pyload records
23 published records for vendor pyload.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 4.3%
- Pre-auth RCE
- 1
- With a fix record
- 78.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-613 Insufficient Session Expiration2
- CWE-20 Improper Input Validation1
- CWE-269 Improper Privilege Management1
- CWE-284 Improper Access Control1
The weakness classes this vendor ships most often: where to look.
CWEAll records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
68This week | CVE-2023-0297Weaponized | Code Injection in pyload/pyloadpyload · pyload · CWE-94 | Critical9.8 | — | 95.9% | Jan 13, 2023 |
43Plan | CVE-2024-21644Proof of concept | pyLoad unauthenticated flask configuration leakagepyload · pyload · CWE-284 | High7.5 | — | 42.4% | Jan 8, 2024 |
39Monitor | CVE-2023-0435No exploit | Excessive Attack Surface in pyload/pyloadpyload · pyload · CWE-1125 | Critical9.8 | — | 0.7% | Jan 22, 2023 |
37Monitor | CVE-2026-33992No exploit | pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltrationpyload · pyload · CWE-918 | Critical9.3 | — | 0.5% | Mar 27, 2026 |
35Monitor | CVE-2023-47890No exploit | pyLoad 0.5.0 is vulnerable to Unrestricted File Upload.pyload · pyload · CWE-22 | High8.8 | — | 1.1% | Jan 8, 2024 |
35Monitor | CVE-2026-33511No exploit | pyload-ng: Authentication Bypass via Host Header Injection in ClickNLoadpyload · pyload · CWE-639 | High8.8 | — | 0.6% | Mar 24, 2026 |
35Monitor | CVE-2026-33509No exploit | pyload-ng: SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configurationpyload · pyload · CWE-269 | High8.8 | — | 0.6% | Mar 24, 2026 |
35Monitor | CVE-2026-41133No exploit | pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)pyload · pyload · CWE-613 | High8.8 | — | 0.5% | Apr 21, 2026 |
32Monitor | CVE-2026-32808No exploit | pyLoad: Arbitrary File Deletion via Path Traversal during Encrypted 7z Password Verificationpyload · pyload · CWE-22 | High8.1 | — | 0.5% | Mar 19, 2026 |
30Monitor | CVE-2023-0434No exploit | Improper Input Validation in pyload/pyloadpyload · pyload · CWE-20 | High7.5 | — | 0.8% | Jan 21, 2023 |
30Monitor | CVE-2026-35464No exploit | pyLoad has an incomplete fix for CVE-2026-33509: unprotected storage_folder enables arbitrary file write to Flask session store and code executionpyload · pyload · CWE-502 | High7.5 | — | 0.6% | Apr 7, 2026 |
29Monitor | CVE-2023-0509No exploit | Improper Certificate Validation in pyload/pyloadpyload · pyload · CWE-295 | High7.4 | — | 0.5% | Jan 26, 2023 |
28Monitor | CVE-2024-21645Proof of concept | pyLoad Log Injectionpyload · pyload · CWE-74 | Medium5.3 | — | 24.7% | Jan 8, 2024 |
28Monitor | CVE-2024-32880No exploit | pyLoad allows upload to arbitrary folder lead to RCEpyload · pyload · CWE-434 | High7.2 | — | 1.4% | Apr 26, 2024 |
26Monitor | CVE-2023-0227No exploit | Insufficient Session Expiration in pyload/pyloadpyload · pyload · CWE-613 | Medium6.5 | — | 0.7% | Jan 11, 2023 |
24Monitor | CVE-2024-24808No exploit | pyLoad open redirect vulnerability due to improper validation of the is_safe_url functionpyload · pyload · CWE-601 | Medium6.1 | — | 0.5% | Feb 6, 2024 |
24Monitor | CVE-2023-0057No exploit | Improper Restriction of Rendered UI Layers or Frames in pyload/pyloadpyload · pyload · CWE-1021 | Medium6.1 | — | 0.5% | Jan 4, 2023 |
24Monitor | CVE-2024-1240No exploit | Open Redirection in pyload/pyloadpyload · pyload · CWE-601 | Medium6.1 | — | 0.3% | Nov 15, 2024 |
21Monitor | CVE-2023-0488No exploit | Cross-site Scripting (XSS) - Stored in pyload/pyloadpyload · pyload · CWE-79 | Medium5.4 | — | 0.8% | Jan 26, 2023 |
21Monitor | CVE-2023-0055No exploit | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in pyload/pyloadpyload · pyload · CWE-614 | Medium5.3 | — | 0.4% | Jan 4, 2023 |
21Monitor | CVE-2026-44226No exploit | pyLoad: Unauthenticated traceback disclosure via global exception handler in WebUIpyload · pyload · CWE-209 | Medium5.3 | — | 0.4% | May 11, 2026 |
21Monitor | CVE-2026-40071No exploit | pyLoad WebUI JSON permission mismatch lets ADD/DELETE users invoke MODIFY-only actionspyload · pyload · CWE-863 | Medium5.4 | — | 0.3% | Apr 9, 2026 |
9Monitor | CVE-2024-47821No exploit | pyLoad vulnerable to remote code execution by download to /.pyload/scripts using /flashgot APIpyload · pyload · CWE-78 | Low2.3 | — | 0.7% | Oct 25, 2024 |
- CVE-2023-029768This week
Code Injection in pyload/pyload
CriticalCVSS 9.8WeaponizedEPSS 96%pyload · pyloadJan 13, 2023
- CVE-2024-2164443Plan
pyLoad unauthenticated flask configuration leakage
HighCVSS 7.5Proof of conceptEPSS 42%pyload · pyloadJan 8, 2024
- CVE-2023-043539Monitor
Excessive Attack Surface in pyload/pyload
CriticalCVSS 9.8No exploitEPSS 1%pyload · pyloadJan 22, 2023
- CVE-2026-3399237Monitor
pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration
CriticalCVSS 9.3No exploitEPSS 0%pyload · pyloadMar 27, 2026
- CVE-2023-4789035Monitor
pyLoad 0.5.0 is vulnerable to Unrestricted File Upload.
