Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2024-34510
Gradio before 4.20 allows credential leakage on Windows.
Gradio
4.20.0+
HIGH 7.5
CVE-2024-1561EPSS 9%
An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of any method on a `Component` …
Gradio
4.13.0+
MEDIUM 6.5
CVE-2024-1183
An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports wi…
Gradio
4.11.0+
HIGH 7.5
CVE-2024-1728EPSS 85%
gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton compone…
Gradio
4.19.2+
MEDIUM 5.9
CVE-2024-1729
A timing attack vulnerability exists in the gradio-app/gradio repository, specifically within the login function in routes.py. The vulnerability aris…
Gradio
4.19.2+
HIGH 8.2
CVE-2024-1540
A command injection vulnerability exists in the deploy+test-visual.yml workflow of the gradio-app/gradio repository, due to improper neutralization o…
Gradio
2024-02-09+
MEDIUM 6.5
CVE-2024-2206
An SSRF vulnerability exists in the gradio-app/gradio due to insufficient validation of user-supplied URLs in the `/proxy` route. Attackers can explo…
Gradio
4.18.0+
CRITICAL 9.4
CVE-2024-0964
A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.
Gradio
Patch available
HIGH 7.5
CVE-2023-51449EPSS 28%
Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbit…
Gradio
4.11.0+
HIGH 8.1
CVE-2023-6572
Command Injection in GitHub repository gradio-app/gradio prior to main.
Gradio
4.14.0+
CRITICAL 9.1
CVE-2023-34239
Gradio is an open-source Python library that is used to build machine learning and data science. Due to a lack of path filtering Gradio does not prop…
Gradio
3.34.0+
CRITICAL 9.8
CVE-2023-25823
Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use o…
Gradio
3.13.1+
HIGH 8.8
CVE-2022-24770
`gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11, `gradio` suffers from Impro…
Gradio
2.8.11+
HIGH 7.7
CVE-2021-43831
Gradio is an open source framework for building interactive machine learning models and demos. In versions prior to 2.5.0 there is a vulnerability th…
Gradio
2.5.0+