ampache kayıtları
ampache üreticisine ait 25 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %48
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-284 Improper Access Control1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-502 Deserialization of Untrusted Data1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
25 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-15153İstismar yok | Unauthenticated SQL injection in Ampacheampache · ampache · CWE-89 | Kritik9,8 | — | %2,4 | 30 Nis 2021 |
36İzleyin | CVE-2024-51490İstismar yok | Stored Cross-Site Scripting in Ampacheampache · ampache · CWE-79 | Kritik9,0 | — | %0,5 | 11 Kas 2024 |
35İzleyin | CVE-2019-12385İstismar yok | An issue was discovered in Ampache through 3.9.1.ampache · ampache · CWE-89 | Yüksek8,8 | — | %1,6 | 22 Ağu 2019 |
35İzleyin | CVE-2017-18375İstismar yok | Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.ampache · ampache · CWE-502 | Yüksek8,8 | — | %1,6 | 24 May 2019 |
35İzleyin | CVE-2022-4665İstismar yok | Unrestricted Upload of File with Dangerous Type in ampache/ampacheampache · ampache · CWE-434 | Yüksek8,8 | — | %0,8 | 22 Ara 2022 |
35İzleyin | CVE-2023-0771İstismar yok | SQL Injection in ampache/ampacheampache · ampache · CWE-89 | Yüksek8,8 | — | %0,7 | 9 Şub 2023 |
33İzleyin | CVE-2024-51486İstismar yok | Stored Cross-Site Scripting in Ampacheampache · ampache · CWE-79 | Yüksek8,4 | — | %0,5 | 11 Kas 2024 |
30İzleyin | CVE-2006-5668İstismar yok | Unspecified vulnerability in Ampache 3.3.2 and earlier, when register_globals is enabled, allows remote attackers to bypass security restricampache · ampache | Yüksek7,5 | — | %1,6 | 2 Kas 2006 |
30İzleyin | CVE-2021-21399İstismar yok | Unauthenticated SubSonic backend access in Ampacheampache · ampache · CWE-284 | Yüksek7,5 | — | %1,4 | 13 Nis 2021 |
28İzleyin | CVE-2008-3929İstismar yok | gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary fileampache · ampache · CWE-59 | Yüksek7,2 | — | %0,4 | 4 Eyl 2008 |
27İzleyin | CVE-2007-4438İstismar yok | Session fixation vulnerability in Ampache before 3.3.3.5 allows remote attackers to hijack web sessions via unspecified vectors.ampache · ampache · CWE-287 | Orta6,8 | — | %1,5 | 20 Ağu 2007 |
27İzleyin | CVE-2007-4437İstismar yok | SQL injection vulnerability in albums.php in Ampache before 3.3.3.5 allows remote attackers to execute arbitrary SQL commands via the match ampache · ampache | Orta6,8 | — | %1,3 | 20 Ağu 2007 |
26İzleyin | CVE-2024-47828İstismar yok | Cross-Site Request Forgery in ampacheampache · ampache · CWE-352 | Orta6,5 | — | %0,3 | 9 Eki 2024 |
24İzleyin | CVE-2023-0606İstismar yok | Cross-site Scripting (XSS) - Reflected in ampache/ampacheampache · ampache · CWE-79 | Orta6,1 | — | %0,6 | 31 Oca 2023 |
24İzleyin | CVE-2024-28852İstismar yok | Ampache has multiple reflective XSS vulnerabilitiesampache · ampache · CWE-79 | Orta6,1 | — | %0,5 | 27 Mar 2024 |
23İzleyin | CVE-2024-28853İstismar yok | Ampache is a web based audio/video streaming application and file manager.ampache · ampache · CWE-79 | Orta5,9 | — | %0,6 | 27 Mar 2024 |
21İzleyin | CVE-2021-32644Kavram kanıtı | Cross-site Scripting in Random.phpampache · ampache · CWE-79 | Orta5,4 | — | %0,8 | 22 Haz 2021 |
21İzleyin | CVE-2019-12386İstismar yok | An issue was discovered in Ampache through 3.9.1.ampache · ampache · CWE-79 | Orta5,4 | — | %0,8 | 22 Ağu 2019 |
21İzleyin | CVE-2024-41665İstismar yok | Ampache Stored Cross-site Scripting Vulnerabilityampache · ampache · CWE-79 | Orta5,4 | — | %0,5 | 23 Tem 2024 |
21İzleyin | CVE-2024-51485İstismar yok | Insufficient Validation in Plugins (Activation/Deactivation) in Ampacheampache · ampache · CWE-352 | Orta5,3 | — | %0,3 | 11 Kas 2024 |
21İzleyin | CVE-2024-51484İstismar yok | Insufficient Validation in Controllers (Activation/Deactivation) in Ampacheampache · ampache · CWE-352 | Orta5,3 | — | %0,3 | 11 Kas 2024 |
21İzleyin | CVE-2024-51487İstismar yok | Insufficient Validation in Catalog (Activation/Deactivation) in Ampacheampache · ampache · CWE-352 | Orta5,3 | — | %0,3 | 11 Kas 2024 |
21İzleyin | CVE-2024-51489İstismar yok | Insufficient Message Token Validation in Ampacheampache · ampache · CWE-352 | Orta5,3 | — | %0,3 | 11 Kas 2024 |
21İzleyin | CVE-2024-51488İstismar yok | Insufficient Validation in Delete Message in Ampacheampache · ampache · CWE-352 | Orta5,3 | — | %0,3 | 11 Kas 2024 |
19İzleyin | CVE-2024-47184İstismar yok | Ampache vulnerable to Stored XSS via Democratic Playlist Nameampache · ampache · CWE-79 | Orta4,8 | — | %0,6 | 27 Eyl 2024 |
- CVE-2020-1515340Planlayın
Unauthenticated SQL injection in Ampache
KritikCVSS 9,8İstismar yokEPSS %2ampache · ampache30 Nis 2021
- CVE-2024-5149036İzleyin
Stored Cross-Site Scripting in Ampache
KritikCVSS 9,0İstismar yokEPSS %1ampache · ampache11 Kas 2024
- CVE-2019-1238535İzleyin
An issue was discovered in Ampache through 3.9.1.
