AISLE CVE Discoveries

CVEs our AI-native engine discovered in the world's most audited code, responsibly disclosed to maintainers.

350CVEs Assigned
175High/Critical Severity
99Projects Secured

CVE-2026-6473

PostgreSQL
8.8

Integer wraparound undersizes allocations, letting unprivileged users write out of bounds

May 14, 2026View details →

CVE-2026-5136

Foreman
8.8

Privilege escalation to administrator via unvalidated usergroup role assignments

Jul 16, 2026View details →

CVE-2026-2206

WeKan
8.8

Improper access control in the fixDuplicateLists admin repair method

Feb 8, 2026View details →

CVE-2025-66287

WebKitGTK
8.8

Memory corruption when processing crafted web content leading to a process crash

Dec 4, 2025View details →

CVE-2025-62525

openwrt
8.8

Arbitrary kernel memory read and write via ltq-ptm driver ioctls

Oct 22, 2025View details →

CVE-2025-15467

OpenSSL
8.8

Stack buffer overflow via an oversized AEAD IV in CMS (Auth)EnvelopedData parsing

Jan 27, 2026View details →

CVE-2025-10680

OpenVPN
8.8

Shell command injection by a malicious server via DNS variables with --dns-updown

Oct 24, 2025View details →

CVE-2026-75140

jsoup
8.7

Uncontrolled Resource Consumption in XmlTreeBuilder

Aug 20, 2026View details →

CVE-2026-67215

cJSON
8.7

Stack exhaustion via uncontrolled recursion when applying crafted JSON Patch documents

Jul 29, 2026View details →

CVE-2026-65052

Ninja Forms
8.7

Payment total tampering via fail-open get_calc_value() in ListSelect and ListRadio fields

Jul 22, 2026View details →

CVE-2026-64834

FFmpeg
8.7

Infinite loop in rtp_asf_fix_header() via an undersized ASF chunksize

Jul 23, 2026View details →

CVE-2026-33346

openemr
8.7

Stored XSS in the patient portal payment flow executing in staff browsers

Mar 19, 2026View details →

CVE-2026-3505

BC-JAVA
8.7

Unbounded PGP AEAD chunk size allows pre-authentication resource exhaustion

Apr 15, 2026View details →

CVE-2026-76207

phpMyFAQ
8.6

2FA Bypass via Remember-Me Cookie

Aug 21, 2026View details →

CVE-2026-10649

Pacemaker
8.6

Integer overflow in remote message decompression crashes the CIB remote listener

Jun 16, 2026View details →

CVE-2025-68473

esp-idf
8.6

Out-of-bounds write in bta_dm_sdp_result() when SDP discovery returns more than 32 services

Dec 26, 2025View details →

CVE-2026-75144

FFmpeg
8.5

FFmpeg Heap Buffer Overflow in VC-2/Dirac RTP Packetizer

Aug 20, 2026View details →

CVE-2026-75142

FFmpeg
8.5

FFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c

Aug 20, 2026View details →

CVE-2026-75141

FFmpeg
8.5

FFmpeg Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing

Aug 20, 2026View details →

CVE-2026-0861

glibc
8.4

Integer overflow in the memalign function family leading to heap corruption

Jan 14, 2026View details →

CVE-2026-67216

cJSON
8.2

Exponential runtime in cJSON_Compare() on deeply nested JSON, leading to denial of service

Jul 29, 2026View details →

CVE-2026-47688

FOG
8.2

Unauthenticated deletion of host AES keys and power schedules via clearAES and clearPMTasks

May 19, 2026View details →

CVE-2026-42013

GnuTLS
8.2

Certificate validation falls back to Common Name checks on an oversized SAN

May 26, 2026View details →

CVE-2026-5260

GnuTLS
8.2

Heap overread in RSA key exchange with a PKCS#11-backed key via a short premaster secret

May 26, 2026View details →

CVE-2025-11931

wolfSSL
8.2

Integer underflow leading to out-of-bounds access in wc_XChaCha20Poly1305_Decrypt()

Nov 21, 2025View details →

CVE-2026-76886

Wireshark
8.1

Heap-based Buffer Overflow in Wireshark

Aug 21, 2026View details →

CVE-2026-75146

FFmpeg
8.1

FFmpeg Out-of-Bounds Read in DASH Demuxer via dashdec.c

Aug 20, 2026View details →

CVE-2026-44169

MariaDB
8.1

Authorization bypass exposes stored routine definitions to role-granted EXECUTE users

Jun 12, 2026View details →

CVE-2026-42512

FreeBSD
8.1

Heap buffer overflow in dhclient's environment array resizing via a crafted packet

Apr 30, 2026View details →

CVE-2026-42511

FreeBSD
8.1

dhclient.conf directive injection via the BOOTP file field, leading to root code execution

Apr 30, 2026View details →

CVE-2026-34055

openemr
8.1

IDOR in the patient notes web UI allows modifying and deleting arbitrary notes

Mar 25, 2026View details →

CVE-2026-34053

openemr
8.1

Missing authorization lets any user delete procedure orders via handle_deletions.php

Mar 25, 2026View details →

CVE-2026-33302

openemr
8.1

Module ACL check in zhAclCheck() ignores explicit deny entries

Mar 19, 2026View details →

CVE-2026-32126

openemr
8.1

Inverted ACL check in the CDR ControllerRouter lets any user modify clinical rules

Mar 11, 2026View details →

CVE-2026-28472

OpenClaw
8.1

Unvalidated auth.token skips device identity checks in the gateway WebSocket handshake

Mar 5, 2026View details →

CVE-2026-28387

OpenSSL
8.1

Use-after-free in client-side DANE TLSA certificate checking

Apr 7, 2026View details →

CVE-2026-26247

Gitea
8.1

OAuth2 PKCE bypass via unpersisted S256 code_challenge_method during authorization

Jul 16, 2026View details →

CVE-2026-25941

FreeRDP
8.1

Out-of-bounds read in the RDPGFX channel via a crafted WIRE_TO_SURFACE_2 PDU

Feb 25, 2026View details →

CVE-2026-25164

openemr
8.1

Missing ACL checks on the document and insurance REST API routes

Feb 25, 2026View details →

CVE-2026-24890

openemr
8.1

Provider signature forgery via missing authorization in the portal signature endpoint

Feb 25, 2026View details →

CVE-2025-15382

wolfSSH
8.1

Heap buffer over-read in wolfSSH_CleanPath() via SCP paths containing '/./' sequences

Jan 6, 2026View details →

CVE-2026-25532

esp-idf
8.0

Integer underflow in WPS Enrollee fragment length handling via truncated EAP-WSC packets

Feb 4, 2026View details →

CVE-2026-72693

openvt
7.8

Local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login

Aug 11, 2026View details →

CVE-2026-48864

libsolv
7.8

Heap buffer overflow when decompressing page data from crafted .solv files

May 26, 2026View details →

CVE-2026-43958

rrdtool
7.8

Stack buffer overflow in rrdcached via an oversized CREATE request

Jun 1, 2026View details →

CVE-2026-39457

FreeBSD
7.8

Stack buffer overflow in libnv via file descriptors exceeding FD_SETSIZE in select()

Apr 30, 2026View details →

CVE-2026-32647

NGINX Open Source
7.8

Buffer over-read and over-write in ngx_http_mp4_module when processing crafted MP4 files

Mar 24, 2026View details →

CVE-2026-18157

yggdrasil-worker-package-manager
7.8

Argument injection in the APT backend via crafted package names leading to root code execution

Jul 31, 2026View details →
CTA background

Meet the system that responds
faster than you can say CVE.