Записи ampache
25 опубликованных записей вендора ampache.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 48 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-284 Improper Access Control1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-502 Deserialization of Untrusted Data1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
25 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-15153Эксплойта нет | Unauthenticated SQL injection in Ampacheampache · ampache · CWE-89 | Критическая9,8 | — | 2,4 % | 30 апр. 2021 г. |
36Наблюдать | CVE-2024-51490Эксплойта нет | Stored Cross-Site Scripting in Ampacheampache · ampache · CWE-79 | Критическая9,0 | — | 0,5 % | 11 нояб. 2024 г. |
35Наблюдать | CVE-2019-12385Эксплойта нет | An issue was discovered in Ampache through 3.9.1.ampache · ampache · CWE-89 | Высокая8,8 | — | 1,6 % | 22 авг. 2019 г. |
35Наблюдать | CVE-2017-18375Эксплойта нет | Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.ampache · ampache · CWE-502 | Высокая8,8 | — | 1,6 % | 24 мая 2019 г. |
35Наблюдать | CVE-2022-4665Эксплойта нет | Unrestricted Upload of File with Dangerous Type in ampache/ampacheampache · ampache · CWE-434 | Высокая8,8 | — | 0,8 % | 22 дек. 2022 г. |
35Наблюдать | CVE-2023-0771Эксплойта нет | SQL Injection in ampache/ampacheampache · ampache · CWE-89 | Высокая8,8 | — | 0,7 % | 9 февр. 2023 г. |
33Наблюдать | CVE-2024-51486Эксплойта нет | Stored Cross-Site Scripting in Ampacheampache · ampache · CWE-79 | Высокая8,4 | — | 0,5 % | 11 нояб. 2024 г. |
30Наблюдать | CVE-2006-5668Эксплойта нет | Unspecified vulnerability in Ampache 3.3.2 and earlier, when register_globals is enabled, allows remote attackers to bypass security restricampache · ampache | Высокая7,5 | — | 1,6 % | 2 нояб. 2006 г. |
30Наблюдать | CVE-2021-21399Эксплойта нет | Unauthenticated SubSonic backend access in Ampacheampache · ampache · CWE-284 | Высокая7,5 | — | 1,4 % | 13 апр. 2021 г. |
28Наблюдать | CVE-2008-3929Эксплойта нет | gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary fileampache · ampache · CWE-59 | Высокая7,2 | — | 0,4 % | 4 сент. 2008 г. |
27Наблюдать | CVE-2007-4438Эксплойта нет | Session fixation vulnerability in Ampache before 3.3.3.5 allows remote attackers to hijack web sessions via unspecified vectors.ampache · ampache · CWE-287 | Средняя6,8 | — | 1,5 % | 20 авг. 2007 г. |
27Наблюдать | CVE-2007-4437Эксплойта нет | SQL injection vulnerability in albums.php in Ampache before 3.3.3.5 allows remote attackers to execute arbitrary SQL commands via the match ampache · ampache | Средняя6,8 | — | 1,3 % | 20 авг. 2007 г. |
26Наблюдать | CVE-2024-47828Эксплойта нет | Cross-Site Request Forgery in ampacheampache · ampache · CWE-352 | Средняя6,5 | — | 0,3 % | 9 окт. 2024 г. |
24Наблюдать | CVE-2023-0606Эксплойта нет | Cross-site Scripting (XSS) - Reflected in ampache/ampacheampache · ampache · CWE-79 | Средняя6,1 | — | 0,6 % | 31 янв. 2023 г. |
24Наблюдать | CVE-2024-28852Эксплойта нет | Ampache has multiple reflective XSS vulnerabilitiesampache · ampache · CWE-79 | Средняя6,1 | — | 0,5 % | 27 мар. 2024 г. |
23Наблюдать | CVE-2024-28853Эксплойта нет | Ampache is a web based audio/video streaming application and file manager.ampache · ampache · CWE-79 | Средняя5,9 | — | 0,6 % | 27 мар. 2024 г. |
21Наблюдать | CVE-2021-32644Proof of concept | Cross-site Scripting in Random.phpampache · ampache · CWE-79 | Средняя5,4 | — | 0,8 % | 22 июн. 2021 г. |
21Наблюдать | CVE-2019-12386Эксплойта нет | An issue was discovered in Ampache through 3.9.1.ampache · ampache · CWE-79 | Средняя5,4 | — | 0,8 % | 22 авг. 2019 г. |
21Наблюдать | CVE-2024-41665Эксплойта нет | Ampache Stored Cross-site Scripting Vulnerabilityampache · ampache · CWE-79 | Средняя5,4 | — | 0,5 % | 23 июл. 2024 г. |
21Наблюдать | CVE-2024-51485Эксплойта нет | Insufficient Validation in Plugins (Activation/Deactivation) in Ampacheampache · ampache · CWE-352 | Средняя5,3 | — | 0,3 % | 11 нояб. 2024 г. |
21Наблюдать | CVE-2024-51484Эксплойта нет | Insufficient Validation in Controllers (Activation/Deactivation) in Ampacheampache · ampache · CWE-352 | Средняя5,3 | — | 0,3 % | 11 нояб. 2024 г. |
21Наблюдать | CVE-2024-51487Эксплойта нет | Insufficient Validation in Catalog (Activation/Deactivation) in Ampacheampache · ampache · CWE-352 | Средняя5,3 | — | 0,3 % | 11 нояб. 2024 г. |
21Наблюдать | CVE-2024-51489Эксплойта нет | Insufficient Message Token Validation in Ampacheampache · ampache · CWE-352 | Средняя5,3 | — | 0,3 % | 11 нояб. 2024 г. |
21Наблюдать | CVE-2024-51488Эксплойта нет | Insufficient Validation in Delete Message in Ampacheampache · ampache · CWE-352 | Средняя5,3 | — | 0,3 % | 11 нояб. 2024 г. |
19Наблюдать | CVE-2024-47184Эксплойта нет | Ampache vulnerable to Stored XSS via Democratic Playlist Nameampache · ampache · CWE-79 | Средняя4,8 | — | 0,6 % | 27 сент. 2024 г. |
- CVE-2020-1515340В плане
Unauthenticated SQL injection in Ampache
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ampache · ampache30 апр. 2021 г.
