Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.32% | — | Circl AIL FrameworkAI | 25/9/2026 | 25/9/2026 | The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS). User-supplied data originating from imported crawler captures—specifically item IDs, URLs, and screenshot file paths—was interpolated directly into inline JavaScript contexts within the HTML… | |
| Aplazada | Media (6.9) | 0.43% | — | Circl AIL FrameworkAI | 25/9/2026 | 25/9/2026 | The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that accepted URLs as valid .onion targets based solely on a length check (exactly 69 characters) and a suffix check (ending in ".onion"), without performing proper hostname parsing or onion-domain validation. An… | |
| Aplazada | Media (6.3) | 0.34% | — | Circl AIL FrameworkAI | 25/9/2026 | 25/9/2026 | The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a user supplied a cookiejar UUID to attach to a one-shot or scheduled crawler task. The original code only verified that the cookiejar existed and, if its access level was 0, compared the cookiejar's… | |
| Aplazada | Alta (8.5) | 0.35% | — | Circl AIL FrameworkAI | 25/9/2026 | 25/9/2026 | The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS). Usernames imported from chats and crawled forums are stored without character restrictions. When an authenticated analyst views the username timeline, the application renders these stored usernames into the DOM using D3's… | |
| Aplazada | Media (5.1) | 0.40% | — | Circl AIL FrameworkAI | 25/9/2026 | 25/9/2026 | The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS). A user with the ability to create a custom tag could embed an HTML payload containing JavaScript event handlers (e.g., <img src=x onerror=alert(1)> or <svg onload=...>) in the tag name. When another… | |
| Aplazada | Alta (8.5) | 0.27% | — | Circl AIL FrameworkAI | 25/9/2026 | 25/9/2026 | The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 templates that render popovers for matched, tracked, or tagged content: var/www/templates/chats_explorer/block_message.html and var/www/templates/objects/item/show_item.html. In both templates,… | |
| Aplazada | Alta (7.1) | 0.40% | — | Circl AIL FrameworkAI | 19/8/2026 | 26/8/2026 | AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission functionality. A low-privileged authenticated user with access to the crawler interface can submit an arbitrary URL for crawling without adequate validation of the destination host. The crawler can therefore be… | |
| Aplazada | Alta (8.2) | 0.40% | — | Circl AIL FrameworkAI | 6/8/2026 | 26/8/2026 | AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occurred while processing a tag operation, the application returned the error value directly as an HTML response using str(res[0]). If attacker-controlled input was included in the generated error… | |
| Aplazada | Alta (7.1) | 0.51% | — | Circl AIL FrameworkAI | 5/7/2026 | 6/7/2026 | AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.get_filepath() function constructed a file path by joining the configured PDF storage directory with a path derived from a PDF object identifier, without verifying that… | |
| Aplazada | Alta (8.3) | 0.44% | — | Circl AIL FrameworkAI | 22/6/2026 | 22/6/2026 | A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticated AIL user can supply crafted object identifiers through the investigation workflow to cause file paths to resolve outside the intended image, favicon, or screenshot… | |
| Aplazada | Media (5.3) | 0.51% | — | Circl AIL FrameworkAI | 19/6/2026 | 22/6/2026 | AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item identifiers through the s1 and s2 query parameters and, prior to the fix, attempted to retrieve and compare item contents without first verifying that both referenced items existed as valid AIL objects.… | |
| Analizada | Alta (8.5) | 0.30% | — | Circl AIL Framework | 8/4/2026 | 24/7/2026 | AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a stored cross-site scripting (XSS) vulnerability was identified in the modal item preview functionality. When item content longer than 800 characters was processed, attacker-controlled content was returned… | |
| Modificada | Alta (7.5) | 1.3% | — | Circl AIL Framework | 3/2/2020 | 17/6/2026 | Global.py in AIL framework 2.8 allows path traversal. |