Filtered by vendor Owncloud Subscriptions
Total 169 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-28646 1 Owncloud 1 Owncloud Desktop Client 2024-11-21 7.8 High
ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were present.
CVE-2020-28645 1 Owncloud 1 Owncloud 2024-11-21 9.1 Critical
Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the data directory in the web root. This affects ownCloud/core versions < 10.6.
CVE-2020-28644 1 Owncloud 1 Owncloud 2024-11-21 4.3 Medium
The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6.
CVE-2020-16255 1 Owncloud 1 Owncloud 2024-11-21 6.1 Medium
ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'
CVE-2020-16144 1 Owncloud 1 Files Antivirus 2024-11-21 5.7 Medium
When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and another user uploads a virus the files antivirus app would detect the virus but fails to delete it due to permission issues. This affects the files_antivirus component versions before 0.15.2 for ownCloud.
CVE-2020-10254 1 Owncloud 1 Owncloud 2024-11-21 5.9 Medium
An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview.
CVE-2020-10252 1 Owncloud 1 Owncloud 2024-11-21 8.3 High
An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated attacker can interact with local services blindly (aka Blind SSRF) or conduct a Denial Of Service attack.
CVE-2014-2048 1 Owncloud 1 Owncloud 2024-11-21 N/A
The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementation.
CVE-2014-1665 1 Owncloud 1 Owncloud 2024-11-21 N/A
Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.