Circl operates a portfolio of focused open-source tools for cybersecurity threat intelligence and vulnerability indexing, including the AIL Framework, CVE-Search, and Pandora, which serve defensive researchers and security teams in identifying and correlating vulnerability data. The durable signal across these products centers on application-layer input-handling weaknesses such as improper input validation, path-traversal conditions, cross-site scripting, and regular-expression complexity issues, reflecting the parsing and web-interface demands of threat-intelligence platforms; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Computer Incident Response Center Luxembourg (CIRCL) over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8545HIGH Global.py in AIL framework 2.8 allows path traversal. | Feb 3, 2020 | 7.5 | 23 | NO | NO |
CVE-2026-39416MEDIUM AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a stored cross-site scripting (XSS) vulnerability was identified in | Apr 8, 2026 | 6.1 | 21 | NO | NO |
CVE-2021-45470HIGH lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular expression denial of service) or other impacts. | Dec 23, 2021 | 7.5 | 20 | NO | NO |
CVE-2023-22898MEDIUM workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits a deeply nested ZIP archive (aka ZIP bomb). | Jan 10, 2023 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Computer Incident Response Center Luxembourg (CIRCL).
Media articles that mention a CVE ID that affects a product developed by Computer Incident Response Center Luxembourg (CIRCL) — matched by CVE ID, not by vendor name.