Vulnerabilities > Circl

DATE CVE VULNERABILITY TITLE RISK
2023-01-10 CVE-2023-22898 Improper Input Validation vulnerability in Circl Pandora
workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits a deeply nested ZIP archive (aka ZIP bomb).
network
low complexity
circl CWE-20
6.5
2021-12-23 CVE-2021-45470 Unspecified vulnerability in Circl Cve-Search
lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular expression denial of service) or other impacts.
network
low complexity
circl
7.5
2020-02-03 CVE-2020-8545 Path Traversal vulnerability in Circl AIL Framework 2.8
Global.py in AIL framework 2.8 allows path traversal.
network
low complexity
circl CWE-22
5.0