These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,135 reserved CVEs with public mentions, ranked by all-time mention count.
Page 21 of 46
FreeBSD System V semaphore handling contains a flaw in semop(2) when a caller blocks awaiting a semaphore condition. The operation releases the semaphore-set lock while sleeping and validates the semaphore set after waking by checking a 15-bit sequence number in its IPC identifier. An attacker can repeatedly create and destroy semaphore sets in the same table slot until the sequence counter wraps. semop(2) may then mistake a replacement set for the original removed set and access a semaphore outside the bounds of the set.
CVE-2026-58098First seen Sep 29, 2026
CVE-2026-101306 is a filesystem-isolation bypass in FreeBSD jails involving SCM_RIGHTS file-descriptor passing. FD_RESOLVE_BENEATH restrictions are not preserved when a directory file descriptor is transferred over a Unix domain socket. A process can send such a descriptor to itself and clear the restriction, enabling a jailed process holding a directory descriptor received from another jail to bypass the jail filesystem root.
CVE-2026-101306First seen Sep 29, 2026
FreeBSD's kqueue copy-on-fork implementation contains two memory-safety race conditions. One condition is a use-after-free involving internal marker knotes. The other occurs when kqueue_fork_copy_knote() uses a knote file-descriptor number to index the child process's file-descriptor table without validating that the index is within bounds. A concurrent parent thread can register knotes beyond the end of the child's table, resulting in an out-of-bounds read.
CVE-2026-58100First seen Sep 29, 2026
First seen Sep 29, 2026
First seen Sep 29, 2026
First seen Sep 29, 2026
First seen Sep 28, 2026
First seen Sep 28, 2026
First seen Sep 27, 2026
First seen Sep 27, 2026
First seen Sep 27, 2026
First seen Sep 27, 2026
First seen Sep 27, 2026
CVE-2025-65852 is a broken access-control vulnerability in Gogs's repository-deletion API. The affected operation verifies that a caller has repository read access but does not additionally enforce repository-owner or administrator authorization before deleting the repository.
CVE-2025-65852First seen Jun 12, 2026
CVE-2016-1000231 is a cross-site scripting vulnerability in versions of the npm emojione package before 1.3.1. The package's toShort(), shortnameToImage(), unicodeToImage(), and toImage() conversion functions can process attacker-controlled input in a manner that permits injection of executable HTML or JavaScript when the resulting output is rendered by a web application.
CVE-2016-1000231First seen Jun 12, 2026
CVE-2025-23390 is an improper certificate/host-key validation vulnerability in Rancher Fleet. By default, Fleet does not validate the identity of a remote SSH server when connecting to a server that has no corresponding entry in its known_hosts configuration. This permits an adversary positioned to intercept the SSH connection to impersonate a Git or other remote SSH service.
CVE-2025-23390First seen Jun 4, 2026
CVE-2024-38393 is a privilege-escalation vulnerability in Foxit PDF Reader and Editor for Windows and macOS. The issue can be exposed while the application performs an update or installs a plugin, permitting an attacker to delete arbitrary files or execute arbitrary code and thereby escalate privileges.
CVE-2024-38393First seen Sep 26, 2026
The npm swagger-ui package through version 2.2.0 contains a cross-site scripting vulnerability in its rendering of Swagger definition data. Crafted values in the consumes or produces fields of a Swagger JSON document can inject script into the Swagger UI page. The query-string mechanism for selecting a Swagger definition permits a crafted link to cause Swagger UI to load an attacker-controlled definition.
CVE-2016-1000226First seen Jun 12, 2026
CVE-2024-45110 is an out-of-bounds read vulnerability in Adobe Photoshop. Processing attacker-controlled content can cause Photoshop to read memory outside an intended buffer boundary. Adobe classified exploitation as potentially allowing arbitrary code execution in the context of the current user.
CVE-2024-45110First seen Sep 26, 2026
CVE-2013-3364 is an unauthenticated remote command-injection vulnerability in the ep_imageconvert plugin for Etherpad Lite. Insufficient handling of attacker-controlled input passed to operating-system command execution permits injection of arbitrary commands on the host running the Etherpad service.
CVE-2013-3364First seen Jun 12, 2026
Affected versions of the npm node-krb5 package fail to validate the identity and authenticity of the Kerberos Key Distribution Center (KDC) during authentication. This permits a malicious network-controlled KDC to impersonate the legitimate KDC and conduct a KDC spoofing attack.
CVE-2016-1000238First seen Jun 12, 2026
First seen Sep 26, 2026
pfSense WebGUI contains an authorization logic error in xmlrpc.php when LDAP or RADIUS is configured for remote authentication. A valid remote-authentication user that has no corresponding local pfSense account can invoke XML-RPC methods without possessing the required system-xmlrpc-ha-sync privilege. The accessible exec_php method permits arbitrary PHP execution, which can be used to execute shell commands on the pfSense appliance.
CVE-2026-92182First seen Sep 26, 2026
CVE-2026-40652First seen Sep 25, 2026
CVE-2026-40660First seen Sep 25, 2026