Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pyload MEDIUM 5.3
CVE-2026-44226

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, pyload-ng WebUI returns full Python traceback details t…

Fix: 2026-04-13+
Fix from $1,600 2026-05-11
Pyload HIGH 8.8
CVE-2026-41133

pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `role` and `permission` in the …

Fix: 2026-04-13+
Fix from $1,950 2026-04-22
Pyload MEDIUM 5.4
CVE-2026-40071

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the /json/package_order, /json/link_order, and /json/abo…

Fix: 2026-04-13+
Fix from $1,600 2026-04-09
Pyload HIGH 7.5
CVE-2026-35464

pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin us…

Fix: 2026-04-02+
Fix from $1,950 2026-04-07
Pyload MEDIUM 6.5
CVE-2026-33992

pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, PyLoad's download engine accepts arbitrary URLs …

Patch available
Fix from $1,600 2026-03-27
Pyload MEDIUM 6.1
CVE-2024-1240

An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the…

Patch available
Fix from $1,600 2024-11-15
Pyload HIGH 7.2
CVE-2024-32880

pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder and upload a crafted template …

Fix: after 0.5.0
Fix from $1,950 2024-04-26
Pyload MEDIUM 6.1
CVE-2024-24808

pyLoad is an open-source Download Manager written in pure Python. There is an open redirect vulnerability due to incorrect validation of input values…

Fix: after 0.5.0
Fix from $1,600 2024-02-06
Pyload HIGH 8.8
CVE-2023-47890

pyLoad 0.5.0 is vulnerable to Unrestricted File Upload.

Mitigation only
Fix from $1,950 2024-01-08
Pyload HIGH 7.5
CVE-2024-21644EPSS 42%

pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask…

Fix: after 0.4.9
Fix from $1,950 2024-01-08
Pyload MEDIUM 5.3
CVE-2024-21645EPSS 25%

pyLoad is the free and open-source Download Manager written in pure Python. A log injection vulnerability was identified in `pyload` allowing any una…

Fix: after 0.4.9
Fix from $1,600 2024-01-08
Pyload CRITICAL 9.8
CVE-2023-0435

Excessive Attack Surface in GitHub repository pyload/pyload prior to 0.5.0b3.dev41.

Fix: after 0.4.20
Fix from $2,300 2023-01-22
Pyload HIGH 7.5
CVE-2023-0434

Improper Input Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev40.

Fix: after 0.4.9
Fix from $1,950 2023-01-22
Pyload CRITICAL 9.8
CVE-2023-0297EPSS 96%

Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.

Fix: after 0.4.20
Fix from $2,300 2023-01-14
Pyload MEDIUM 6.5
CVE-2023-0227

Insufficient Session Expiration in GitHub repository pyload/pyload prior to 0.5.0b3.dev36.

Fix: 2023-01-12+
Fix from $1,600 2023-01-12
Pyload MEDIUM 5.3
CVE-2023-0055

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository pyload/pyload prior to 0.5.0b3.dev32.

Patch available
Fix from $1,600 2023-01-04