15.3 has an exposed dangerous method or function. Attackers with administrative privileges may leverage functionality to execute… | |
| Aplazada | Media (5.3) | 0.42% | — | OwncloudAI | 12/2/2026 | 17/6/2026 | OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by manipulating the share.php endpoint. Attackers can send crafted GET requests to /index.php/core/ajax/share.php with a wildcard search parameter to retrieve comprehensive user information. | |
| Analizada | Media (5.3) | 0.89% | — | Owncloud Guests | 5/11/2025 | 17/6/2026 | ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient validation of the supplied token in showPasswordForm, the server responds differently when an e-mail address corresponds to a valid pending guest user rather than a… | |
| Aplazada | Media (6.8) | 0.45% | — | Owncloud Android APKAI | 22/11/2024 | 17/6/2026 | An issue in Owncloud android apk v.4.3.1 allows a physically proximate attacker to escalate privileges via the PassCodeViewModel class, specifically in the checkPassCodeIsValid method | |
| Aplazada | Media (6.8) | 0.22% | — | OwncloudAI | 1/10/2024 | 17/6/2026 | Cross site request forgery in Kiteworks OwnCloud allows an unauthenticated attacker to forge requests. If a request has no Authorization header, it is created with an empty string as value by a rewrite rule. The CSRF check is done by comparing the header value to null, meaning that the existing CSRF check is bypassed… | |
| Analizada | Crítica (9.8) | 43% | ⚠ Explotación activa | Owncloud Server | 21/11/2023 | 28/8/2026 | An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for… | |
| Modificada | Media (6.1) | 0.56% | — | Owncloud Oauth2 | 21/11/2023 | 17/6/2026 | An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able to pass in a crafted redirect-url that bypasses validation, and consequently allows an attacker to redirect callbacks to a Top Level Domain controlled by the attacker. | |
| Analizada | Alta (7.5) | 78% | ⚠ Explotación activa | Owncloud Graph API | 21/11/2023 | 17/6/2026 | An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the… | |
| Analizada | Media (4.4) | 0.52% | — | Owncloud Client | 13/2/2023 | 17/6/2026 | The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Prior to version 3.0, the app has an incomplete fix for a path traversal issue and is vulnerable to two bypass methods. The bypasses may lead to information disclosure when uploading the app’s internal files, and to arbitrary… | |
| Modificada | Media (5.5) | 0.46% | — | Owncloud Client | 13/2/2023 | 17/6/2026 | The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCloud Android app is vulnerable to SQL injection in `FileContentProvider.kt`. This issue can lead to information disclosure. Two databases, `filelist` and `owncloud_database`, are affected. In version… | |
| Modificada | Media (5.3) | 0.34% | — | Owncloud | 10/11/2022 | 17/6/2026 | The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config useless. This could be abused to spoof the URL in password-reset e-mail messages. | |
| Modificada | Alta (7.5) | 1.3% | — | Owncloud | 9/6/2022 | 17/6/2026 | ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer. | |
| Analizada | Media (5.5) | 0.22% | — | Owncloud Client | 7/4/2022 | 17/6/2026 | ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers. | |
| Analizada | Media (6.8) | 0.24% | — | Owncloud Client | 7/4/2022 | 17/6/2026 | ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers. | |
| Modificada | Alta (7.8) | 2.7% | — | Owncloud Desktop ClientFedoraproject Fedora | 15/1/2022 | 17/6/2026 | ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution. | |
| Modificada | Alta (8.8) | 1.2% | — | Owncloud Files Antivirus | 15/1/2022 | 17/6/2026 | The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detection. | |
| Modificada | Alta (7.2) | 2.1% | — | Owncloud Files Antivirus | 15/1/2022 | 17/6/2026 | The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings. | |
| Modificada | Baja (2.7) | 0.69% | — | Owncloud User Ldap | 8/9/2021 | 17/6/2026 | Server Side Request Forgery (SSRF) vulnerability exists in owncloud/user_ldap < 0.15.4 in the settings of the user_ldap app. Administration role is necessary for exploitation. | |
| Modificada | Media (5.4) | 0.69% | — | Owncloud | 7/9/2021 | 17/6/2026 | Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie. | |
| Modificada | Crítica (9.8) | 1.5% | — | Owncloud | 7/9/2021 | 17/6/2026 | A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate their own permissions. |