All 36 CVE vulnerabilities found in pyload, with AI-generated Chinese analysis, references, and POCs.
This page presents a comprehensive aggregation of security vulnerabilities affecting pyload, a popular download management tool developed by pyload team. The collected data encompasses a wide spectrum of weakness types, ranging from critical remote code execution and buffer overflows to less severe issues like cross-site scripting and information disclosure. This repository captures vulnerability records spanning from the initial release of the software through recent updates, ensuring a complete historical perspective on the product’s security posture. By organizing these entries, the page allows security researchers and system administrators to effectively track vendor advisories and understand the evolution of specific weakness classes within this ecosystem. Users can look up pyload’s vulnerability history to identify patterns in development flaws or assess risk exposure based on known CVEs associated with specific versions. This resource serves as a centralized reference point for evaluating the integrity and safety of pyload installations, helping stakeholders make informed decisions regarding patching and mitigation strategies without relying on fragmented sources. The structured presentation facilitates deeper analysis of how common coding errors or configuration mistakes have impacted the tool over time.
Vendor: pyload
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-47821 | pyLoad vulnerable to remote code execution by download to /.pyload/scripts using /flashgot API CWE-78 | 9.1 | Critical | 2024-10-25 |
| CVE-2024-32880 | pyLoad allows upload to arbitrary folder lead to RCE CWE-434 | 9.1 | Critical | 2024-04-26 |
| CVE-2024-24808 | pyLoad open redirect vulnerability due to improper validation of the is_safe_url function CWE-601 | 4.7 | Medium | 2024-02-06 |
| CVE-2024-22416 | Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation CWE-352 | 9.7 | Critical | 2024-01-17 |
| CVE-2024-21644 | pyLoad unauthenticated flask configuration leakage CWE-284 | 7.5 | High | 2024-01-08 |
| CVE-2024-21645 | pyLoad Log Injection CWE-74 | 5.3 | Medium | 2024-01-08 |
All 36 known CVE vulnerabilities affecting pyload with full Chinese analysis, references, and POCs where available.