AISLE CVE Discoveries
CVEs our AI-native engine discovered in the world's most audited code, responsibly disclosed to maintainers.
CVE-2026-6473
PostgreSQLInteger wraparound undersizes allocations, letting unprivileged users write out of bounds
CVE-2026-5136
ForemanPrivilege escalation to administrator via unvalidated usergroup role assignments
CVE-2026-2206
WeKanImproper access control in the fixDuplicateLists admin repair method
CVE-2025-66287
WebKitGTKMemory corruption when processing crafted web content leading to a process crash
CVE-2025-62525
openwrtArbitrary kernel memory read and write via ltq-ptm driver ioctls
CVE-2025-15467
OpenSSLStack buffer overflow via an oversized AEAD IV in CMS (Auth)EnvelopedData parsing
CVE-2025-10680
OpenVPNShell command injection by a malicious server via DNS variables with --dns-updown
CVE-2026-75140
jsoupUncontrolled Resource Consumption in XmlTreeBuilder
CVE-2026-67215
cJSONStack exhaustion via uncontrolled recursion when applying crafted JSON Patch documents
CVE-2026-65052
Ninja FormsPayment total tampering via fail-open get_calc_value() in ListSelect and ListRadio fields
CVE-2026-64834
FFmpegInfinite loop in rtp_asf_fix_header() via an undersized ASF chunksize
CVE-2026-33346
openemrStored XSS in the patient portal payment flow executing in staff browsers
CVE-2026-3505
BC-JAVAUnbounded PGP AEAD chunk size allows pre-authentication resource exhaustion
CVE-2026-76207
phpMyFAQ2FA Bypass via Remember-Me Cookie
CVE-2026-10649
PacemakerInteger overflow in remote message decompression crashes the CIB remote listener
CVE-2025-68473
esp-idfOut-of-bounds write in bta_dm_sdp_result() when SDP discovery returns more than 32 services
CVE-2026-75144
FFmpegFFmpeg Heap Buffer Overflow in VC-2/Dirac RTP Packetizer
CVE-2026-75142
FFmpegFFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c
CVE-2026-75141
FFmpegFFmpeg Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing
CVE-2026-0861
glibcInteger overflow in the memalign function family leading to heap corruption
CVE-2026-67216
cJSONExponential runtime in cJSON_Compare() on deeply nested JSON, leading to denial of service
CVE-2026-47688
FOGUnauthenticated deletion of host AES keys and power schedules via clearAES and clearPMTasks
CVE-2026-42013
GnuTLSCertificate validation falls back to Common Name checks on an oversized SAN
CVE-2026-5260
GnuTLSHeap overread in RSA key exchange with a PKCS#11-backed key via a short premaster secret
CVE-2025-11931
wolfSSLInteger underflow leading to out-of-bounds access in wc_XChaCha20Poly1305_Decrypt()
CVE-2026-76886
WiresharkHeap-based Buffer Overflow in Wireshark
CVE-2026-75146
FFmpegFFmpeg Out-of-Bounds Read in DASH Demuxer via dashdec.c
CVE-2026-44169
MariaDBAuthorization bypass exposes stored routine definitions to role-granted EXECUTE users
CVE-2026-42512
FreeBSDHeap buffer overflow in dhclient's environment array resizing via a crafted packet
CVE-2026-42511
FreeBSDdhclient.conf directive injection via the BOOTP file field, leading to root code execution
CVE-2026-34055
openemrIDOR in the patient notes web UI allows modifying and deleting arbitrary notes
CVE-2026-34053
openemrMissing authorization lets any user delete procedure orders via handle_deletions.php
CVE-2026-33302
openemrModule ACL check in zhAclCheck() ignores explicit deny entries
CVE-2026-32126
openemrInverted ACL check in the CDR ControllerRouter lets any user modify clinical rules
CVE-2026-28472
OpenClawUnvalidated auth.token skips device identity checks in the gateway WebSocket handshake
CVE-2026-28387
OpenSSLUse-after-free in client-side DANE TLSA certificate checking
CVE-2026-26247
GiteaOAuth2 PKCE bypass via unpersisted S256 code_challenge_method during authorization
CVE-2026-25941
FreeRDPOut-of-bounds read in the RDPGFX channel via a crafted WIRE_TO_SURFACE_2 PDU
CVE-2026-25164
openemrMissing ACL checks on the document and insurance REST API routes
CVE-2026-24890
openemrProvider signature forgery via missing authorization in the portal signature endpoint
CVE-2025-15382
wolfSSHHeap buffer over-read in wolfSSH_CleanPath() via SCP paths containing '/./' sequences
CVE-2026-25532
esp-idfInteger underflow in WPS Enrollee fragment length handling via truncated EAP-WSC packets
CVE-2026-72693
openvtLocal privilege escalation in openvt via incorrect process owner verification allowing passwordless root login
CVE-2026-48864
libsolvHeap buffer overflow when decompressing page data from crafted .solv files
CVE-2026-43958
rrdtoolStack buffer overflow in rrdcached via an oversized CREATE request
CVE-2026-39457
FreeBSDStack buffer overflow in libnv via file descriptors exceeding FD_SETSIZE in select()
CVE-2026-32647
NGINX Open SourceBuffer over-read and over-write in ngx_http_mp4_module when processing crafted MP4 files
CVE-2026-18157
yggdrasil-worker-package-managerArgument injection in the APT backend via crafted package names leading to root code execution
