Vulnerability index

Browse CVEs

44 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gradio HIGH 7.5
CVE-2024-34510

Gradio before 4.20 allows credential leakage on Windows.

Fix: 4.20.0+
Fix from $1,950 2024-05-05
Gradio HIGH 7.5
CVE-2024-1561EPSS 9%

An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of any method on a `Component` …

Fix: 4.13.0+
Fix from $1,950 2024-04-16
Gradio MEDIUM 6.5
CVE-2024-1183

An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports wi…

Fix: 4.11.0+
Fix from $1,600 2024-04-16
Gradio HIGH 7.5
CVE-2024-1728EPSS 85%

gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton compone…

Fix: 4.19.2+
Fix from $1,950 2024-04-10
Gradio MEDIUM 5.9
CVE-2024-1729

A timing attack vulnerability exists in the gradio-app/gradio repository, specifically within the login function in routes.py. The vulnerability aris…

Fix: 4.19.2+
Fix from $1,600 2024-03-29
Gradio HIGH 8.2
CVE-2024-1540

A command injection vulnerability exists in the deploy+test-visual.yml workflow of the gradio-app/gradio repository, due to improper neutralization o…

Fix: 2024-02-09+
Fix from $1,950 2024-03-27
Gradio MEDIUM 6.5
CVE-2024-2206

An SSRF vulnerability exists in the gradio-app/gradio due to insufficient validation of user-supplied URLs in the `/proxy` route. Attackers can explo…

Fix: 4.18.0+
Fix from $1,600 2024-03-27
Gradio CRITICAL 9.4
CVE-2024-0964

A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.

Patch available
Fix from $2,300 2024-02-05
Gradio HIGH 7.5
CVE-2023-51449EPSS 28%

Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbit…

Fix: 4.11.0+
Fix from $1,950 2023-12-22
Gradio HIGH 8.1
CVE-2023-6572

Command Injection in GitHub repository gradio-app/gradio prior to main.

Fix: 4.14.0+
Fix from $1,950 2023-12-14
Gradio CRITICAL 9.1
CVE-2023-34239

Gradio is an open-source Python library that is used to build machine learning and data science. Due to a lack of path filtering Gradio does not prop…

Fix: 3.34.0+
Fix from $2,300 2023-06-08
Gradio CRITICAL 9.8
CVE-2023-25823

Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use o…

Fix: 3.13.1+
Fix from $2,300 2023-02-23
Gradio HIGH 8.8
CVE-2022-24770

`gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11, `gradio` suffers from Impro…

Fix: 2.8.11+
Fix from $1,950 2022-03-17
Gradio HIGH 7.7
CVE-2021-43831

Gradio is an open source framework for building interactive machine learning models and demos. In versions prior to 2.5.0 there is a vulnerability th…

Fix: 2.5.0+
Fix from $1,950 2021-12-15