Title |
Severity |
Exploit |
Date |
Affected Version |
CVE-2024-1968
|
Medium
|
|
May 20, 2024
|
< 2.11.2
|
Scrapy allows redirect following in protocols other than HTTP
|
Medium
|
|
May 14, 2024
|
< 2.11.2
|
Scrapy's redirects ignoring scheme-specific proxy settings
|
Medium
|
|
May 14, 2024
|
< 2.11.2
|
CVE-2024-3574
|
High
|
|
Apr 16, 2024
|
>= 2 < 2.11.1
< 1.8.4
|
CVE-2024-3572
|
High
|
|
Apr 16, 2024
|
>= 2.0.0 < 2.11.1
< 1.8.4
|
CVE-2024-1892
|
Medium
|
|
Feb 28, 2024
|
>= 2 < 2.11.1
< 1.8.4
|
Scrapy decompression bomb vulnerability
|
High
|
|
Feb 16, 2024
|
>= 2.0.0 < 2.11.1
< 1.8.4
|
Scrapy authorization header leakage on cross-domain redirect
|
High
|
|
Feb 15, 2024
|
>= 2 < 2.11.1
< 1.8.4
|
ReDos vulnerability of XMLFeedSpider
|
High
|
|
Feb 15, 2024
|
>= 2 < 2.11.1
< 1.8.4
|
Scrapy before v2.6.2 and v1.8.3 vulnerable to one proxy sending credentials to another
|
Medium
|
|
Jul 29, 2022
|
< 1.8.3
>= 2.0.0 < 2.6.2
|