Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

pypi gradio Security Advisories

Loading...
High
GSA_kwCzR0hTQS1nOWNqLWNmcHAtNGcyeM4AA7B5
gradio vulnerable to Path Traversal
Ecosystems: pypi
Packages: gradio
Source: GitHub Advisory Database
Blast Radius: 30.5
Published: 8 days ago
Moderate
GSA_kwCzR0hTQS1xaDZ4LWo4MmgtdnBmOc4AA7CK
gradio Server-Side Request Forgery vulnerability
Ecosystems: pypi
Packages: gradio
Source: GitHub Advisory Database
Blast Radius: 26.5
Published: 8 days ago
High
GSA_kwCzR0hTQS0zZjk1LW14cTItMmY2M84AA64H
Gradio Local File Inclusion vulnerability
Ecosystems: pypi
Packages: gradio
Source: GitHub Advisory Database
Blast Radius: 30.5
Published: 14 days ago
High
GSA_kwCzR0hTQS1yMzY0LW0yajktbWY0aM4AA6Un
gradio Server-Side Request Forgery vulnerability
Ecosystems: pypi
Packages: gradio
Source: GitHub Advisory Database
Blast Radius: 29.7
Published: 28 days ago
Moderate
GSA_kwCzR0hTQS0zeDlnLXhmajUtZnE4NM4AA6Nf
Cross-Site Request Forgery in Gradio
Ecosystems: pypi
Packages: gradio
Source: GitHub Advisory Database
Blast Radius: 17.5
Published: about 1 month ago
Moderate
GSA_kwCzR0hTQS1obXg2LXI3NmMtODVnOc4AA5du
Gradio apps vulnerable to timing attacks to guess password
Ecosystems: pypi
Packages: gradio
Source: GitHub Advisory Database
Blast Radius: 24.0
Published: 2 months ago
High
GSA_kwCzR0hTQS1mM2g5LThwaGMtNmd2aM4AA5F4
Gradio Path Traversal vulnerability
Ecosystems: pypi
Packages: gradio
Source: GitHub Advisory Database
Blast Radius: 30.5
Published: 3 months ago
High
GSA_kwCzR0hTQS02cW0yLXdweHEtN3FoMs4AA39-
Gradio makes the `/file` secure against file traversal and server-side request forgery attacks
Ecosystems: pypi
Packages: gradio
Source: GitHub Advisory Database
Blast Radius: 35.0
Published: 4 months ago
Critical
GSA_kwCzR0hTQS1ncXZmLTNoZ3AtNWh4ds4AA3xA
Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Ecosystems: pypi
Packages: gradio
Source: GitHub Advisory Database
Blast Radius: 39.1
Published: 4 months ago
Moderate
GSA_kwCzR0hTQS12NHE5LXFncWYtN2p3cM4AA15s
Gradio arbitrary file upload vulnerability
Ecosystems: pypi
Packages: gradio
Source: GitHub Advisory Database
Blast Radius: 19.6
Published: 7 months ago
High
GSA_kwCzR0hTQS0zcXFnLXBncXEtMzY5Nc4AAzxc
Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
Ecosystems: pypi
Packages: gradio
Source: GitHub Advisory Database
Blast Radius: 29.7
Published: 11 months ago
Moderate
GSA_kwCzR0hTQS0zeDVqLTl2d3ItOHJyNc4AAxyq
Update share links to use FRP instead of SSH tunneling
Ecosystems: pypi
Packages: gradio
Source: GitHub Advisory Database
Blast Radius: 22.0
Published: about 1 year ago
High
GSA_kwCzR0hTQS1mOHhxLXE3cHgtd2c4Y800Kw
Improper Neutralization of Formula Elements in a CSV File in Gradio Flagging
Ecosystems: pypi
Packages: gradio
Source: GitHub Advisory Database
Blast Radius: 35.8
Published: about 2 years ago
High
GSA_kwCzR0hTQS1yaHEyLTN2cjktNm1jcs0kJA
