GammaC0de
20 exploits
Active since Jan 2023
pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)
CVSS 8.8
pyLoad has Improper Neutralization of Special Elements used in an OS Command
CVSS 8.8
pyLoad has an incomplete fix for CVE-2026-33509: unprotected storage_folder enables arbitrary file write to Flask session store and code execution
CVSS 7.5
pyLoad has SSRF in parse_urls API endpoint via unvalidated URL parameter
CVSS 7.7
pyLoad has SSRF fix bypass via HTTP redirect
CVSS 9.1
pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration
CVSS 6.5
pyload <0.5.0b3.dev32 - Info Disclosure
CVSS 5.3
pyload <0.5.0b3.dev33 - Info Disclosure
CVSS 6.1
pyload <0.5.0b3.dev36 - Info Disclosure
CVSS 6.5
Pyload < 0.4.9 - Improper Input Validation
CVSS 7.5
pyload/pyload <0.5.0b3.dev41 - Info Disclosure
CVSS 9.8
Pyload < 2023-01-24 - XSS
CVSS 5.4
Pyload < 2023-01-25 - Improper Certificate Validation
CVSS 7.4
Pyload - Open Redirect
CVSS 6.1
Pyload < 0.4.9 - Injection
CVSS 5.3
pyLoad - Open Redirect
CVSS 4.7
pyload - RCE
CVSS 9.8
Pyload-ng < 0.5.0b3.dev90 - Path Traversal
CVSS 9.8
pyLoad <0.5.0b3.dev91 - SQL Injection
Pypi Pyload-ng < 0.5.0b3.dev91 - XSS
CVSS 8.1