YüksekCVSS 8,8İstismar yokEPSS %2ampache · ampache22 Ağu 2019
- CVE-2017-1837535İzleyin
Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.
YüksekCVSS 8,8İstismar yokEPSS %2ampache · ampache24 May 2019
- CVE-2022-466535İzleyin
Unrestricted Upload of File with Dangerous Type in ampache/ampache
YüksekCVSS 8,8İstismar yokEPSS %1ampache · ampache22 Ara 2022
- CVE-2023-077135İzleyin
SQL Injection in ampache/ampache
YüksekCVSS 8,8İstismar yokEPSS %1ampache · ampache9 Şub 2023
- CVE-2024-5148633İzleyin
Stored Cross-Site Scripting in Ampache
YüksekCVSS 8,4İstismar yokEPSS %0ampache · ampache11 Kas 2024
- CVE-2006-566830İzleyin
Unspecified vulnerability in Ampache 3.3.2 and earlier, when register_globals is enabled, allows remote attackers to bypass security restric
YüksekCVSS 7,5İstismar yokEPSS %2ampache · ampache2 Kas 2006
- CVE-2021-2139930İzleyin
Unauthenticated SubSonic backend access in Ampache
YüksekCVSS 7,5İstismar yokEPSS %1ampache · ampache13 Nis 2021
- CVE-2008-392928İzleyin
gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary file
YüksekCVSS 7,2İstismar yokEPSS %0ampache · ampache4 Eyl 2008
- CVE-2007-443827İzleyin
Session fixation vulnerability in Ampache before 3.3.3.5 allows remote attackers to hijack web sessions via unspecified vectors.
OrtaCVSS 6,8İstismar yokEPSS %1ampache · ampache20 Ağu 2007
- CVE-2007-443727İzleyin
SQL injection vulnerability in albums.php in Ampache before 3.3.3.5 allows remote attackers to execute arbitrary SQL commands via the match
OrtaCVSS 6,8İstismar yokEPSS %1ampache · ampache20 Ağu 2007
- CVE-2024-4782826İzleyin
Cross-Site Request Forgery in ampache
OrtaCVSS 6,5İstismar yokEPSS %0ampache · ampache9 Eki 2024
- CVE-2023-060624İzleyin
Cross-site Scripting (XSS) - Reflected in ampache/ampache
OrtaCVSS 6,1İstismar yokEPSS %1ampache · ampache31 Oca 2023
- CVE-2024-2885224İzleyin
Ampache has multiple reflective XSS vulnerabilities
OrtaCVSS 6,1İstismar yokEPSS %1ampache · ampache27 Mar 2024
- CVE-2024-2885323İzleyin
Ampache is a web based audio/video streaming application and file manager.
OrtaCVSS 5,9İstismar yokEPSS %1ampache · ampache27 Mar 2024
- CVE-2021-3264421İzleyin
Cross-site Scripting in Random.php
OrtaCVSS 5,4Kavram kanıtıEPSS %1ampache · ampache22 Haz 2021
- CVE-2019-1238621İzleyin
An issue was discovered in Ampache through 3.9.1.
OrtaCVSS 5,4İstismar yokEPSS %1ampache · ampache22 Ağu 2019
- CVE-2024-4166521İzleyin
Ampache Stored Cross-site Scripting Vulnerability
OrtaCVSS 5,4İstismar yokEPSS %0ampache · ampache23 Tem 2024
- CVE-2024-5148521İzleyin
Insufficient Validation in Plugins (Activation/Deactivation) in Ampache
OrtaCVSS 5,3İstismar yokEPSS %0ampache · ampache11 Kas 2024
- CVE-2024-5148421İzleyin
Insufficient Validation in Controllers (Activation/Deactivation) in Ampache
OrtaCVSS 5,3İstismar yokEPSS %0ampache · ampache11 Kas 2024
- CVE-2024-5148721İzleyin
Insufficient Validation in Catalog (Activation/Deactivation) in Ampache
OrtaCVSS 5,3İstismar yokEPSS %0ampache · ampache11 Kas 2024
- CVE-2024-5148921İzleyin
Insufficient Message Token Validation in Ampache
OrtaCVSS 5,3İstismar yokEPSS %0ampache · ampache11 Kas 2024
- CVE-2024-5148821İzleyin
Insufficient Validation in Delete Message in Ampache
OrtaCVSS 5,3İstismar yokEPSS %0ampache · ampache11 Kas 2024
- CVE-2024-4718419İzleyin
Ampache vulnerable to Stored XSS via Democratic Playlist Name
OrtaCVSS 4,8İstismar yokEPSS %1ampache · ampache27 Eyl 2024