Files on the host computer can be accessed from the Gradio interface
Ecosystems: pypi
Packages: gradio
Source: GitHub Advisory Database
Blast Radius: 33.8
Published: over 2 years ago
Statistics
Advisories: 17,749
Packages: 8,183
Repositories: 2
Ecosystems: 12
Filter by Package
tensorflow 432 tensorflow-cpu 387 tensorflow-gpu 384 django 80 apache-airflow 78 ansible 63 apache-superset 48 plone 42 rdiffweb 42 Pillow 41 salt 38 Plone 36 matrix-synapse 35 vyper 32 opencv-contrib-python 30 opencv-python 30 mlflow 30 Django 21 langchain 18 PaddlePaddle 17 cobbler 17 cryptography 15 pillow 15 notebook 15 paddlepaddle 15 gradio 14 modoboa 14 pyload-ng 13 pyftpdlib 13 nova 13 keystone 12 OctoPrint 12 vantage6 12 neutron 12 twisted 11 calibreweb 11 urllib3 11 onionshare-cli 11 glance 11 Flask-AppBuilder 10 aiohttp 10 kiwitcms 9 waitress 9 zope 9 wagtail 9 Zope 9 moin 9 opencv-contrib-python-headless 9 opencv-python-headless 9 ethyca-fides 9 aubio 8 numpy 8 label-studio 8 pysaml2 7 scrapy 7 lief 7 pip 7 python-keystoneclient 7 matrix-sydent 7 nautobot 7 swift 7 jupyter-server 7 pgadmin4 6 lxml 6 tuf 6 mailman 6 apache-airflow-providers-apache-hive 6 graphite-web 6 mindsdb 6 Zope2 6 sentry 6 web2py 6 ipython 6 inventree 6 requests 5 bleach 5 paramiko 5 lmdb 5 Products.CMFPlone 5 pyspark 5 whoogle-search 5 python-gnupg 5 roundup 5 saleor 5 horizon 5 trytond 5 ckan 5 feedparser 5 omero-web 4 bottle 4 nvflare 4 httpie 4 FreeTAKServer-UI 4 Flask-Security-Too 4 datasette 4 ansible-core 4 transformers 4 nltk 4 Jinja2 4 markdown2 4 oauthenticator 4 yt-dlp 4 reportlab 4 starlette 4 werkzeug 4 grpc 4 grpcio 4 Pygments 4 buildbot 4 esphome 4 PyPDF2 4 software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk 4 GitPython 4 pretix 4 aws-iot-device-sdk-v2 4 awsiotsdk 4 qutebrowser 4 keylime 4 jupyterhub 4 aim 3 io.grpc:grpc-protobuf 3 Products.PluggableAuthService 3 apache-libcloud 3 indy-node 3 tripleo-heat-templates 3 barbican 3 sanic 3 tornado 3 onnx 3 pyarrow 3 asyncssh 3 ray 3 zenml 3 flask 3 rsa 3 apache-iotdb 3 pyyaml 3 django-helpdesk 3 sqlparse 3 ujson 3 ansible-runner 3 fava 3 pandasai 3 Weblate 3 mayan-edms 3 asyncua 3 jwcrypto 3 pywasm3 3 mitmproxy 3 Werkzeug 3 cinder 3 copyparty 3 localstack 3 apache-airflow-providers-apache-spark 3 mistune 3 ecdsa 3 Keystone 3 poetry 3 quokka 3 plone.app.event 3 plone.app.theming 3 openvpn-monitor 3 gerapy 3 wger 3 indico 3 sickrage 3 keyring 3 torchserve 3 slixmpp 3 ryu 3 bitlyshortener 3 jupyterlab 3 clearml 3 docassemble.webapp 3 streamlit 3 protobuf 3 plone.supermodel 3 plone.app.dexterity 3 mercurial 2 openapi-python-client 2 dtale 2 uvicorn 2 tlslite-ng 2 pyopenssl 2 flaskcode 2 wasm3 2 in-toto 2 tripleo-ansible 2 scancodeio 2 aws-encryption-sdk 2 apache-airflow-providers-apache-drill 2 snowflake-connector-python 2 aiohttp-session 2 keystonemiddleware 2 pyxdg 2 DIRAC 2 zope2 2 python-cjson 2 Products.CMFCore 2 mako 2