Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ampache CRITICAL 9.0
CVE-2024-51490

Ampache is a web based audio/video streaming application and file manager. This vulnerability exists in the interface section of the Ampache menu, wh…

No fix yet
Fix from $2,300 2024-11-11
Ampache HIGH 8.4
CVE-2024-51486

Ampache is a web based audio/video streaming application and file manager. The vulnerability exists in the interface section of the Ampache menu, whe…

No fix yet
Fix from $1,950 2024-11-11
Ampache HIGH 8.1
CVE-2024-51484

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSR…

No fix yet
Fix from $1,950 2024-11-11
Ampache HIGH 8.1
CVE-2024-51485

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSR…

No fix yet
Fix from $1,950 2024-11-11
Ampache HIGH 8.1
CVE-2024-51487

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSR…

No fix yet
Fix from $1,950 2024-11-11
Ampache MEDIUM 5.4
CVE-2024-51488

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate C…

No fix yet
Fix from $1,600 2024-11-11
Ampache MEDIUM 5.4
CVE-2024-51489

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate C…

No fix yet
Fix from $1,600 2024-11-11
Ampache MEDIUM 6.5
CVE-2024-47828

ampache is a web based audio/video streaming application and file manager. A CSRF attack can be performed in order to delete objects (Playlist, smart…

Fix: after 6.6.0
Fix from $1,600 2024-10-09
Ampache MEDIUM 5.4
CVE-2024-41665

Ampache, a web based audio/video streaming application and file manager, has a stored cross-site scripting (XSS) vulnerability in versions prior to 6…

Fix: 6.6.0+
Fix from $1,600 2024-07-23
Ampache MEDIUM 6.1
CVE-2024-28852

Ampache is a web based audio/video streaming application and file manager. Ampache has multiple reflective XSS vulnerabilities,this means that all fo…

Fix: 6.3.1+
Fix from $1,600 2024-03-27
Ampache MEDIUM 5.9
CVE-2024-28853

Ampache is a web based audio/video streaming application and file manager. Stored Cross Site Scripting (XSS) vulnerability in ampache before v6.3.1 a…

Fix: 6.3.1+
Fix from $1,600 2024-03-27
Ampache HIGH 8.8
CVE-2023-0771

SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop.

Fix: 5.5.7+
Fix from $1,950 2023-02-10
Ampache MEDIUM 6.1
CVE-2023-0606

Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7.

Fix: 5.5.7+
Fix from $1,600 2023-02-01
Ampache HIGH 8.8
CVE-2022-4665

Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6.

Fix: 5.5.6+
Fix from $1,950 2022-12-23
Ampache MEDIUM 5.4
CVE-2021-32644

Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerabl…

Patch available
Fix from $1,600 2021-06-22
Ampache CRITICAL 9.8
CVE-2020-15153

Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and …

Fix: 4.2.2+
Fix from $2,300 2021-04-30
Ampache HIGH 7.5
CVE-2021-21399

Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the …

Fix: 4.4.1+
Fix from $1,950 2021-04-13
Ampache HIGH 8.8
CVE-2019-12385

An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.clas…

Fix: after 3.9.1
Fix from $1,950 2019-08-22
Ampache MEDIUM 5.4
CVE-2019-12386

An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code …

Fix: after 3.9.1
Fix from $1,600 2019-08-22
Ampache HIGH 8.8
CVE-2017-18375

Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.

No fix yet
Fix from $1,950 2019-05-24
Ampache HIGH 7.2
CVE-2008-3929

gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary file.

Mitigation only
Fix from $1,950 2008-09-04
Ampache MEDIUM 6.8
CVE-2007-4437

SQL injection vulnerability in albums.php in Ampache before 3.3.3.5 allows remote attackers to execute arbitrary SQL commands via the match parameter…

Fix: after 3.3.3.4
Fix from $1,600 2007-08-20
Ampache MEDIUM 6.8
CVE-2007-4438

Session fixation vulnerability in Ampache before 3.3.3.5 allows remote attackers to hijack web sessions via unspecified vectors.

Fix: after 3.3.3.4
Fix from $1,600 2007-08-20
Ampache HIGH 7.5
CVE-2006-5668

Unspecified vulnerability in Ampache 3.3.2 and earlier, when register_globals is enabled, allows remote attackers to bypass security restrictions and…

Patch available
Fix from $1,950 2006-11-03