AISLE CVE Discoveries

CVEs our AI-native engine discovered in the world's most audited code, responsibly disclosed to maintainers.

381CVEs Assigned
186High/Critical Severity
105Projects Secured

CVE-2026-33918

openemr
8.8

Missing authorization on get_claim_file.php lets any user download and delete claim files

Mar 25, 2026View details →

CVE-2026-26323

OpenClaw
8.8

Command injection in the update-clawtributors maintainer script via commit author emails

Feb 19, 2026View details →

CVE-2026-25859

WeKan
8.8

Insufficient permission checks allow non-admin users to run migration operations

Feb 7, 2026View details →

CVE-2026-23627

openemr
8.8

SQL injection in the Immunization module via the patient_id parameter

Feb 25, 2026View details →

CVE-2026-6638

PostgreSQL
8.8

SQL injection in logical replication via crafted table names at REFRESH PUBLICATION

May 14, 2026View details →

CVE-2026-6473

PostgreSQL
8.8

Integer wraparound undersizes allocations, letting unprivileged users write out of bounds

May 14, 2026View details →

CVE-2026-5136

Foreman
8.8

Privilege escalation to administrator via unvalidated usergroup role assignments

Jul 16, 2026View details →

CVE-2026-2206

WeKan
8.8

Improper access control in the fixDuplicateLists admin repair method

Feb 8, 2026View details →

CVE-2025-66287

WebKitGTK
8.8

Memory corruption when processing crafted web content leading to a process crash

Dec 4, 2025View details →

CVE-2025-62525

openwrt
8.8

Arbitrary kernel memory read and write via ltq-ptm driver ioctls

Oct 22, 2025View details →

CVE-2025-15467

OpenSSL
8.8

Stack buffer overflow via an oversized AEAD IV in CMS (Auth)EnvelopedData parsing

Jan 27, 2026View details →

CVE-2025-10680

OpenVPN
8.8

Shell command injection by a malicious server via DNS variables with --dns-updown

Oct 24, 2025View details →

CVE-2026-75140

jsoup
8.7

Uncontrolled Resource Consumption in XmlTreeBuilder

Aug 20, 2026View details →

CVE-2026-67215

cJSON
8.7

Stack exhaustion via uncontrolled recursion when applying crafted JSON Patch documents

Jul 29, 2026View details →

CVE-2026-65052

Ninja Forms
8.7

Payment total tampering via fail-open get_calc_value() in ListSelect and ListRadio fields

Jul 22, 2026View details →

CVE-2026-64834

FFmpeg
8.7

Infinite loop in rtp_asf_fix_header() via an undersized ASF chunksize

Jul 23, 2026View details →

CVE-2026-33346

openemr
8.7

Stored XSS in the patient portal payment flow executing in staff browsers

Mar 19, 2026View details →

CVE-2026-3505

BC-JAVA
8.7

Unbounded PGP AEAD chunk size allows pre-authentication resource exhaustion

Apr 15, 2026View details →

CVE-2026-82463

pac4j
8.6

pac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type Check

Aug 29, 2026View details →

CVE-2026-82461

pac4j
8.6

pac4j-oidc before 6.5.6 Privilege Escalation via Unverified Keycloak Access Token

Aug 29, 2026View details →

CVE-2026-76207

phpMyFAQ
8.6

2FA Bypass via Remember-Me Cookie

Aug 21, 2026View details →

CVE-2026-10649

Pacemaker
8.6

Integer overflow in remote message decompression crashes the CIB remote listener

Jun 16, 2026View details →

CVE-2025-68473

esp-idf
8.6

Out-of-bounds write in bta_dm_sdp_result() when SDP discovery returns more than 32 services

Dec 26, 2025View details →

CVE-2026-75144

FFmpeg
8.5

FFmpeg Heap Buffer Overflow in VC-2/Dirac RTP Packetizer

Aug 20, 2026View details →

CVE-2026-75142

FFmpeg
8.5

FFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c

Aug 20, 2026View details →

CVE-2026-75141

FFmpeg
8.5

FFmpeg Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing

Aug 20, 2026View details →

CVE-2026-0861

glibc
8.4

Integer overflow in the memalign function family leading to heap corruption

Jan 14, 2026View details →

CVE-2026-67216

cJSON
8.2

Exponential runtime in cJSON_Compare() on deeply nested JSON, leading to denial of service

Jul 29, 2026View details →

CVE-2026-47688

FOG
8.2

Unauthenticated deletion of host AES keys and power schedules via clearAES and clearPMTasks

May 19, 2026View details →

CVE-2026-42013

GnuTLS
8.2

Certificate validation falls back to Common Name checks on an oversized SAN

May 26, 2026View details →

CVE-2026-5260

GnuTLS
8.2

Heap overread in RSA key exchange with a PKCS#11-backed key via a short premaster secret

May 26, 2026View details →

CVE-2025-11931

wolfSSL
8.2

Integer underflow leading to out-of-bounds access in wc_XChaCha20Poly1305_Decrypt()

Nov 21, 2025View details →

CVE-2026-76886

Wireshark
8.1

Heap-based Buffer Overflow in Wireshark

Aug 21, 2026View details →

CVE-2026-75146

FFmpeg
8.1

FFmpeg Out-of-Bounds Read in DASH Demuxer via dashdec.c

Aug 20, 2026View details →

CVE-2026-44169

MariaDB
8.1

Authorization bypass exposes stored routine definitions to role-granted EXECUTE users

Jun 12, 2026View details →

CVE-2026-42512

FreeBSD
8.1

Heap buffer overflow in dhclient's environment array resizing via a crafted packet

Apr 30, 2026View details →

CVE-2026-42511

FreeBSD
8.1

dhclient.conf directive injection via the BOOTP file field, leading to root code execution

Apr 30, 2026View details →

CVE-2026-34055

openemr
8.1

IDOR in the patient notes web UI allows modifying and deleting arbitrary notes

Mar 25, 2026View details →

CVE-2026-34053

openemr
8.1

Missing authorization lets any user delete procedure orders via handle_deletions.php

Mar 25, 2026View details →

CVE-2026-33302

openemr
8.1

Module ACL check in zhAclCheck() ignores explicit deny entries

Mar 19, 2026View details →

CVE-2026-32126

openemr
8.1

Inverted ACL check in the CDR ControllerRouter lets any user modify clinical rules

Mar 11, 2026View details →

CVE-2026-28472

OpenClaw
8.1

Unvalidated auth.token skips device identity checks in the gateway WebSocket handshake

Mar 5, 2026View details →

CVE-2026-28387

OpenSSL
8.1

Use-after-free in client-side DANE TLSA certificate checking

Apr 7, 2026View details →

CVE-2026-26247

Gitea
8.1

OAuth2 PKCE bypass via unpersisted S256 code_challenge_method during authorization

Jul 16, 2026View details →

CVE-2026-25941

FreeRDP
8.1

Out-of-bounds read in the RDPGFX channel via a crafted WIRE_TO_SURFACE_2 PDU

Feb 25, 2026View details →

CVE-2026-25164

openemr
8.1

Missing ACL checks on the document and insurance REST API routes

Feb 25, 2026View details →

CVE-2026-24890

openemr
8.1

Provider signature forgery via missing authorization in the portal signature endpoint

Feb 25, 2026View details →

CVE-2025-15382

wolfSSH
8.1

Heap buffer over-read in wolfSSH_CleanPath() via SCP paths containing '/./' sequences

Jan 6, 2026View details →
CTA background

Meet the system that responds
faster than you can say CVE.