← Back

Circl

circl

4 CVEs • 3 products

Products (3)

Click to collapse
Toggle
Ail Framework
ail_framework
Cve Search
cve-search
Pandora
pandora

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Circl
1Ail Framework
Jul 24, 2026
Apr 8, 2026
8.5 HIGH· v4
6.1 MEDIUM· v3
N/A· v2
AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a stored cross-site scripting (XSS) vulnerability was identified in the modal item preview functionality. W...Show more
AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a stored cross-site scripting (XSS) vulnerability was identified in the modal item preview functionality. When item content longer than 800 characters was processed, attacker-controlled content was returned without an explicit text/plain content type, allowing the browser to interpret the response as active HTML. This could result in execution of arbitrary JavaScript in the context of an authenticated user viewing a crafted item. This vulnerability is fixed in 6.8.Show less
1Circl
1Pandora
Jun 17, 2026
Jan 10, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits a deeply nested ZIP archive (aka ZIP bomb).
1Circl
1Cve Search
Jun 17, 2026
Dec 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular expression denial of service) or other impacts.
1Circl
1Ail Framework
Jun 17, 2026
Feb 3, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Global.py in AIL framework 2.8 allows path traversal.