Vulnerability index

Browse CVEs

44 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-49119 Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers… Gradio 6.16.0+ Fix from $1,9502026-07-01 MEDIUM 6.8 CVE-2026-48545 Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploi… Gradio 6.15.0+ Fix from $1,6002026-05-27 HIGH 8.6 CVE-2026-28416EPSS 7% Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in… Gradio 6.6.0+ Fix from $1,9502026-02-27 HIGH 7.5 CVE-2026-28414 Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vul… Gradio 6.7.0+ Fix from $1,9502026-02-27 MEDIUM 5.9 CVE-2026-27167 Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications ru… Gradio 6.6.0+ Fix from $1,6002026-02-27 HIGH 7.5 CVE-2025-48889 Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Py… Gradio 5.31.0+ Fix from $1,9502025-05-30 HIGH 7.5 CVE-2025-0187 A Denial of Service (DoS) vulnerability was discovered in the file upload feature of gradio-app/gradio version 0.39.1. The vulnerability is due to im… Gradio No fix yet Fix from $1,9502025-03-20 MEDIUM 6.1 CVE-2024-8021 An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicio… Gradio No fix yet Fix from $1,6002025-03-20 HIGH 8.2 CVE-2024-10648 A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. This vulnerability allows an att… Gradio No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-10569 A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to… Gradio No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-10624 A Regular Expression Denial of Service (ReDoS) vulnerability exists in the gradio-app/gradio repository, affecting the gr.Datetime component. The aff… Gradio No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2025-23042 Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Py… Gradio 5.6.0+ Fix from $1,9502025-01-14 MEDIUM 6.5 CVE-2024-51751 Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadButton components are used as … Gradio 5.5.0+ Fix from $1,6002024-11-06 MEDIUM 6.5 CVE-2024-48052 In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_… Gradio after 4.42.0 Fix from $1,6002024-11-04 CRITICAL 9.1 CVE-2024-47871 Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **insecure communication** between the FRP (Fast … Gradio 5.0.0+ Fix from $2,3002024-10-10 HIGH 8.1 CVE-2024-47870 Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **race condition** in the `update_root_in_confi… Gradio 5.0.0+ Fix from $1,9502024-10-10 MEDIUM 5.4 CVE-2024-47872 Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **Cross-Site Scripting (XSS)** on any Gradio serv… Gradio 5.0.0+ Fix from $1,6002024-10-10 HIGH 7.5 CVE-2024-47867 Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity check** on the downloaded FRP cli… Gradio 5.0.0+ Fix from $1,9502024-10-10 HIGH 7.5 CVE-2024-47868 Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affecting several Gradio componen… Gradio 5.0.0+ Fix from $1,9502024-10-10 CRITICAL 9.8 CVE-2024-47167 Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **Server-Side Request Forgery (SSRF)** in the `… Gradio 5.0.0+ Fix from $2,3002024-10-10 HIGH 8.3 CVE-2024-47084 Gradio is an open-source Python package designed for quick prototyping. This vulnerability is related to **CORS origin validation**, where the Gradio… Gradio 4.44.0+ Fix from $1,9502024-10-10 MEDIUM 6.5 CVE-2024-47164 Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to the **bypass of directory traversal checks** wi… Gradio 5.0.0+ Fix from $1,6002024-10-10 MEDIUM 5.4 CVE-2024-47165 Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **CORS origin validation accepting a null origi… Gradio 5.0.0+ Fix from $1,6002024-10-10 MEDIUM 5.3 CVE-2024-47166 Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **one-level read path traversal** in the `/cust… Gradio 4.44.0+ Fix from $1,6002024-10-10 CRITICAL 9.8 CVE-2024-39236 Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered … Gradio No fix yet Fix from $2,3002024-07-01 MEDIUM 6.1 CVE-2024-4940 An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users … Gradio No fix yet Fix from $1,6002024-06-22 HIGH 8.6 CVE-2024-4325EPSS 37% A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio version 4.21.0, specifically within the `/queue/join` endpoint and… Gradio 4.41.0+ Fix from $1,9502024-06-06 HIGH 7.5 CVE-2024-4941 A local file inclusion vulnerability exists in the JSON component of gradio-app/gradio version 4.25. The vulnerability arises from improper input val… Gradio 4.31.4+ Fix from $1,9502024-06-06 HIGH 7.1 CVE-2024-4254 The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main' branch, is vulnerable to secrets exfiltration due t… Gradio No fix yet Fix from $1,9502024-06-04 CRITICAL 9.1 CVE-2024-4253 A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerabili… Gradio 4.29.0+ Fix from $2,3002024-06-04