Vulnerability index

Browse CVEs

44 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gradio HIGH 7.5
CVE-2026-49119

Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers…

Fix: 6.16.0+
Fix from $1,950 2026-07-01
Gradio MEDIUM 6.8
CVE-2026-48545

Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploi…

Fix: 6.15.0+
Fix from $1,600 2026-05-27
Gradio HIGH 8.6
CVE-2026-28416EPSS 7%

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in…

Fix: 6.6.0+
Fix from $1,950 2026-02-27
Gradio HIGH 7.5
CVE-2026-28414

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vul…

Fix: 6.7.0+
Fix from $1,950 2026-02-27
Gradio MEDIUM 5.9
CVE-2026-27167

Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications ru…

Fix: 6.6.0+
Fix from $1,600 2026-02-27
Gradio HIGH 7.5
CVE-2025-48889

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Py…

Fix: 5.31.0+
Fix from $1,950 2025-05-30
Gradio HIGH 7.5
CVE-2025-0187

A Denial of Service (DoS) vulnerability was discovered in the file upload feature of gradio-app/gradio version 0.39.1. The vulnerability is due to im…

No fix yet
Fix from $1,950 2025-03-20
Gradio MEDIUM 6.1
CVE-2024-8021

An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicio…

No fix yet
Fix from $1,600 2025-03-20
Gradio HIGH 8.2
CVE-2024-10648

A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. This vulnerability allows an att…

No fix yet
Fix from $1,950 2025-03-20
Gradio HIGH 7.5
CVE-2024-10569

A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to…

No fix yet
Fix from $1,950 2025-03-20
Gradio HIGH 7.5
CVE-2024-10624

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the gradio-app/gradio repository, affecting the gr.Datetime component. The aff…

No fix yet
Fix from $1,950 2025-03-20
Gradio HIGH 7.5
CVE-2025-23042

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Py…

Fix: 5.6.0+
Fix from $1,950 2025-01-14
Gradio MEDIUM 6.5
CVE-2024-51751

Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadButton components are used as …

Fix: 5.5.0+
Fix from $1,600 2024-11-06
Gradio MEDIUM 6.5
CVE-2024-48052

In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_…

Fix: after 4.42.0
Fix from $1,600 2024-11-04
Gradio CRITICAL 9.1
CVE-2024-47871

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **insecure communication** between the FRP (Fast …

Fix: 5.0.0+
Fix from $2,300 2024-10-10
Gradio HIGH 8.1
CVE-2024-47870

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **race condition** in the `update_root_in_confi…

Fix: 5.0.0+
Fix from $1,950 2024-10-10
Gradio MEDIUM 5.4
CVE-2024-47872

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **Cross-Site Scripting (XSS)** on any Gradio serv…

Fix: 5.0.0+
Fix from $1,600 2024-10-10
Gradio HIGH 7.5
CVE-2024-47867

Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity check** on the downloaded FRP cli…

Fix: 5.0.0+
Fix from $1,950 2024-10-10
Gradio HIGH 7.5
CVE-2024-47868

Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affecting several Gradio componen…

Fix: 5.0.0+
Fix from $1,950 2024-10-10
Gradio CRITICAL 9.8
CVE-2024-47167

Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **Server-Side Request Forgery (SSRF)** in the `…

Fix: 5.0.0+
Fix from $2,300 2024-10-10
Gradio HIGH 8.3
CVE-2024-47084

Gradio is an open-source Python package designed for quick prototyping. This vulnerability is related to **CORS origin validation**, where the Gradio…

Fix: 4.44.0+
Fix from $1,950 2024-10-10
Gradio MEDIUM 6.5
CVE-2024-47164

Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to the **bypass of directory traversal checks** wi…

Fix: 5.0.0+
Fix from $1,600 2024-10-10
Gradio MEDIUM 5.4
CVE-2024-47165

Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **CORS origin validation accepting a null origi…

Fix: 5.0.0+
Fix from $1,600 2024-10-10
Gradio MEDIUM 5.3
CVE-2024-47166

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **one-level read path traversal** in the `/cust…

Fix: 4.44.0+
Fix from $1,600 2024-10-10
Gradio CRITICAL 9.8
CVE-2024-39236

Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered …

No fix yet
Fix from $2,300 2024-07-01
Gradio MEDIUM 6.1
CVE-2024-4940

An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users …

No fix yet
Fix from $1,600 2024-06-22
Gradio HIGH 8.6
CVE-2024-4325EPSS 37%

A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio version 4.21.0, specifically within the `/queue/join` endpoint and…

Fix: 4.41.0+
Fix from $1,950 2024-06-06
Gradio HIGH 7.5
CVE-2024-4941

A local file inclusion vulnerability exists in the JSON component of gradio-app/gradio version 4.25. The vulnerability arises from improper input val…

Fix: 4.31.4+
Fix from $1,950 2024-06-06
Gradio HIGH 7.1
CVE-2024-4254

The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main' branch, is vulnerable to secrets exfiltration due t…

No fix yet
Fix from $1,950 2024-06-04
Gradio CRITICAL 9.1
CVE-2024-4253

A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerabili…

Fix: 4.29.0+
Fix from $2,300 2024-06-04