Vulnerabilities
Last updated 35 minutes ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
pyLoad: Tar extraction creates device nodes and FIFOs (member types not filtered; tarfile extractall without filter=) | High Risk 8.0 | 4 hours ago | 4 hours ago |
|
|
pyLoad WindowsPhoneNotify addon: non-admin SETTINGS user triggers SSRF via unguarded http.client notification host | Medium Risk 6.4 | 4 hours ago | 4 hours ago |
|
|
pyload-ng: getUserData/get_userdata exposed at Perms.ANY allow any authenticated account to brute-force the administrator password | High Risk 8.1 | 4 hours ago | 4 hours ago |
|
|
pyLoad: Api.set_user_permission never invalidates the target's session | High Risk 7.5 | 4 hours ago | 4 hours ago |
|
|
pyLoad: Rate-Limit Bypass and Audit-Log Spoofing via Trusted Client-Controlled `X-Forwarded-For` Header | Medium Risk 6.0 | 4 hours ago | 4 hours ago |
|
|
pyLoad: Privilege revocation and password change through the REST API do not invalidate the user's session | High Risk 7.5 | 4 hours ago | 4 hours ago |
|
|
pyLoad has an authentication bypass in API key validation (check_apikey cache) | High Risk 8.1 | 5 hours ago | 4 hours ago |
|
|
pyLoad: Unauthenticated access to /web/<path:filename> bypasses authentication on sensitive templates and leaks internal error details via exception attribute typo | Medium Risk 5.3 | 5 hours ago | 5 hours ago |
|
|
pyLoad: Lack of Input Size Validation Leads to Denial of Service (DoS) and Process Termination | Medium Risk 6.5 | 5 hours ago | 5 hours ago |
|
|
pyload-ng has a WebUI JSON permission mismatch that lets ADD/DELETE users invoke MODIFY-only actions | Medium Risk 5.4 | 6 months ago | 29 days ago |
|
|
pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33509) | High Risk 7.5 | 6 months ago | 29 days ago |
|
|
pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE) | Critical 9.8 | 1 year ago | 29 days ago |
|
|
pyLoad vulnerable to XSS through insecure CAPTCHA | Critical 9.8 | 1 year ago | 29 days ago |
|
|
pyLoad allows upload to arbitrary folder lead to RCE | Critical 9.1 | 2 years ago | 29 days ago |
|
|
pyLoad open redirect vulnerability due to improper validation of the is_safe_url function | Medium Risk 6.1 | 2 years ago | 29 days ago |
|
|
pyload Unauthenticated Flask Configuration Leakage vulnerability | High Risk 7.5 | 2 years ago | 29 days ago |
|
|
Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation | Critical 9.6 | 2 years ago | 29 days ago |
|
|
pyload Log Injection vulnerability | Medium Risk 5.3 | 2 years ago | 29 days ago |
|
|
pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal | High Risk 8.7 | 4 months ago | 2 months ago |
|
|
pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad | Medium Risk 6.5 | 4 months ago | 2 months ago |
|
|
PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI | Medium Risk 5.3 | 5 months ago | 2 months ago |
|
|
pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API | Medium Risk 5.0 | 4 months ago | 2 months ago |
|
|
pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass) | High Risk 8.8 | 5 months ago | 2 months ago |
|
|
pyLoad SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configuration | High Risk 7.5 | 6 months ago | 2 months ago |
|
|
pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManager | Medium Risk 6.5 | 3 months ago | 2 months ago |
|
|
pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal IPs | Medium Risk 4.9 | 3 months ago | 2 months ago |
|
|
pyLoad: SSRF in parse_urls API endpoint via unvalidated URL parameter | High Risk 7.7 | 6 months ago | 2 months ago |
|
|
pyload-ng has a WebUI JSON permission mismatch that lets ADD/DELETE users invoke MODIFY-only actions | Medium Risk 5.4 | 2 months ago | 2 months ago |
|
|
pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad | Medium Risk 6.5 | 2 months ago | 2 months ago |
|
|
PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI | Medium Risk 5.3 | 2 months ago | 2 months ago |
|
|
pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal | High Risk 8.7 | 2 months ago | 2 months ago |
|
|
pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal IPs | Medium Risk 4.9 | 2 months ago | 2 months ago |
|
|
pyLoad SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configuration | High Risk 7.5 | 2 months ago | 2 months ago |
|
|
pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33509) | High Risk 7.5 | 2 months ago | 2 months ago |
|
|
pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass) | High Risk 8.8 | 2 months ago | 2 months ago |
|
|
pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API | Medium Risk 5.0 | 2 months ago | 2 months ago |
|
|
pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManager | Medium Risk 6.5 | 2 months ago | 2 months ago |
|
|
pyLoad: SSRF in parse_urls API endpoint via unvalidated URL parameter | High Risk 7.7 | 2 months ago | 2 months ago |
|
|
pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE) | Critical 9.8 | 3 months ago | 2 months ago |
|
|
pyLoad: Improper Neutralization of Special Elements used in an OS Command | High Risk 8.8 | 6 months ago | 2 months ago |
|
|
No summary available | High Risk 8.8 | 6 months ago | 2 months ago |
|
|
pyLoad allows upload to arbitrary folder lead to RCE | Critical 9.1 | 3 months ago | 3 months ago |
|
|
pyLoad vulnerable to XSS through insecure CAPTCHA | Critical 9.8 | 3 months ago | 3 months ago |
|
|
Download to arbitrary folder can lead to RCE | High Risk 7.6 | 2 years ago | 3 months ago |
|
|
Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs | High Risk 8.0 | 1 year ago | 3 months ago |
|
|
pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters | High Risk 8.1 | 1 year ago | 3 months ago |
|
|
pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages | High Risk 7.5 | 1 year ago | 3 months ago |
|
|
`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write | High Risk 7.5 | 1 year ago | 3 months ago |
|
|
PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter | High Risk 8.0 | 1 year ago | 3 months ago |
|
|
pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters | High Risk 8.1 | 3 months ago | 3 months ago |
Page 1