AISLE CVE Discoveries

CVEs our AI-native engine discovered in the world's most audited code, responsibly disclosed to maintainers.

350CVEs Assigned
175High/Critical Severity
99Projects Secured

CVE-2025-64756

node-glob
7.5

Command injection via shell metacharacters in filenames with the CLI -c/--cmd option

Nov 17, 2025View details →

CVE-2025-59464

node
7.5

Memory leak converting X.509 certificate fields in socket.getPeerCertificate(true)

Jan 20, 2026View details →

CVE-2025-55753

Apache HTTP Server
7.5

Integer overflow in the mod_md ACME renewal backoff leading to delay-free retries

Dec 5, 2025View details →

CVE-2025-13502

WebKitGTK
7.5

Out-of-bounds read and integer underflow in the GLib remote inspector server

Nov 25, 2025View details →

CVE-2025-13016

Firefox
7.5

Incorrect boundary conditions in the JavaScript WebAssembly component

Nov 11, 2025View details →

CVE-2025-9230

OpenSSL
7.5

Out-of-bounds read and write in RFC 3211 KEK unwrap when decrypting CMS messages

Sep 30, 2025View details →

CVE-2026-32144

OTP
7.4

OCSP designated-responder authorization bypass via missing signature verification

Apr 7, 2026View details →

CVE-2026-9547

curl
7.4

Known-host key type mismatch silently accepted via the CURLOPT_SSH_KEYFUNCTION callback

Jul 16, 2026View details →

CVE-2026-3833

GnuTLS
7.4

Name constraints bypass via case-sensitive dNSName and rfc822Name comparison

Apr 30, 2026View details →

CVE-2025-69419

OpenSSL
7.4

Out-of-bounds write in PKCS12_get_friendlyname() UTF-8 conversion

Jan 27, 2026View details →

CVE-2026-71226

libkcapi
7.3

Memory corruption from uncanceled AIO requests in the one-shot AIO error path

Aug 5, 2026View details →

CVE-2026-47687

FOG
7.3

Stored XSS in the Inventory Report via unescaped option labels in selectForm()

May 19, 2026View details →

CVE-2026-47685

FOG
7.3

Stored XSS in the Host Management page via the unauthenticated inventory endpoint

May 19, 2026View details →

CVE-2026-29168

Apache HTTP Server
7.3

Unbounded resource allocation in mod_md when processing OCSP response data

May 5, 2026View details →

CVE-2026-28448

OpenClaw
7.3

allowFrom allowlist bypass in the Twitch plugin when allowedRoles is empty

Mar 5, 2026View details →

CVE-2026-9080

curl
7.3

Use-after-free when curl_easy_pause() is called from the socket callback

Jul 16, 2026View details →

CVE-2026-75147

FFmpeg
7.1

FFmpeg Out-of-Bounds Read in AV1 RTP Packetizer via rtpenc_av1.c

Aug 20, 2026View details →

CVE-2026-72694

mrtg
7.1

Symlink-following chown allows local privilege escalation via pid file path manipulation

Aug 11, 2026View details →

CVE-2026-67419

RabbitMQ
7.1

Consecutive topic wildcards cause combinatorial routing work

Aug 18, 2026View details →

CVE-2026-65050

Ninja Forms
7.1

Missing authorization in the submissions-table block exposes form submissions to visitors

Jul 22, 2026View details →

CVE-2026-64833

FFmpeg
7.1

Out-of-bounds read in the S/PDIF muxer via an oversized DTS core_size value

Jul 23, 2026View details →

CVE-2026-48613

phpBB
7.1

SQL injection during profile field migration via user-supplied profile field data

Jun 12, 2026View details →

CVE-2026-25927

openemr
7.1

IDOR in the DICOM viewer state API allows reading or modifying any document's state

Feb 25, 2026View details →

CVE-2026-25147

openemr
7.1

IDOR in the portal payment page via a user-supplied pid parameter

Feb 27, 2026View details →

CVE-2026-24902

TrustTunnel
7.1

SSRF and private network restriction bypass via numeric IP destinations

Jan 29, 2026View details →

CVE-2026-22695

libpng
7.1

Heap buffer over-read in png_image_finish_read when reading interlaced 16-bit PNGs

Jan 12, 2026View details →

CVE-2026-9808

mautic/core
7.1

Owner-scope role restrictions not enforced on API v2 endpoints, exposing other users' data

May 29, 2026View details →

CVE-2025-39840

Linux
7.1

Out-of-bounds read in audit_compare_dname_path() when watching the root directory

Sep 19, 2025View details →

CVE-2025-39839

Linux
7.1

Out-of-bounds read and write in batman-adv network-coding decode

Sep 19, 2025View details →

CVE-2026-56109

alsa-lib
7.0

Double free in parse_def() when parsing nested compound configuration blocks

Jun 22, 2026View details →

CVE-2026-44604

rpm
7.0

Command injection in rpmuncompress via an archive's top-level directory name

May 28, 2026View details →

CVE-2026-67217

cJSON
6.9

Non-atomic JSON Patch application destroys target document members on failed operations

Jul 29, 2026View details →

CVE-2026-65051

Ninja Forms
6.9

Validation bypass via client-controlled field metadata in the AJAX submission handler

Jul 22, 2026View details →

CVE-2025-65092

esp-idf
6.9

Out-of-bounds read when parsing JPEG headers for the ESP32-P4 hardware decoder

Nov 21, 2025View details →

CVE-2026-28450

OpenClaw
6.8

Missing authentication on the Nostr plugin's profile HTTP endpoints

Mar 5, 2026View details →

CVE-2026-23893

opencryptoki
6.8

Symlink following in group-writable token directories leading to privilege escalation

Jan 22, 2026View details →

CVE-2025-41117

grafana/grafana
6.8

XSS via stack traces rendered as raw HTML in the Explore Traces view

Feb 12, 2026View details →

CVE-2026-73583

sblim-sfcb
6.6

Unsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds memory access via malformed operationhdr

Aug 13, 2026View details →

CVE-2026-22791

opencryptoki
6.6

Heap buffer overflow in C_WrapKey with CKM_ECDH_AES_KEY_WRAP via compressed EC keys

Jan 13, 2026View details →

CVE-2026-19696

Wireshark
6.6

Out-of-bounds write in BLF file parsing

Aug 13, 2026View details →

CVE-2026-73199

freeipa
6.5

Null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) via missing request value

Aug 21, 2026View details →

CVE-2026-71225

libkcapi
6.5

IV reuse across chunks in one-shot symmetric cipher operations on large inputs

Aug 5, 2026View details →

CVE-2026-70368

stunnel
6.5

Stack out-of-bounds read in s_vlog() when handling oversized log messages

Aug 4, 2026View details →

CVE-2026-55894

Capstone
6.5

Out-of-bounds read in sh_disassemble when disassembling crafted SH2A bytecode

Jun 16, 2026View details →

CVE-2026-55893

Capstone
6.5

Heap buffer overflow in set_reg_n when disassembling crafted SH2A FPU bytecode

Jun 15, 2026View details →

CVE-2026-53583

libgit2
6.5

Inverted IP SubjectAltName comparison in the OpenSSL backend skips authenticity checks

Jul 16, 2026View details →

CVE-2026-48744

saleor/saleor
6.5

Permission check bypass in channelUpdate via all([]) lets anonymous users modify channels

Jul 27, 2026View details →

CVE-2026-47729

squid
6.5

Out-of-bounds read parsing FTP directory listings leaks memory from other transactions

Jul 16, 2026View details →
CTA background

Meet the system that responds
faster than you can say CVE.