HighCVSS 8.8No exploitEPSS 1%pyload · pyloadJan 8, 2024
- CVE-2026-3351135Monitor
pyload-ng: Authentication Bypass via Host Header Injection in ClickNLoad
HighCVSS 8.8No exploitEPSS 1%pyload · pyloadMar 24, 2026
- CVE-2026-3350935Monitor
pyload-ng: SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configuration
HighCVSS 8.8No exploitEPSS 1%pyload · pyloadMar 24, 2026
- CVE-2026-4113335Monitor
pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)
HighCVSS 8.8No exploitEPSS 0%pyload · pyloadApr 21, 2026
- CVE-2026-3280832Monitor
pyLoad: Arbitrary File Deletion via Path Traversal during Encrypted 7z Password Verification
HighCVSS 8.1No exploitEPSS 0%pyload · pyloadMar 19, 2026
- CVE-2023-043430Monitor
Improper Input Validation in pyload/pyload
HighCVSS 7.5No exploitEPSS 1%pyload · pyloadJan 21, 2023
- CVE-2026-3546430Monitor
pyLoad has an incomplete fix for CVE-2026-33509: unprotected storage_folder enables arbitrary file write to Flask session store and code execution
HighCVSS 7.5No exploitEPSS 1%pyload · pyloadApr 7, 2026
- CVE-2023-050929Monitor
Improper Certificate Validation in pyload/pyload
HighCVSS 7.4No exploitEPSS 1%pyload · pyloadJan 26, 2023
- CVE-2024-2164528Monitor
pyLoad Log Injection
MediumCVSS 5.3Proof of conceptEPSS 25%pyload · pyloadJan 8, 2024
- CVE-2024-3288028Monitor
pyLoad allows upload to arbitrary folder lead to RCE
HighCVSS 7.2No exploitEPSS 1%pyload · pyloadApr 26, 2024
- CVE-2023-022726Monitor
Insufficient Session Expiration in pyload/pyload
MediumCVSS 6.5No exploitEPSS 1%pyload · pyloadJan 11, 2023
- CVE-2024-2480824Monitor
pyLoad open redirect vulnerability due to improper validation of the is_safe_url function
MediumCVSS 6.1No exploitEPSS 1%pyload · pyloadFeb 6, 2024
- CVE-2023-005724Monitor
Improper Restriction of Rendered UI Layers or Frames in pyload/pyload
MediumCVSS 6.1No exploitEPSS 0%pyload · pyloadJan 4, 2023
- CVE-2024-124024Monitor
Open Redirection in pyload/pyload
MediumCVSS 6.1No exploitEPSS 0%pyload · pyloadNov 15, 2024
- CVE-2023-048821Monitor
Cross-site Scripting (XSS) - Stored in pyload/pyload
MediumCVSS 5.4No exploitEPSS 1%pyload · pyloadJan 26, 2023
- CVE-2023-005521Monitor
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in pyload/pyload
MediumCVSS 5.3No exploitEPSS 0%pyload · pyloadJan 4, 2023
- CVE-2026-4422621Monitor
pyLoad: Unauthenticated traceback disclosure via global exception handler in WebUI
MediumCVSS 5.3No exploitEPSS 0%pyload · pyloadMay 11, 2026
- CVE-2026-4007121Monitor
pyLoad WebUI JSON permission mismatch lets ADD/DELETE users invoke MODIFY-only actions
MediumCVSS 5.4No exploitEPSS 0%pyload · pyloadApr 9, 2026
- CVE-2024-478219Monitor
pyLoad vulnerable to remote code execution by download to /.pyload/scripts using /flashgot API
LowCVSS 2.3No exploitEPSS 1%pyload · pyloadOct 25, 2024