Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.32% | — | Circl AIL FrameworkAI | 25/9/2026 | 25/9/2026 | The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS). User-supplied data originating from imported crawler captures—specifically item IDs, URLs, and screenshot file paths—was interpolated directly into inline JavaScript contexts within the HTML… | |
| Aplazada | Media (6.9) | 0.43% | — | Circl AIL FrameworkAI | 25/9/2026 | 25/9/2026 | The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that accepted URLs as valid .onion targets based solely on a length check (exactly 69 characters) and a suffix check (ending in ".onion"), without performing proper hostname parsing or onion-domain validation. An… | |
| Aplazada | Media (6.3) | 0.34% | — | Circl AIL FrameworkAI | 25/9/2026 | 25/9/2026 | The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a user supplied a cookiejar UUID to attach to a one-shot or scheduled crawler task. The original code only verified that the cookiejar existed and, if its access level was 0, compared the cookiejar's… | |
| Aplazada | Alta (8.5) | 0.35% | — | Circl AIL FrameworkAI | 25/9/2026 | 25/9/2026 | The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS). Usernames imported from chats and crawled forums are stored without character restrictions. When an authenticated analyst views the username timeline, the application renders these stored usernames into the DOM using D3's… | |
| Aplazada | Media (5.1) | 0.40% | — | Circl AIL FrameworkAI | 25/9/2026 | 25/9/2026 | The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS). A user with the ability to create a custom tag could embed an HTML payload containing JavaScript event handlers (e.g., <img src=x onerror=alert(1)> or <svg onload=...>) in the tag name. When another… | |
| Aplazada | Alta (8.5) | 0.27% | — | Circl AIL FrameworkAI | 25/9/2026 | 25/9/2026 | The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 templates that render popovers for matched, tracked, or tagged content: var/www/templates/chats_explorer/block_message.html and var/www/templates/objects/item/show_item.html. In both templates,… | |
| Aplazada | Media (6.2) | 0.19% | — | Nextcloud CirclesAI | 18/9/2026 | 18/9/2026 | Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF protections. The public, unauthenticated endpoints POST /apps/circles/event/ and… | |
| Aplazada | Alta (7.1) | 0.40% | — | Circl AIL FrameworkAI | 19/8/2026 | 26/8/2026 | AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission functionality. A low-privileged authenticated user with access to the crawler interface can submit an arbitrary URL for crawling without adequate validation of the destination host. The crawler can therefore be… | |
| Aplazada | Alta (8.2) | 0.40% | — | Circl AIL FrameworkAI | 6/8/2026 | 26/8/2026 | AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occurred while processing a tag operation, the application returned the error value directly as an HTML response using str(res[0]). If attacker-controlled input was included in the generated error… | |
| Aplazada | Alta (7.1) | 0.51% | — | Circl AIL FrameworkAI | 5/7/2026 | 6/7/2026 | AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.get_filepath() function constructed a file path by joining the configured PDF storage directory with a path derived from a PDF object identifier, without verifying that… | |
| Aplazada | Crítica (9.2) | 1.4% | — | Circl Cve-searchAI | 5/7/2026 | 6/7/2026 | An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote attacker can manipulate request parameters controlling the MongoDB collection, projected fields, and regular-expression filters to read arbitrary application MongoDB collections. This can expose… | |
| Aplazada | Alta (8.3) | 0.44% | — | Circl AIL FrameworkAI | 22/6/2026 | 22/6/2026 | A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticated AIL user can supply crafted object identifiers through the investigation workflow to cause file paths to resolve outside the intended image, favicon, or screenshot… | |
| Aplazada | Media (5.3) | 0.51% | — | Circl AIL FrameworkAI | 19/6/2026 | 22/6/2026 | AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item identifiers through the s1 and s2 query parameters and, prior to the fix, attempted to retrieve and compare item contents without first verifying that both referenced items existed as valid AIL objects.… | |
| Aplazada | Media (6.4) | 0.41% | — | WP CirclifulAI | 15/4/2026 | 17/6/2026 | The WP Circliful plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of the [circliful] shortcode and via multiple shortcode attributes of the [circliful_direct] shortcode in all versions up to and including 1.2. This is due to insufficient input sanitization and output… | |
| Analizada | Alta (8.5) | 0.30% | — | Circl AIL Framework | 8/4/2026 | 24/7/2026 | AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a stored cross-site scripting (XSS) vulnerability was identified in the modal item preview functionality. When item content longer than 800 characters was processed, attacker-controlled content was returned… | |
| Analizada | Baja (2.9) | 0.39% | — | Cloudflare Circl | 24/2/2026 | 17/6/2026 | The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected. The bug was fixed in v1.6.3… | |
| Aplazada | Baja (3.7) | 0.48% | — | CirclAI | 6/8/2025 | 17/6/2026 | A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange. | |
| Aplazada | Media (4.9) | 0.41% | — | I13websolution Team Circle Image Slider With LightboxAI | 8/4/2025 | 17/6/2026 | The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.13% | — | James Andrews Full CircleAI | 31/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in James Andrews Full Circle full-circle allows Stored XSS.This issue affects Full Circle: from n/a through <= 0.5.7.8. | |
| Aplazada | Media (6.5) | 0.23% | — | Harun R Rayhan CC Circle Progress BARAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Harun R. Rayhan(thecrazycoder) CC Circle Progress Bar cc-circle-progress-bar allows Stored XSS.This issue affects CC Circle Progress Bar: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.4) | 0.35% | — | ScancircleAI | 18/12/2024 | 17/6/2026 | The ScanCircle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'scancircle' shortcode in all versions up to, and including, 2.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.4) | 0.40% | — | Shafayat Pure CSS Circle Progress BAR | 21/11/2024 | 17/6/2026 | The Pure CSS Circle Progress bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'circle_progress' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (4.3) | 0.20% | — | I13websolution Team Circle Image Slider With Lightbox | 13/3/2024 | 17/6/2026 | The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the circle_thumbnail_slider_with_lightbox_image_management_func() function. This makes it possible for unauthenticated attackers to edit… | |
| Modificada | Media (6.1) | 0.43% | — | I13websolution Team Circle Image Slider With Lightbox | 9/6/2023 | 17/6/2026 | The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Modificada | Alta (8.2) | 0.39% | — | Cloudflare Circl | 10/5/2023 | 17/6/2026 | When sampling randomness for a shared secret, the implementation of Kyber and FrodoKEM, did not check whether crypto/rand.Read() returns an error. In rare deployment cases (error thrown by the Read() function), this could lead to a predictable shared secret. The tkn20 and blindrsa components did not check whether… |