Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.50%—Pyload-ng Project Pyload-ng11/5/202617/6/2026
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name in the set_package_data() API function call inside the data object with key "_folder", there is no sanitization at all, allowing a user with Perms.MODIFY to specify arbitrary directories as download…
AnalizadaMedia (6.5)0.42%—Pyload-ng Project Pyload-ng11/5/202617/6/2026
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient string replacement. The pattern ....// becomes .._ after replacement (partial removal), leaving .. which can be exploited when the path is later resolved by the OS. This…
AnalizadaAlta (8.3)0.39%—Pyload-ng Project Pyload-ng11/5/202617/6/2026
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand-maintained allowlist ADMIN_ONLY_CORE_OPTIONS. The allowlist contains ("proxy",…
AnalizadaMedia (6.8)0.19%—Pyload-ng Project Pyload-ng11/5/202617/6/2026
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand-maintained allowlist ADMIN_ONLY_CORE_OPTIONS. The option ("general",…
AnalizadaMedia (4.8)0.16%—Pyload-ng Project Pyload-ng21/4/202617/6/2026
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev98, the set_session_cookie_secure before_request handler in src/pyload/webui/app/__init__.py reads the X-Forwarded-Proto header from any HTTP request without validating that the request originates from a trusted proxy, then…
AnalizadaMedia (6.5)0.35%—Pyload-ng Project Pyload-ng7/4/202617/6/2026
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the _safe_extractall() function in src/pyload/plugins/extractors/UnTar.py uses os.path.commonprefix() for its path traversal check, which performs character-level string comparison rather than path-level comparison. This…
AnalizadaMedia (6.8)0.19%—Pyload-ng Project Pyload-ng7/4/202617/6/2026
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS authorization set in set_config_value() uses incorrect option names ssl_cert and ssl_key, while the actual configuration option names are ssl_certfile and ssl_keyfile. This name mismatch causes the…
AnalizadaAlta (8.8)0.91%—Pyload-ng Project Pyload-ng7/4/202617/6/2026
pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTIONS protection mechanism restricts security-critical configuration values (reconnect scripts, SSL certs, proxy credentials) to admin-only access. However, this protection is only applied to core config…
AnalizadaCrítica (9.3)0.38%—Pyload-ng Project Pyload-ng6/4/202624/7/2026
pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vulnerability. The fix for CVE-2026-33992 added IP validation to BaseDownloader.download() that checks the hostname of the initial download URL. However, pycurl is…
AnalizadaAlta (7.7)0.36%—Pyload-ng Project Pyload-ng6/4/202624/7/2026
pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the parse_urls API function in src/pyload/core/api/__init__.py fetches arbitrary URLs server-side via get_url(url) (pycurl) without any URL validation, protocol restriction, or IP blacklist. An authenticated user with…
AnalizadaAlta (8.8)0.62%—PyloadPyload-ng Project Pyload-ng24/3/202617/6/2026
pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator in pyLoad's ClickNLoad feature can be bypassed by any remote attacker through HTTP Host header spoofing. This allows unauthenticated remote users to access…
AnalizadaAlta (8.8)0.58%—PyloadPyload-ng Project Pyload-ng24/3/202617/6/2026
pyLoad is a free and open-source download manager written in Python. From version 0.4.0 to before version 0.5.0b3.dev97, the set_config_value() API endpoint allows users with the non-admin SETTINGS permission to modify any configuration option without restriction. The reconnect.script config option controls a file…
AnalizadaMedia (6.5)0.18%—Pyload-ng Project Pyload-ng24/3/202617/6/2026
pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, a Host Header Spoofing vulnerability in the @local_check decorator allows unauthenticated external attackers to bypass local-only restrictions. This grants access to the Click'N'Load API endpoints, enabling attackers…
AnalizadaAlta (8.1)0.46%—PyloadPyload-ng Project Pyload-ng20/3/202617/6/2026
pyLoad is a free and open-source download manager written in Python. Versions before 0.5.0b3.dev97 are vulnerable to path traversal during password verification of certain encrypted 7z archives (encrypted files with non-encrypted headers), causing arbitrary file deletion outside of the extraction directory. During…
AnalizadaMedia (6.5)0.53%—Pyload-ng Project Pyload-ng7/3/202617/6/2026
pyLoad is a free and open-source download manager written in Python. From version 0.5.0b3.dev13 to 0.5.0b3.dev96, the edit_package() function implements insufficient sanitization for the pack_folder parameter. The current protection relies on a single-pass string replacement of "../", which can be bypassed using…
AnalizadaCrítica (9.8)1.2%—Pyload-ng Project Pyload-ng5/8/202517/6/2026
pyLoad is the free and open-source Download Manager written in pure Python. In versions 0.5.0b3.dev89 and below, there is an opportunity for path traversal in pyLoad-ng CNL Blueprint via package parameter, allowing Arbitrary File Write which leads to Remote Code Execution (RCE). The addcrypted endpoint in pyload-ng…
AplazadaCrítica (9.8)17%—Pyload-ngAIPythonAI28/10/202417/6/2026
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request.
ModificadaAlta (8.8)0.95%—Pyload-ng Project Pyload-ng18/1/202417/6/2026
pyLoad is a free and open-source Download Manager written in pure Python. The `pyload` API allows any API call to be made using GET requests. Since the session cookie is not set to `SameSite: strict`, this opens the library up to severe attack possibilities via a Cross-Site Request Forgery (CSRF) attack. As a result…
ModificadaAlta (7.4)0.53%—PyloadPyload-ng Project Pyload-ng26/1/202317/6/2026
Improper Certificate Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev44.
ModificadaMedia (5.4)0.83%—PyloadPyload-ng Project Pyload-ng26/1/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository pyload/pyload prior to 0.5.0b3.dev42.
ModificadaMedia (6.1)0.46%—PyloadPyload-ng Project Pyload-ng5/1/202317/6/2026
Improper Restriction of Rendered UI Layers or Frames in GitHub repository pyload/pyload prior to 0.5.0b3.dev33.