AISLE CVE Discoveries
CVEs our AI-native engine discovered in the world's most audited code, responsibly disclosed to maintainers.
CVE-2026-33918
openemrMissing authorization on get_claim_file.php lets any user download and delete claim files
CVE-2026-26323
OpenClawCommand injection in the update-clawtributors maintainer script via commit author emails
CVE-2026-25859
WeKanInsufficient permission checks allow non-admin users to run migration operations
CVE-2026-23627
openemrSQL injection in the Immunization module via the patient_id parameter
CVE-2026-6638
PostgreSQLSQL injection in logical replication via crafted table names at REFRESH PUBLICATION
CVE-2026-6473
PostgreSQLInteger wraparound undersizes allocations, letting unprivileged users write out of bounds
CVE-2026-5136
ForemanPrivilege escalation to administrator via unvalidated usergroup role assignments
CVE-2026-2206
WeKanImproper access control in the fixDuplicateLists admin repair method
CVE-2025-66287
WebKitGTKMemory corruption when processing crafted web content leading to a process crash
CVE-2025-62525
openwrtArbitrary kernel memory read and write via ltq-ptm driver ioctls
CVE-2025-15467
OpenSSLStack buffer overflow via an oversized AEAD IV in CMS (Auth)EnvelopedData parsing
CVE-2025-10680
OpenVPNShell command injection by a malicious server via DNS variables with --dns-updown
CVE-2026-75140
jsoupUncontrolled Resource Consumption in XmlTreeBuilder
CVE-2026-67215
cJSONStack exhaustion via uncontrolled recursion when applying crafted JSON Patch documents
CVE-2026-65052
Ninja FormsPayment total tampering via fail-open get_calc_value() in ListSelect and ListRadio fields
CVE-2026-64834
FFmpegInfinite loop in rtp_asf_fix_header() via an undersized ASF chunksize
CVE-2026-33346
openemrStored XSS in the patient portal payment flow executing in staff browsers
CVE-2026-3505
BC-JAVAUnbounded PGP AEAD chunk size allows pre-authentication resource exhaustion
CVE-2026-82463
pac4jpac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type Check
CVE-2026-82461
pac4jpac4j-oidc before 6.5.6 Privilege Escalation via Unverified Keycloak Access Token
CVE-2026-76207
phpMyFAQ2FA Bypass via Remember-Me Cookie
CVE-2026-10649
PacemakerInteger overflow in remote message decompression crashes the CIB remote listener
CVE-2025-68473
esp-idfOut-of-bounds write in bta_dm_sdp_result() when SDP discovery returns more than 32 services
CVE-2026-75144
FFmpegFFmpeg Heap Buffer Overflow in VC-2/Dirac RTP Packetizer
CVE-2026-75142
FFmpegFFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c
CVE-2026-75141
FFmpegFFmpeg Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing
CVE-2026-0861
glibcInteger overflow in the memalign function family leading to heap corruption
CVE-2026-67216
cJSONExponential runtime in cJSON_Compare() on deeply nested JSON, leading to denial of service
CVE-2026-47688
FOGUnauthenticated deletion of host AES keys and power schedules via clearAES and clearPMTasks
CVE-2026-42013
GnuTLSCertificate validation falls back to Common Name checks on an oversized SAN
CVE-2026-5260
GnuTLSHeap overread in RSA key exchange with a PKCS#11-backed key via a short premaster secret
CVE-2025-11931
wolfSSLInteger underflow leading to out-of-bounds access in wc_XChaCha20Poly1305_Decrypt()
CVE-2026-76886
WiresharkHeap-based Buffer Overflow in Wireshark
CVE-2026-75146
FFmpegFFmpeg Out-of-Bounds Read in DASH Demuxer via dashdec.c
CVE-2026-44169
MariaDBAuthorization bypass exposes stored routine definitions to role-granted EXECUTE users
CVE-2026-42512
FreeBSDHeap buffer overflow in dhclient's environment array resizing via a crafted packet
CVE-2026-42511
FreeBSDdhclient.conf directive injection via the BOOTP file field, leading to root code execution
CVE-2026-34055
openemrIDOR in the patient notes web UI allows modifying and deleting arbitrary notes
CVE-2026-34053
openemrMissing authorization lets any user delete procedure orders via handle_deletions.php
CVE-2026-33302
openemrModule ACL check in zhAclCheck() ignores explicit deny entries
CVE-2026-32126
openemrInverted ACL check in the CDR ControllerRouter lets any user modify clinical rules
CVE-2026-28472
OpenClawUnvalidated auth.token skips device identity checks in the gateway WebSocket handshake
CVE-2026-28387
OpenSSLUse-after-free in client-side DANE TLSA certificate checking
CVE-2026-26247
GiteaOAuth2 PKCE bypass via unpersisted S256 code_challenge_method during authorization
CVE-2026-25941
FreeRDPOut-of-bounds read in the RDPGFX channel via a crafted WIRE_TO_SURFACE_2 PDU
CVE-2026-25164
openemrMissing ACL checks on the document and insurance REST API routes
CVE-2026-24890
openemrProvider signature forgery via missing authorization in the portal signature endpoint
CVE-2025-15382
wolfSSHHeap buffer over-read in wolfSSH_CleanPath() via SCP paths containing '/./' sequences

