Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.27% | — | Gradio Project Gradio | 10/10/2024 | 17/6/2026 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **Cross-Site Scripting (XSS)** on any Gradio server that allows file uploads. Authenticated users can upload files such as HTML, JavaScript, or SVG files containing malicious scripts. When other users download or view… | |
| Analizada | Alta (8.2) | 0.18% | — | Gradio Project Gradio | 10/10/2024 | 17/6/2026 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **insecure communication** between the FRP (Fast Reverse Proxy) client and server when Gradio's `share=True` option is used. HTTPS is not enforced on the connection, allowing attackers to intercept and read files… | |
| Analizada | Alta (7.1) | 0.37% | — | Gradio Project Gradio | 10/10/2024 | 17/6/2026 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **race condition** in the `update_root_in_config` function, allowing an attacker to modify the `root` URL used by the Gradio frontend to communicate with the backend. By exploiting this flaw, an attacker can redirect… | |
| Analizada | Baja (2.3) | 0.29% | — | Gradio Project Gradio | 10/10/2024 | 17/6/2026 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **timing attack** in the way Gradio compares hashes for the `analytics_dashboard` function. Since the comparison is not done in constant time, an attacker could exploit this by measuring the response time of different… | |
| Analizada | Media (6.3) | 0.81% | — | Gradio Project Gradio | 10/10/2024 | 17/6/2026 | Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affecting several Gradio components, which allows arbitrary file leaks through the post-processing step. Attackers can exploit these components by crafting requests that bypass expected input… | |
| Analizada | Baja (2.1) | 0.21% | — | Gradio Project Gradio | 10/10/2024 | 17/6/2026 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity check** on the downloaded FRP client, which could potentially allow attackers to introduce malicious code. If an attacker gains access to the remote URL from which the FRP client is downloaded, they… | |
| Analizada | Baja (2.3) | 0.33% | — | Gradio Project Gradio | 10/10/2024 | 17/6/2026 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves data exposure due to the enable_monitoring flag not properly disabling monitoring when set to False. Even when monitoring is supposedly disabled, an attacker or unauthorized user can still access the monitoring… | |
| Analizada | Media (6.9) | 0.48% | 💥 PoC | Gradio Project Gradio | 10/10/2024 | 17/6/2026 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **Server-Side Request Forgery (SSRF)** in the `/queue/join` endpoint. Gradio’s `async_save_url_to_cache` function allows attackers to force the Gradio server to send HTTP requests to user-controlled URLs. This could… | |
| Analizada | Baja (2.3) | 0.43% | — | Gradio Project Gradio | 10/10/2024 | 17/6/2026 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **one-level read path traversal** in the `/custom_component` endpoint. Attackers can exploit this flaw to access and leak source code from custom Gradio components by manipulating the file path in the request.… | |
| Analizada | Media (6.9) | 0.30% | — | Gradio Project Gradio | 10/10/2024 | 17/6/2026 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **CORS origin validation accepting a null origin**. When a Gradio server is deployed locally, the `localhost_aliases` variable includes "null" as a valid origin. This allows attackers to make unauthorized requests… | |
| Analizada | Baja (2.3) | 0.70% | — | Gradio Project Gradio | 10/10/2024 | 17/6/2026 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to the **bypass of directory traversal checks** within the `is_in_or_equal` function. This function, intended to check if a file resides within a given directory, can be bypassed with certain payloads that manipulate… | |
| Analizada | Media (6.9) | 0.53% | — | Gradio Project Gradio | 10/10/2024 | 17/6/2026 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability is related to **CORS origin validation**, where the Gradio server fails to validate the request origin when a cookie is present. This allows an attacker’s website to make unauthorized requests to a local Gradio server.… | |
| Modificada | Media (5.4) | 0.35% | — | Softlabbd Radio Player | 25/9/2024 | 17/6/2026 | The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute within the 'wp:radio-player' Gutenberg block in all versions up to, and including, 2.0.78 due to insufficient input sanitization and output… | |
| Modificada | Alta (8.1) | 19% | 💥 PoC | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 29/8/2024 | 17/6/2026 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'file' parameter in all versions up to, and including, 5.7.0.1.… | |
| Analizada | Media (5.3) | 0.41% | — | Softlabbd Radio Player | 17/8/2024 | 17/6/2026 | The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_settings function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to update plugin settings. | |
| Analizada | Media (5.3) | 0.41% | — | Softlabbd Radio Player | 17/8/2024 | 17/6/2026 | The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to update player instances. | |
| Analizada | Media (5.3) | 0.51% | — | Softlabbd Radio Player | 17/8/2024 | 17/6/2026 | The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to delete player instances. | |
| Modificada | Media (5.4) | 0.33% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 10/7/2024 | 17/6/2026 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute within the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.5 due to insufficient input sanitization and output escaping on user… | |
| Analizada | Crítica (9.8) | 0.87% | — | Gradio Project Gradio | 1/7/2024 | 17/6/2026 | Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input. NOTE: the supplier disputes this because the report is about a user attacking himself. | |
| Analizada | Media (6.1) | 1.0% | 💥 Exploit | Gradio Project Gradio | 22/6/2024 | 17/6/2026 | An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users to arbitrary websites, which can be exploited for phishing attacks, Cross-site Scripting (XSS), Server-Side Request Forgery (SSRF), amongst others. This issue is due to… | |
| Modificada | Media (5.3) | 0.34% | — | Softlabbd Radio Player | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. | |
| Modificada | Alta (7.5) | 0.83% | — | Gradio Project Gradio | 6/6/2024 | 17/6/2026 | A local file inclusion vulnerability exists in the JSON component of gradio-app/gradio version 4.25. The vulnerability arises from improper input validation in the `postprocess()` function within `gradio/components/json_component.py`, where a user-controlled string is parsed as JSON. If the parsed JSON object contains… | |
| Modificada | Alta (8.6) | 37% | 💥 Exploit | Gradio Project Gradio | 6/6/2024 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio version 4.21.0, specifically within the `/queue/join` endpoint and the `save_url_to_cache` function. The vulnerability arises when the `path` value, obtained from the user and expected to be a URL, is used to make an HTTP request… | |
| Modificada | Alta (7.1) | 0.47% | 💥 PoC | Gradio Project Gradio | 4/6/2024 | 17/6/2026 | The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main' branch, is vulnerable to secrets exfiltration due to improper authorization. The vulnerability arises from the workflow's explicit checkout and execution of code from a fork, which is unsafe as it allows the running of… | |
| Modificada | Crítica (9.1) | 1.7% | 💥 PoC | Gradio Project Gradio | 4/6/2024 | 17/6/2026 | A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing for unauthorized modification of the base repository or secrets exfiltration. The… |