- CVE-2024-5149036Наблюдать
Stored Cross-Site Scripting in Ampache
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %ampache · ampache11 нояб. 2024 г.
- CVE-2019-1238535Наблюдать
An issue was discovered in Ampache through 3.9.1.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %ampache · ampache22 авг. 2019 г.
- CVE-2017-1837535Наблюдать
Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %ampache · ampache24 мая 2019 г.
- CVE-2022-466535Наблюдать
Unrestricted Upload of File with Dangerous Type in ampache/ampache
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %ampache · ampache22 дек. 2022 г.
- CVE-2023-077135Наблюдать
SQL Injection in ampache/ampache
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %ampache · ampache9 февр. 2023 г.
- CVE-2024-5148633Наблюдать
Stored Cross-Site Scripting in Ampache
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %ampache · ampache11 нояб. 2024 г.
- CVE-2006-566830Наблюдать
Unspecified vulnerability in Ampache 3.3.2 and earlier, when register_globals is enabled, allows remote attackers to bypass security restric
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %ampache · ampache2 нояб. 2006 г.
- CVE-2021-2139930Наблюдать
Unauthenticated SubSonic backend access in Ampache
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ampache · ampache13 апр. 2021 г.
- CVE-2008-392928Наблюдать
gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary file
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %ampache · ampache4 сент. 2008 г.
- CVE-2007-443827Наблюдать
Session fixation vulnerability in Ampache before 3.3.3.5 allows remote attackers to hijack web sessions via unspecified vectors.
СредняяCVSS 6,8Эксплойта нетEPSS 1 %ampache · ampache20 авг. 2007 г.
- CVE-2007-443727Наблюдать
SQL injection vulnerability in albums.php in Ampache before 3.3.3.5 allows remote attackers to execute arbitrary SQL commands via the match
СредняяCVSS 6,8Эксплойта нетEPSS 1 %ampache · ampache20 авг. 2007 г.
- CVE-2024-4782826Наблюдать
Cross-Site Request Forgery in ampache
СредняяCVSS 6,5Эксплойта нетEPSS 0 %ampache · ampache9 окт. 2024 г.
- CVE-2023-060624Наблюдать
Cross-site Scripting (XSS) - Reflected in ampache/ampache
СредняяCVSS 6,1Эксплойта нетEPSS 1 %ampache · ampache31 янв. 2023 г.
- CVE-2024-2885224Наблюдать
Ampache has multiple reflective XSS vulnerabilities
СредняяCVSS 6,1Эксплойта нетEPSS 1 %ampache · ampache27 мар. 2024 г.
- CVE-2024-2885323Наблюдать
Ampache is a web based audio/video streaming application and file manager.
СредняяCVSS 5,9Эксплойта нетEPSS 1 %ampache · ampache27 мар. 2024 г.
- CVE-2021-3264421Наблюдать
Cross-site Scripting in Random.php
СредняяCVSS 5,4Proof of conceptEPSS 1 %ampache · ampache22 июн. 2021 г.
- CVE-2019-1238621Наблюдать
An issue was discovered in Ampache through 3.9.1.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %ampache · ampache22 авг. 2019 г.
- CVE-2024-4166521Наблюдать
Ampache Stored Cross-site Scripting Vulnerability
СредняяCVSS 5,4Эксплойта нетEPSS 0 %ampache · ampache23 июл. 2024 г.
- CVE-2024-5148521Наблюдать
Insufficient Validation in Plugins (Activation/Deactivation) in Ampache
СредняяCVSS 5,3Эксплойта нетEPSS 0 %ampache · ampache11 нояб. 2024 г.
- CVE-2024-5148421Наблюдать
Insufficient Validation in Controllers (Activation/Deactivation) in Ampache
СредняяCVSS 5,3Эксплойта нетEPSS 0 %ampache · ampache11 нояб. 2024 г.
- CVE-2024-5148721Наблюдать
Insufficient Validation in Catalog (Activation/Deactivation) in Ampache
СредняяCVSS 5,3Эксплойта нетEPSS 0 %ampache · ampache11 нояб. 2024 г.
- CVE-2024-5148921Наблюдать
Insufficient Message Token Validation in Ampache
СредняяCVSS 5,3Эксплойта нетEPSS 0 %ampache · ampache11 нояб. 2024 г.
- CVE-2024-5148821Наблюдать
Insufficient Validation in Delete Message in Ampache
СредняяCVSS 5,3Эксплойта нетEPSS 0 %ampache · ampache11 нояб. 2024 г.
- CVE-2024-4718419Наблюдать
Ampache vulnerable to Stored XSS via Democratic Playlist Name
СредняяCVSS 4,8Эксплойта нетEPSS 1 %ampache · ampache27 сент. 2024 г.