Перейти к содержимому
Noroxi

Записи ampache

25 опубликованных записей вендора ampache.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
48 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

25 записей
  • CVE-2020-15153
    40В плане

    Unauthenticated SQL injection in Ampache

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    ampache · ampache30 апр. 2021 г.

  • CVE-2024-51490
    36Наблюдать

    Stored Cross-Site Scripting in Ampache

    КритическаяCVSS 9,0Эксплойта нетEPSS 1 %

    ampache · ampache11 нояб. 2024 г.

  • CVE-2019-12385
    35Наблюдать

    An issue was discovered in Ampache through 3.9.1.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    ampache · ampache22 авг. 2019 г.

  • CVE-2017-18375
    35Наблюдать

    Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    ampache · ampache24 мая 2019 г.

  • CVE-2022-4665
    35Наблюдать

    Unrestricted Upload of File with Dangerous Type in ampache/ampache

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    ampache · ampache22 дек. 2022 г.

  • CVE-2023-0771
    35Наблюдать

    SQL Injection in ampache/ampache

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    ampache · ampache9 февр. 2023 г.

  • CVE-2024-51486
    33Наблюдать

    Stored Cross-Site Scripting in Ampache

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    ampache · ampache11 нояб. 2024 г.

  • CVE-2006-5668
    30Наблюдать

    Unspecified vulnerability in Ampache 3.3.2 and earlier, when register_globals is enabled, allows remote attackers to bypass security restric

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    ampache · ampache2 нояб. 2006 г.

  • CVE-2021-21399
    30Наблюдать

    Unauthenticated SubSonic backend access in Ampache

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    ampache · ampache13 апр. 2021 г.

  • CVE-2008-3929
    28Наблюдать

    gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary file

    ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %

    ampache · ampache4 сент. 2008 г.

  • CVE-2007-4438
    27Наблюдать

    Session fixation vulnerability in Ampache before 3.3.3.5 allows remote attackers to hijack web sessions via unspecified vectors.

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    ampache · ampache20 авг. 2007 г.

  • CVE-2007-4437
    27Наблюдать

    SQL injection vulnerability in albums.php in Ampache before 3.3.3.5 allows remote attackers to execute arbitrary SQL commands via the match

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    ampache · ampache20 авг. 2007 г.

  • CVE-2024-47828
    26Наблюдать

    Cross-Site Request Forgery in ampache

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    ampache · ampache9 окт. 2024 г.

  • CVE-2023-0606
    24Наблюдать

    Cross-site Scripting (XSS) - Reflected in ampache/ampache

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    ampache · ampache31 янв. 2023 г.

  • CVE-2024-28852
    24Наблюдать

    Ampache has multiple reflective XSS vulnerabilities

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    ampache · ampache27 мар. 2024 г.

  • CVE-2024-28853
    23Наблюдать

    Ampache is a web based audio/video streaming application and file manager.

    СредняяCVSS 5,9Эксплойта нетEPSS 1 %

    ampache · ampache27 мар. 2024 г.

  • CVE-2021-32644
    21Наблюдать

    Cross-site Scripting in Random.php

    СредняяCVSS 5,4Proof of conceptEPSS 1 %

    ampache · ampache22 июн. 2021 г.

  • CVE-2019-12386
    21Наблюдать

    An issue was discovered in Ampache through 3.9.1.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    ampache · ampache22 авг. 2019 г.

  • CVE-2024-41665
    21Наблюдать

    Ampache Stored Cross-site Scripting Vulnerability

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    ampache · ampache23 июл. 2024 г.

  • CVE-2024-51485
    21Наблюдать

    Insufficient Validation in Plugins (Activation/Deactivation) in Ampache

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    ampache · ampache11 нояб. 2024 г.

  • CVE-2024-51484
    21Наблюдать

    Insufficient Validation in Controllers (Activation/Deactivation) in Ampache

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    ampache · ampache11 нояб. 2024 г.

  • CVE-2024-51487
    21Наблюдать

    Insufficient Validation in Catalog (Activation/Deactivation) in Ampache

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    ampache · ampache11 нояб. 2024 г.

  • CVE-2024-51489
    21Наблюдать

    Insufficient Message Token Validation in Ampache

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    ampache · ampache11 нояб. 2024 г.

  • CVE-2024-51488
    21Наблюдать

    Insufficient Validation in Delete Message in Ampache

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    ampache · ampache11 нояб. 2024 г.

  • CVE-2024-47184
    19Наблюдать

    Ampache vulnerable to Stored XSS via Democratic Playlist Name

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    ampache · ampache27 сент. 2024 г.