AISLE CVE Discoveries
CVEs our AI-native engine discovered in the world's most audited code, responsibly disclosed to maintainers.
CVE-2026-24908
openemrSQL injection in the Patient REST API via the _sort parameter
CVE-2026-24898
openemrUnauthenticated MedEx API token disclosure via the callback endpoint
CVE-2025-10230
SambaUnauthenticated command injection via NetBIOS names in the WINS server hook script
CVE-2026-40472
hackage-serverStored XSS via package metadata rendered unescaped in href attributes
CVE-2026-44170
MariaDBArgument injection in the CONNECT engine's curl command line via the table HTTP attribute
CVE-2026-42010
GnuTLSAuthentication bypass via NUL character in RSA-PSK usernames
CVE-2026-29167
Apache HTTP ServerUse-after-free in mod_ldap with per-directory configuration
CVE-2026-28808
OTPAuthentication bypass for ScriptAlias CGI scripts via a mod_auth/mod_cgi path mismatch
CVE-2026-28474
nextcloud-talkAllowlist bypass via spoofed actor.name display names in the Nextcloud Talk plugin
CVE-2026-28470
OpenClawExec allowlist bypass via command substitution inside double-quoted strings
CVE-2026-28391
OpenClawCommand injection via cmd.exe metacharacters in allowlist-gated exec requests
CVE-2026-25560
WeKanLDAP filter injection via unescaped usernames during authentication
CVE-2026-25241
pearwebUnauthenticated SQL injection in the /get/<package>/<version> endpoint
CVE-2026-25240
pearwebSQL injection in user::maintains() via role filters interpolated into an IN() clause
CVE-2026-25238
pearwebSQL injection in bug subscription deletion via a crafted email value
CVE-2026-25237
pearwebPHP code execution via preg_replace /e in bug update email handling
CVE-2026-25236
pearwebSQL injection in Damblan_Karma via unsafe literal substitution in an IN() list
CVE-2026-25234
pearwebSQL injection in category deletion via the category id
CVE-2026-10536
curlUse-after-free in HTTP/2 stream-dependency handling after curl_easy_reset()
CVE-2026-8925
curlDouble free of the GSASL context during SASL authentication cleanup
CVE-2026-2757
FirefoxIncorrect boundary conditions in the WebRTC audio/video component
CVE-2026-1963
WeKanImproper access control in the attachment storage move operation
CVE-2026-1962
WeKanImproper access control in the attachment migration routine
CVE-2025-14321
FirefoxUse-after-free in the WebRTC signaling component
CVE-2025-11624
wolfSSHStack buffer overwrite when processing oversized file handles in the SFTP server
CVE-2026-40471
hackage-serverMissing CSRF protection allows cross-site package uploads and admin actions
CVE-2026-28446
OpenClawInbound allowlist bypass in the voice-call extension via empty or suffix-matched caller IDs
CVE-2026-23941
OTPRequest smuggling via first-wins Content-Length parsing in inets httpd
CVE-2026-65049
Ninja FormsSite-scoped capability check in nf_delete_all_data enables network-wide data deletion
CVE-2026-65048
Ninja FormsUnauthenticated stored XSS via crafted Repeatable Fieldset submission indexes
CVE-2026-33845
GnuTLSOut-of-bounds read via integer underflow when reassembling zero-length DTLS fragments
CVE-2026-25233
pearwebRoadmap authorization bypass via an operator precedence bug in the role check
CVE-2026-8926
curlPassword for another .netrc user sent when the URL specifies only a username
CVE-2026-32118
openemrStored XSS in the Graphical Pain Map (clickmap) encounter form
CVE-2026-64835
FFmpegOut-of-bounds read and write in the ADX audio decoder via a mid-stream channel layout change
CVE-2026-64832
FFmpegDouble free in the NVDEC hardware decoder when no decoder surfaces remain
CVE-2026-64831
FFmpegStack buffer overflow in the Vulkan HEVC decoder via oversized vps_num_hrd_parameters
CVE-2026-64830
FFmpegHeap buffer overflow in the VobSub subtitle demuxer via excessive distinct stream IDs
CVE-2026-59851
libsshMissing Kerberos principal check in the gssapi-keyex path allows login as arbitrary users
CVE-2026-39461
FreeBSDStack buffer overflow in libcasper via file descriptors exceeding FD_SETSIZE in select()
CVE-2026-33918
openemrMissing authorization on get_claim_file.php lets any user download and delete claim files
CVE-2026-26323
OpenClawCommand injection in the update-clawtributors maintainer script via commit author emails
CVE-2026-25859
WeKanInsufficient permission checks allow non-admin users to run migration operations
CVE-2026-23627
openemrSQL injection in the Immunization module via the patient_id parameter
CVE-2026-6638
PostgreSQLSQL injection in logical replication via crafted table names at REFRESH PUBLICATION
CVE-2026-6473
PostgreSQLInteger wraparound undersizes allocations, letting unprivileged users write out of bounds
CVE-2026-5136
ForemanPrivilege escalation to administrator via unvalidated usergroup role assignments
CVE-2026-2206
WeKanImproper access control in the fixDuplicateLists admin repair method
