AISLE CVE Discoveries
CVEs our AI-native engine discovered in the world's most audited code, responsibly disclosed to maintainers.
CVE-2026-25532
esp-idfInteger underflow in WPS Enrollee fragment length handling via truncated EAP-WSC packets
CVE-2026-84838
rpmCommand injection in rpmuncompress via unescaped filenames passed to popen()
CVE-2026-84837
rpmCommand injection in rpmbuild via unescaped tarball path
CVE-2026-72693
openvtLocal privilege escalation in openvt via incorrect process owner verification allowing passwordless root login
CVE-2026-48864
libsolvHeap buffer overflow when decompressing page data from crafted .solv files
CVE-2026-43958
rrdtoolStack buffer overflow in rrdcached via an oversized CREATE request
CVE-2026-39457
FreeBSDStack buffer overflow in libnv via file descriptors exceeding FD_SETSIZE in select()
CVE-2026-32647
NGINX Open SourceBuffer over-read and over-write in ngx_http_mp4_module when processing crafted MP4 files
CVE-2026-18157
yggdrasil-worker-package-managerArgument injection in the APT backend via crafted package names leading to root code execution
CVE-2026-10118
PopplerInteger overflow in SplashOutputDev::tilingPatternFill leading to heap buffer overflow
CVE-2025-59534
CryptoLibCommand injection in initialize_kerberos_keytab_file_login()
CVE-2026-46518
openemrStored XSS in the prescription multi-print view via patient demographic fields
CVE-2026-32123
openemrBroken sensitivity check lets restricted users view sensitive group encounters
CVE-2026-32121
openemrStored DOM XSS in the portal signer modal via unsanitized patient names
CVE-2026-33932
openemrStored XSS in the CCDA document preview via unsanitized linkHtml attributes
CVE-2025-68474
esp-idfOut-of-bounds write in avrc_vendor_msg() when handling AVRCP vendor commands
CVE-2026-76928
WiresharkNULL Pointer Dereference in Wireshark
CVE-2026-76880
WiresharkOut-of-bounds Write in Wireshark
CVE-2026-76879
WiresharkStack-based Buffer Overflow in Wireshark
CVE-2026-73198
freeipaUnauthenticated DoS in via unbounded request body read
CVE-2026-73197
freeipaUnauthenticated DoS in `/ipa/migration/migration.py` via unbounded request body read
CVE-2026-71217
Iperf3Unbounded peer-controlled json parameters enables remote denial of service via resource exhaustion
CVE-2026-54554
FOGUnauthenticated disclosure of the Active Directory default join password via adInfo()
CVE-2026-53460
ImageMagickUnbounded memory request in AcquireAlignedMemory leading to out-of-memory condition
CVE-2026-49218
ImageMagickMissing check in the DCM decoder allows images with invalid dimensions, causing crashes
CVE-2026-48863
libsolvStack buffer overflow verifying EdDSA PGP signatures with mismatched MPI lengths
CVE-2026-42765
OpenSSLNULL pointer dereference during OCSP chain checking with partial-chain verification
CVE-2026-42009
GnuTLSDenial of service via duplicate sequence numbers in DTLS packet reordering
CVE-2026-29169
GnuTLSNULL pointer dereference in mod_dav_lock via a malicious request
CVE-2026-28454
OpenClawUnvalidated Telegram webhook secret allows forged updates that bypass sender allowlists
CVE-2026-28390
OpenSSLNULL pointer dereference when processing CMS KeyTransportRecipientInfo
CVE-2026-28389
OpenSSLNULL pointer dereference when processing CMS KeyAgreeRecipientInfo
CVE-2026-28388
OpenSSLNULL pointer dereference when processing a delta CRL missing the CRL Number extension
CVE-2026-28386
OpenSSLOut-of-bounds read when processing partial AES-CFB128 blocks on AVX-512 systems
CVE-2026-27571
nats-serverPre-authentication memory exhaustion via a WebSocket compression bomb
CVE-2026-26932
PacketbeatImproper array index validation in the PostgreSQL protocol parser causing a panic
CVE-2026-26316
OpenClawWebhook authentication bypass in the BlueBubbles plugin via loopback address trust
CVE-2026-25564
WeKanCross-board IDOR in checklist deletion via unverified cardId-to-board relationship
CVE-2026-25563
WeKanCross-board IDOR in checklist creation via unverified cardId-to-board relationship
CVE-2026-25561
WeKanMissing object relationship validation in the attachment upload API
CVE-2026-25556
MuPDFDouble free in fz_fill_pixmap_from_display_list() error handling during barcode decoding
CVE-2026-25476
openemrSession timeout bypass via the skip_timeout_reset parameter
CVE-2026-25239
pearwebSQL injection in apidoc queue insertion via an unescaped filename
CVE-2026-25235
pearwebPredictable verification hashes in election account requests
CVE-2026-24138
FOGUnauthenticated SSRF in getversion.php via the url parameter
CVE-2026-22245
mastodonSSRF protection bypass via address ranges missing from the local IP denylist
CVE-2026-22045
traefikUnauthenticated resource exhaustion via stalled ACME TLS-ALPN handshakes
CVE-2026-18358
gnome-remote-desktopMissing connection throttling in the system-mode RDP listener allows unauthenticated DoS

