AISLE CVE Discoveries

CVEs our AI-native engine discovered in the world's most audited code, responsibly disclosed to maintainers.

381CVEs Assigned
186High/Critical Severity
105Projects Secured

CVE-2026-25532

esp-idf
8.0

Integer underflow in WPS Enrollee fragment length handling via truncated EAP-WSC packets

Feb 4, 2026View details →

CVE-2026-84838

rpm
7.8

Command injection in rpmuncompress via unescaped filenames passed to popen()

Sep 4, 2026View details →

CVE-2026-84837

rpm
7.8

Command injection in rpmbuild via unescaped tarball path

Sep 4, 2026View details →

CVE-2026-72693

openvt
7.8

Local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login

Aug 11, 2026View details →

CVE-2026-48864

libsolv
7.8

Heap buffer overflow when decompressing page data from crafted .solv files

May 26, 2026View details →

CVE-2026-43958

rrdtool
7.8

Stack buffer overflow in rrdcached via an oversized CREATE request

Jun 1, 2026View details →

CVE-2026-39457

FreeBSD
7.8

Stack buffer overflow in libnv via file descriptors exceeding FD_SETSIZE in select()

Apr 30, 2026View details →

CVE-2026-32647

NGINX Open Source
7.8

Buffer over-read and over-write in ngx_http_mp4_module when processing crafted MP4 files

Mar 24, 2026View details →

CVE-2026-18157

yggdrasil-worker-package-manager
7.8

Argument injection in the APT backend via crafted package names leading to root code execution

Jul 31, 2026View details →

CVE-2026-10118

Poppler
7.8

Integer overflow in SplashOutputDev::tilingPatternFill leading to heap buffer overflow

Jun 1, 2026View details →

CVE-2025-59534

CryptoLib
7.8

Command injection in initialize_kerberos_keytab_file_login()

Sep 23, 2025View details →

CVE-2026-46518

openemr
7.7

Stored XSS in the prescription multi-print view via patient demographic fields

Jun 9, 2026View details →

CVE-2026-32123

openemr
7.7

Broken sensitivity check lets restricted users view sensitive group encounters

Mar 11, 2026View details →

CVE-2026-32121

openemr
7.7

Stored DOM XSS in the portal signer modal via unsanitized patient names

Mar 11, 2026View details →

CVE-2026-33932

openemr
7.6

Stored XSS in the CCDA document preview via unsanitized linkHtml attributes

Mar 25, 2026View details →

CVE-2025-68474

esp-idf
7.6

Out-of-bounds write in avrc_vendor_msg() when handling AVRCP vendor commands

Dec 26, 2025View details →

CVE-2026-76928

Wireshark
7.5

NULL Pointer Dereference in Wireshark

Aug 21, 2026View details →

CVE-2026-76880

Wireshark
7.5

Out-of-bounds Write in Wireshark

Aug 21, 2026View details →

CVE-2026-76879

Wireshark
7.5

Stack-based Buffer Overflow in Wireshark

Aug 21, 2026View details →

CVE-2026-73198

freeipa
7.5

Unauthenticated DoS in via unbounded request body read

Aug 21, 2026View details →

CVE-2026-73197

freeipa
7.5

Unauthenticated DoS in `/ipa/migration/migration.py` via unbounded request body read

Aug 21, 2026View details →

CVE-2026-71217

Iperf3
7.5

Unbounded peer-controlled json parameters enables remote denial of service via resource exhaustion

Aug 11, 2026View details →

CVE-2026-54554

FOG
7.5

Unauthenticated disclosure of the Active Directory default join password via adInfo()

Jun 14, 2026View details →

CVE-2026-53460

ImageMagick
7.5

Unbounded memory request in AcquireAlignedMemory leading to out-of-memory condition

Jun 10, 2026View details →

CVE-2026-49218

ImageMagick
7.5

Missing check in the DCM decoder allows images with invalid dimensions, causing crashes

Jun 10, 2026View details →

CVE-2026-48863

libsolv
7.5

Stack buffer overflow verifying EdDSA PGP signatures with mismatched MPI lengths

Jul 24, 2026View details →

CVE-2026-42765

OpenSSL
7.5

NULL pointer dereference during OCSP chain checking with partial-chain verification

Jun 9, 2026View details →

CVE-2026-42009

GnuTLS
7.5

Denial of service via duplicate sequence numbers in DTLS packet reordering

May 18, 2026View details →

CVE-2026-29169

GnuTLS
7.5

NULL pointer dereference in mod_dav_lock via a malicious request

May 4, 2026View details →

CVE-2026-28454

OpenClaw
7.5

Unvalidated Telegram webhook secret allows forged updates that bypass sender allowlists

Mar 5, 2026View details →

CVE-2026-28390

OpenSSL
7.5

NULL pointer dereference when processing CMS KeyTransportRecipientInfo

Apr 7, 2026View details →

CVE-2026-28389

OpenSSL
7.5

NULL pointer dereference when processing CMS KeyAgreeRecipientInfo

Apr 7, 2026View details →

CVE-2026-28388

OpenSSL
7.5

NULL pointer dereference when processing a delta CRL missing the CRL Number extension

Apr 7, 2026View details →

CVE-2026-28386

OpenSSL
7.5

Out-of-bounds read when processing partial AES-CFB128 blocks on AVX-512 systems

Apr 7, 2026View details →

CVE-2026-27571

nats-server
7.5

Pre-authentication memory exhaustion via a WebSocket compression bomb

Feb 24, 2026View details →

CVE-2026-26932

Packetbeat
7.5

Improper array index validation in the PostgreSQL protocol parser causing a panic

Feb 26, 2026View details →

CVE-2026-26316

OpenClaw
7.5

Webhook authentication bypass in the BlueBubbles plugin via loopback address trust

Feb 19, 2026View details →

CVE-2026-25564

WeKan
7.5

Cross-board IDOR in checklist deletion via unverified cardId-to-board relationship

Feb 7, 2026View details →

CVE-2026-25563

WeKan
7.5

Cross-board IDOR in checklist creation via unverified cardId-to-board relationship

Feb 7, 2026View details →

CVE-2026-25561

WeKan
7.5

Missing object relationship validation in the attachment upload API

Feb 7, 2026View details →

CVE-2026-25556

MuPDF
7.5

Double free in fz_fill_pixmap_from_display_list() error handling during barcode decoding

Feb 6, 2026View details →

CVE-2026-25476

openemr
7.5

Session timeout bypass via the skip_timeout_reset parameter

Feb 25, 2026View details →

CVE-2026-25239

pearweb
7.5

SQL injection in apidoc queue insertion via an unescaped filename

Feb 3, 2026View details →

CVE-2026-25235

pearweb
7.5

Predictable verification hashes in election account requests

Feb 3, 2026View details →

CVE-2026-24138

FOG
7.5

Unauthenticated SSRF in getversion.php via the url parameter

Jan 23, 2026View details →

CVE-2026-22245

mastodon
7.5

SSRF protection bypass via address ranges missing from the local IP denylist

Jan 8, 2026View details →

CVE-2026-22045

traefik
7.5

Unauthenticated resource exhaustion via stalled ACME TLS-ALPN handshakes

Jan 15, 2026View details →

CVE-2026-18358

gnome-remote-desktop
7.5

Missing connection throttling in the system-mode RDP listener allows unauthenticated DoS

Jul 31, 2026View details →
CTA background

Meet the system that responds
faster than you can say CVE.