İçeriğe atla
Noroxi

ampache kayıtları

ampache üreticisine ait 25 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%48
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

25 kayıt
  • CVE-2020-15153
    40Planlayın

    Unauthenticated SQL injection in Ampache

    KritikCVSS 9,8İstismar yokEPSS %2

    ampache · ampache30 Nis 2021

  • CVE-2024-51490
    36İzleyin

    Stored Cross-Site Scripting in Ampache

    KritikCVSS 9,0İstismar yokEPSS %1

    ampache · ampache11 Kas 2024

  • CVE-2019-12385
    35İzleyin

    An issue was discovered in Ampache through 3.9.1.

    YüksekCVSS 8,8İstismar yokEPSS %2

    ampache · ampache22 Ağu 2019

  • CVE-2017-18375
    35İzleyin

    Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.

    YüksekCVSS 8,8İstismar yokEPSS %2

    ampache · ampache24 May 2019

  • CVE-2022-4665
    35İzleyin

    Unrestricted Upload of File with Dangerous Type in ampache/ampache

    YüksekCVSS 8,8İstismar yokEPSS %1

    ampache · ampache22 Ara 2022

  • CVE-2023-0771
    35İzleyin

    SQL Injection in ampache/ampache

    YüksekCVSS 8,8İstismar yokEPSS %1

    ampache · ampache9 Şub 2023

  • CVE-2024-51486
    33İzleyin

    Stored Cross-Site Scripting in Ampache

    YüksekCVSS 8,4İstismar yokEPSS %0

    ampache · ampache11 Kas 2024

  • CVE-2006-5668
    30İzleyin

    Unspecified vulnerability in Ampache 3.3.2 and earlier, when register_globals is enabled, allows remote attackers to bypass security restric

    YüksekCVSS 7,5İstismar yokEPSS %2

    ampache · ampache2 Kas 2006

  • CVE-2021-21399
    30İzleyin

    Unauthenticated SubSonic backend access in Ampache

    YüksekCVSS 7,5İstismar yokEPSS %1

    ampache · ampache13 Nis 2021

  • CVE-2008-3929
    28İzleyin

    gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary file

    YüksekCVSS 7,2İstismar yokEPSS %0

    ampache · ampache4 Eyl 2008

  • CVE-2007-4438
    27İzleyin

    Session fixation vulnerability in Ampache before 3.3.3.5 allows remote attackers to hijack web sessions via unspecified vectors.

    OrtaCVSS 6,8İstismar yokEPSS %1

    ampache · ampache20 Ağu 2007

  • CVE-2007-4437
    27İzleyin

    SQL injection vulnerability in albums.php in Ampache before 3.3.3.5 allows remote attackers to execute arbitrary SQL commands via the match

    OrtaCVSS 6,8İstismar yokEPSS %1

    ampache · ampache20 Ağu 2007

  • CVE-2024-47828
    26İzleyin

    Cross-Site Request Forgery in ampache

    OrtaCVSS 6,5İstismar yokEPSS %0

    ampache · ampache9 Eki 2024

  • CVE-2023-0606
    24İzleyin

    Cross-site Scripting (XSS) - Reflected in ampache/ampache

    OrtaCVSS 6,1İstismar yokEPSS %1

    ampache · ampache31 Oca 2023

  • CVE-2024-28852
    24İzleyin

    Ampache has multiple reflective XSS vulnerabilities

    OrtaCVSS 6,1İstismar yokEPSS %1

    ampache · ampache27 Mar 2024

  • CVE-2024-28853
    23İzleyin

    Ampache is a web based audio/video streaming application and file manager.

    OrtaCVSS 5,9İstismar yokEPSS %1

    ampache · ampache27 Mar 2024

  • CVE-2021-32644
    21İzleyin

    Cross-site Scripting in Random.php

    OrtaCVSS 5,4Kavram kanıtıEPSS %1

    ampache · ampache22 Haz 2021

  • CVE-2019-12386
    21İzleyin

    An issue was discovered in Ampache through 3.9.1.

    OrtaCVSS 5,4İstismar yokEPSS %1

    ampache · ampache22 Ağu 2019

  • CVE-2024-41665
    21İzleyin

    Ampache Stored Cross-site Scripting Vulnerability

    OrtaCVSS 5,4İstismar yokEPSS %0

    ampache · ampache23 Tem 2024

  • CVE-2024-51485
    21İzleyin

    Insufficient Validation in Plugins (Activation/Deactivation) in Ampache

    OrtaCVSS 5,3İstismar yokEPSS %0

    ampache · ampache11 Kas 2024

  • CVE-2024-51484
    21İzleyin

    Insufficient Validation in Controllers (Activation/Deactivation) in Ampache

    OrtaCVSS 5,3İstismar yokEPSS %0

    ampache · ampache11 Kas 2024

  • CVE-2024-51487
    21İzleyin

    Insufficient Validation in Catalog (Activation/Deactivation) in Ampache

    OrtaCVSS 5,3İstismar yokEPSS %0

    ampache · ampache11 Kas 2024

  • CVE-2024-51489
    21İzleyin

    Insufficient Message Token Validation in Ampache

    OrtaCVSS 5,3İstismar yokEPSS %0

    ampache · ampache11 Kas 2024

  • CVE-2024-51488
    21İzleyin

    Insufficient Validation in Delete Message in Ampache

    OrtaCVSS 5,3İstismar yokEPSS %0

    ampache · ampache11 Kas 2024

  • CVE-2024-47184
    19İzleyin

    Ampache vulnerable to Stored XSS via Democratic Playlist Name

    OrtaCVSS 4,8İstismar yokEPSS %1

    ampache · ampache27 Eyl 2024