AISLE CVE Discoveries

CVEs our AI-native engine discovered in the world's most audited code, responsibly disclosed to maintainers.

350CVEs Assigned
175High/Critical Severity
99Projects Secured

CVE-2026-10118

Poppler
7.8

Integer overflow in SplashOutputDev::tilingPatternFill leading to heap buffer overflow

Jun 1, 2026View details →

CVE-2025-59534

CryptoLib
7.8

Command injection in initialize_kerberos_keytab_file_login()

Sep 23, 2025View details →

CVE-2026-46518

openemr
7.7

Stored XSS in the prescription multi-print view via patient demographic fields

Jun 9, 2026View details →

CVE-2026-32123

openemr
7.7

Broken sensitivity check lets restricted users view sensitive group encounters

Mar 11, 2026View details →

CVE-2026-32121

openemr
7.7

Stored DOM XSS in the portal signer modal via unsanitized patient names

Mar 11, 2026View details →

CVE-2026-33932

openemr
7.6

Stored XSS in the CCDA document preview via unsanitized linkHtml attributes

Mar 25, 2026View details →

CVE-2025-68474

esp-idf
7.6

Out-of-bounds write in avrc_vendor_msg() when handling AVRCP vendor commands

Dec 26, 2025View details →

CVE-2026-76928

Wireshark
7.5

NULL Pointer Dereference in Wireshark

Aug 21, 2026View details →

CVE-2026-76880

Wireshark
7.5

Out-of-bounds Write in Wireshark

Aug 21, 2026View details →

CVE-2026-76879

Wireshark
7.5

Stack-based Buffer Overflow in Wireshark

Aug 21, 2026View details →

CVE-2026-73198

freeipa
7.5

Unauthenticated DoS in via unbounded request body read

Aug 21, 2026View details →

CVE-2026-73197

freeipa
7.5

Unauthenticated DoS in `/ipa/migration/migration.py` via unbounded request body read

Aug 21, 2026View details →

CVE-2026-71217

Iperf3
7.5

Unbounded peer-controlled json parameters enables remote denial of service via resource exhaustion

Aug 11, 2026View details →

CVE-2026-54554

FOG
7.5

Unauthenticated disclosure of the Active Directory default join password via adInfo()

Jun 14, 2026View details →

CVE-2026-53460

ImageMagick
7.5

Unbounded memory request in AcquireAlignedMemory leading to out-of-memory condition

Jun 10, 2026View details →

CVE-2026-49218

ImageMagick
7.5

Missing check in the DCM decoder allows images with invalid dimensions, causing crashes

Jun 10, 2026View details →

CVE-2026-48863

libsolv
7.5

Stack buffer overflow verifying EdDSA PGP signatures with mismatched MPI lengths

Jul 24, 2026View details →

CVE-2026-42765

OpenSSL
7.5

NULL pointer dereference during OCSP chain checking with partial-chain verification

Jun 9, 2026View details →

CVE-2026-42009

GnuTLS
7.5

Denial of service via duplicate sequence numbers in DTLS packet reordering

May 18, 2026View details →

CVE-2026-29169

GnuTLS
7.5

NULL pointer dereference in mod_dav_lock via a malicious request

May 4, 2026View details →

CVE-2026-28454

OpenClaw
7.5

Unvalidated Telegram webhook secret allows forged updates that bypass sender allowlists

Mar 5, 2026View details →

CVE-2026-28390

OpenSSL
7.5

NULL pointer dereference when processing CMS KeyTransportRecipientInfo

Apr 7, 2026View details →

CVE-2026-28389

OpenSSL
7.5

NULL pointer dereference when processing CMS KeyAgreeRecipientInfo

Apr 7, 2026View details →

CVE-2026-28388

OpenSSL
7.5

NULL pointer dereference when processing a delta CRL missing the CRL Number extension

Apr 7, 2026View details →

CVE-2026-28386

OpenSSL
7.5

Out-of-bounds read when processing partial AES-CFB128 blocks on AVX-512 systems

Apr 7, 2026View details →

CVE-2026-27571

nats-server
7.5

Pre-authentication memory exhaustion via a WebSocket compression bomb

Feb 24, 2026View details →

CVE-2026-26932

Packetbeat
7.5

Improper array index validation in the PostgreSQL protocol parser causing a panic

Feb 26, 2026View details →

CVE-2026-26316

OpenClaw
7.5

Webhook authentication bypass in the BlueBubbles plugin via loopback address trust

Feb 19, 2026View details →

CVE-2026-25564

WeKan
7.5

Cross-board IDOR in checklist deletion via unverified cardId-to-board relationship

Feb 7, 2026View details →

CVE-2026-25563

WeKan
7.5

Cross-board IDOR in checklist creation via unverified cardId-to-board relationship

Feb 7, 2026View details →

CVE-2026-25561

WeKan
7.5

Missing object relationship validation in the attachment upload API

Feb 7, 2026View details →

CVE-2026-25556

MuPDF
7.5

Double free in fz_fill_pixmap_from_display_list() error handling during barcode decoding

Feb 6, 2026View details →

CVE-2026-25476

openemr
7.5

Session timeout bypass via the skip_timeout_reset parameter

Feb 25, 2026View details →

CVE-2026-25239

pearweb
7.5

SQL injection in apidoc queue insertion via an unescaped filename

Feb 3, 2026View details →

CVE-2026-25235

pearweb
7.5

Predictable verification hashes in election account requests

Feb 3, 2026View details →

CVE-2026-24138

FOG
7.5

Unauthenticated SSRF in getversion.php via the url parameter

Jan 23, 2026View details →

CVE-2026-22245

mastodon
7.5

SSRF protection bypass via address ranges missing from the local IP denylist

Jan 8, 2026View details →

CVE-2026-22045

traefik
7.5

Unauthenticated resource exhaustion via stalled ACME TLS-ALPN handshakes

Jan 15, 2026View details →

CVE-2026-18358

gnome-remote-desktop
7.5

Missing connection throttling in the system-mode RDP listener allows unauthenticated DoS

Jul 31, 2026View details →

CVE-2026-8932

curl
7.5

Connection reuse ignores changed client certificate and private key TLS options

Jul 16, 2026View details →

CVE-2026-6893

dracut
7.5

Command injection via crafted DHCP options allows root code execution in the initramfs

Jun 10, 2026View details →

CVE-2026-3336

AWS-LC
7.5

Certificate chain verification bypass in PKCS7_verify() with multiple signers

Mar 2, 2026View details →

CVE-2026-3312

Pagure
7.5

Local file exposure allows any user to read internal system files

Mar 17, 2026View details →

CVE-2026-2229

undici
7.5

Unhandled exception in the WebSocket client via an out-of-range server_max_window_bits

Mar 12, 2026View details →

CVE-2026-0915

glibc
7.5

Stack memory disclosure to the DNS resolver in getnetbyaddr and getnetbyaddr_r

Jan 15, 2026View details →

CVE-2026-0528

Metricbeat
7.5

Denial of service via malformed payloads in the Graphite, Zookeeper, and Prometheus metricsets

Jan 13, 2026View details →

CVE-2025-69421

OpenSSL
7.5

NULL pointer dereference in PKCS12_item_decrypt_d2i_ex() on malformed PKCS#12 files

Jan 27, 2026View details →

CVE-2025-69420

OpenSSL
7.5

Type confusion in TS_RESP_verify_response() causing a NULL pointer dereference

Jan 27, 2026View details →
CTA background

Meet the system that responds
faster than you can say CVE.