Pyload

Pyload

49 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.27%
  • Veröffentlicht 06.04.2026 19:33:06
  • Zuletzt bearbeitet 24.07.2026 21:10:00

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the parse_urls API function in src/pyload/core/api/__init__.py fetches arbitrary URLs server-side via get_url(url) (pycurl) without any URL validation,...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 27.03.2026 22:12:39
  • Zuletzt bearbeitet 31.03.2026 14:49:16

pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, PyLoad's download engine accepts arbitrary URLs without validation, enabling Server-Side Request Forgery (SSRF) attacks. An authenticated attacker ca...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 24.03.2026 18:56:08
  • Zuletzt bearbeitet 26.03.2026 20:29:49

pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator in pyLoad's ClickNLoad feature can be bypassed by any remote attacker through HTTP Host header spoofin...

Exploit
  • EPSS 0.53%
  • Veröffentlicht 24.03.2026 18:55:37
  • Zuletzt bearbeitet 26.03.2026 20:47:02

pyLoad is a free and open-source download manager written in Python. From version 0.4.0 to before version 0.5.0b3.dev97, the set_config_value() API endpoint allows users with the non-admin SETTINGS permission to modify any configuration option withou...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 24.03.2026 18:52:28
  • Zuletzt bearbeitet 26.03.2026 12:01:09

pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, a Host Header Spoofing vulnerability in the @local_check decorator allows unauthenticated external attackers to bypass local-only restrictions. This ...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 20.03.2026 02:16:34
  • Zuletzt bearbeitet 26.03.2026 18:36:48

pyLoad is a free and open-source download manager written in Python. Versions before 0.5.0b3.dev97 are vulnerable to path traversal during password verification of certain encrypted 7z archives (encrypted files with non-encrypted headers), causing ar...

Exploit
  • EPSS 0.52%
  • Veröffentlicht 07.03.2026 15:28:36
  • Zuletzt bearbeitet 11.03.2026 22:09:15

pyLoad is a free and open-source download manager written in Python. From version 0.5.0b3.dev13 to 0.5.0b3.dev96, the edit_package() function implements insufficient sanitization for the pack_folder parameter. The current protection relies on a singl...

  • EPSS 0.39%
  • Veröffentlicht 09.10.2025 20:49:53
  • Zuletzt bearbeitet 15.04.2026 00:35:42

pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web interface contained insufficient input validation in both the Captcha script endpoint and the Click'N'Load (CNL) Blueprint. This flaw ...

  • EPSS 0.32%
  • Veröffentlicht 21.08.2025 18:27:04
  • Zuletzt bearbeitet 15.04.2026 00:35:42

pyLoad is the free and open-source Download Manager written in pure Python. The jk parameter is received in pyLoad CNL Blueprint. Due to the lack of jk parameter verification, the jk parameter input by the user is directly determined as dykpy.evaljs(...

  • EPSS 0.33%
  • Veröffentlicht 11.08.2025 22:21:52
  • Zuletzt bearbeitet 15.04.2026 00:35:42

pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the parameter add_links in API /json/add_package is vulnerable to SQL Injection. Attackers can modify or delete data in the database, causing ...