Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.0 CVE-2024-51490 Ampache is a web based audio/video streaming application and file manager. This vulnerability exists in the interface section of the Ampache menu, wh… Ampache No fix yet Fix from $2,3002024-11-11 HIGH 8.4 CVE-2024-51486 Ampache is a web based audio/video streaming application and file manager. The vulnerability exists in the interface section of the Ampache menu, whe… Ampache No fix yet Fix from $1,9502024-11-11 HIGH 8.1 CVE-2024-51484 Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSR… Ampache No fix yet Fix from $1,9502024-11-11 HIGH 8.1 CVE-2024-51485 Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSR… Ampache No fix yet Fix from $1,9502024-11-11 HIGH 8.1 CVE-2024-51487 Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSR… Ampache No fix yet Fix from $1,9502024-11-11 MEDIUM 5.4 CVE-2024-51488 Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate C… Ampache No fix yet Fix from $1,6002024-11-11 MEDIUM 5.4 CVE-2024-51489 Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate C… Ampache No fix yet Fix from $1,6002024-11-11 MEDIUM 6.5 CVE-2024-47828 ampache is a web based audio/video streaming application and file manager. A CSRF attack can be performed in order to delete objects (Playlist, smart… Ampache after 6.6.0 Fix from $1,6002024-10-09 MEDIUM 5.4 CVE-2024-41665 Ampache, a web based audio/video streaming application and file manager, has a stored cross-site scripting (XSS) vulnerability in versions prior to 6… Ampache 6.6.0+ Fix from $1,6002024-07-23 MEDIUM 6.1 CVE-2024-28852 Ampache is a web based audio/video streaming application and file manager. Ampache has multiple reflective XSS vulnerabilities,this means that all fo… Ampache 6.3.1+ Fix from $1,6002024-03-27 MEDIUM 5.9 CVE-2024-28853 Ampache is a web based audio/video streaming application and file manager. Stored Cross Site Scripting (XSS) vulnerability in ampache before v6.3.1 a… Ampache 6.3.1+ Fix from $1,6002024-03-27 HIGH 8.8 CVE-2023-0771 SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop. Ampache 5.5.7+ Fix from $1,9502023-02-10 MEDIUM 6.1 CVE-2023-0606 Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7. Ampache 5.5.7+ Fix from $1,6002023-02-01 HIGH 8.8 CVE-2022-4665 Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6. Ampache 5.5.6+ Fix from $1,9502022-12-23 MEDIUM 5.4 CVE-2021-32644 Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerabl… Ampache Patch available Fix from $1,6002021-06-22 CRITICAL 9.8 CVE-2020-15153 Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and … Ampache 4.2.2+ Fix from $2,3002021-04-30 HIGH 7.5 CVE-2021-21399 Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the … Ampache 4.4.1+ Fix from $1,9502021-04-13 HIGH 8.8 CVE-2019-12385 An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.clas… Ampache after 3.9.1 Fix from $1,9502019-08-22 MEDIUM 5.4 CVE-2019-12386 An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code … Ampache after 3.9.1 Fix from $1,6002019-08-22 HIGH 8.8 CVE-2017-18375 Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php. Ampache No fix yet Fix from $1,9502019-05-24 HIGH 7.2 CVE-2008-3929 gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary file. Ampache Mitigation only Fix from $1,9502008-09-04 MEDIUM 6.8 CVE-2007-4437 SQL injection vulnerability in albums.php in Ampache before 3.3.3.5 allows remote attackers to execute arbitrary SQL commands via the match parameter… Ampache after 3.3.3.4 Fix from $1,6002007-08-20 MEDIUM 6.8 CVE-2007-4438 Session fixation vulnerability in Ampache before 3.3.3.5 allows remote attackers to hijack web sessions via unspecified vectors. Ampache after 3.3.3.4 Fix from $1,6002007-08-20 HIGH 7.5 CVE-2006-5668 Unspecified vulnerability in Ampache 3.3.2 and earlier, when register_globals is enabled, allows remote attackers to bypass security restrictions and… Ampache Patch available Fix from $1,9502006-11-03