These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,131 reserved CVEs with public mentions, ranked by all-time mention count.
Page 31 of 46
CVE-2015-8518 is a missing authorization check vulnerability in SAP Adaptive Server Enterprise (ASE). The flaw allows an authenticated user who has the CREATE PROCEDURE privilege to invoke restricted system extended stored procedures that should not normally be accessible to that user. Reported abuse includes redefining xp_cmdshell, which can be used to reach privileged functionality otherwise protected by normal security controls. The issue stems from improper enforcement of authorization on invocation of system stored procedures from user-created procedures.
CVE-2015-8518First seen Aug 20, 2026
CVE-2014-6282 is a pre-authentication SQL injection vulnerability in Gerber WebPDM 5.0.58. The flaw affects the ACCOUNT parameter processed by the VerifyLogin.asp page, where unsanitized user-supplied input is incorporated into backend SQL queries. An attacker can submit crafted input to alter query logic and interact with the underlying database without first authenticating to the application.
CVE-2014-6282First seen Aug 20, 2026
CVE-2014-6286 is a SQL injection vulnerability in the dbcc createws command of SAP Adaptive Server Enterprise (ASE). The implementation flow of this command allows a user with CREATE DATABASE privilege to inject SQL statements that are subsequently executed without normal security checks. Because the injected SQL runs in a privileged context, the flaw can be used to bypass intended authorization boundaries and elevate privileges within the database server.
CVE-2014-6286First seen Aug 20, 2026
CVE-2015-3311 is an insecure library loading vulnerability in SAP Adaptive Server Enterprise when the Java subsystem is enabled. The issue arises from the product allowing native libraries to be loaded in an unsafe manner. A valid database user can abuse this behavior to cause attacker-controlled native code to be loaded and executed within the database server process context. Because the vulnerable code executes inside the ASE server process, exploitation can cross the boundary from database-level access into operating-system-level code execution within the privileges of the database service account.
CVE-2015-3311First seen Aug 20, 2026
CVE-2013-2775 is a reflected cross-site scripting vulnerability in the ColdBox debug panel affecting versions prior to 3.6.0. The flaw allows untrusted input to be reflected in a web response without proper sanitization or output encoding, enabling execution of attacker-supplied JavaScript in a victim's browser when a crafted request is processed by the debug panel.
CVE-2013-2775First seen Aug 20, 2026
CVE-2014-6281 is a reflected cross-site scripting vulnerability in Gerber WebPDM Product Data Management 5.0.58. The flaw affects the main login form, where input supplied through the txtUserName parameter is reflected to the client without sufficient sanitization or output encoding. An attacker can craft a malicious request that causes script content to execute in a victim user's browser when the crafted link or request is processed. The issue is present in the application's login workflow and can be triggered without prior authentication.
CVE-2014-6281First seen Aug 20, 2026
CVE-2016-5088 is an information disclosure vulnerability in SAP Adaptive Server Enterprise (ASE) affecting ASE 16.0 SP02 PL02 and earlier. During installation, the installer logs the SCC repository password in cleartext to an installation properties file under the SYBASE home directory. Because this file is publicly readable, an unprivileged local user can recover the stored SCC repository credential and use it to access the SCC repository.
CVE-2016-5088First seen Aug 20, 2026
CVE-2017-18181 is an arbitrary file deletion vulnerability in the nas_sharing.cgi CGI component of Western Digital My Cloud personal cloud storage devices prior to firmware version 2.30.172. The vulnerable CGI binary accepts a path parameter that can be used to target files on the device for deletion without proper restriction or authorization enforcement. As a result, an attacker can cause deletion of arbitrary files on the underlying system, which can affect device integrity and availability and may contribute to broader device compromise when combined with other weaknesses.
CVE-2017-18181First seen Aug 20, 2026
CVE-2017-18182 is a hardcoded credential vulnerability in Western Digital My Cloud personal cloud storage devices prior to firmware 2.30.172. The issue is present in the nas_sharing.cgi CGI component, which contains a built-in administrative account credential. Because the credential is embedded in the binary rather than provisioned securely at deployment time, an attacker who knows or recovers it can authenticate as an administrator without possessing legitimate user-assigned credentials. This results in a complete authorization bypass on affected devices.
CVE-2017-18182First seen Aug 20, 2026
CVE-2014-4681 is a denial-of-service vulnerability affecting the Wing HTTP server component in Wing FTP Server 4.3.7 and earlier on Windows. The flaw is caused by improper filtering of requests for certain reserved or special file names. By requesting one of these names, a remote attacker can trigger a condition that causes the embedded web server to become unavailable.
CVE-2014-4681First seen Aug 20, 2026
CVE-2014-2876 is an unauthenticated information disclosure vulnerability affecting NetSupport Manager and NetSupport Client. By sending a specially crafted request to a host running the NetSupport application, a remote attacker can retrieve sensitive host configuration information. The issue is exposed when NetSupport authentication is not configured, allowing unauthenticated access to information that should not be disclosed. Reported exposed data includes host settings and encrypted passwords, which can support follow-on compromise or facilitate additional attack paths.
CVE-2014-2876First seen Aug 20, 2026
CVE-2011-1037 is a broken authentication and session management vulnerability in the web-based administrative console of Avocent Cyclades ACS Web Manager. The flaw affects the application's authentication and session handling logic, allowing an unauthenticated user to bypass normal access controls and reach administrative console content. The issue exposes application pages and sensitive information intended only for authenticated administrative users, although the available information indicates the flaw does not enable access to dynamic functionality for changing settings through this issue alone.
CVE-2011-1037First seen Aug 20, 2026
CVE-2021-35470 is a multiple authenticated stored cross-site scripting vulnerability in the WordPress plugin Inline Related Posts affecting versions up to and including 3.0.4. Multiple plugin parameters can be used by an authenticated administrator to inject malicious JavaScript that is stored by the application. The payload is subsequently executed in the browsers of users who view a post containing the affected inline references.
CVE-2021-35470First seen Aug 20, 2026
CVE-2020-28003 is an arbitrary code execution issue in WinZip affecting the application's trial-mode content retrieval behavior. When operating in trial mode, WinZip fetches and renders remote HTML content over HTTP rather than HTTPS. Because the content is delivered without transport integrity, a network-positioned attacker can tamper with the response and supply malicious HTML and script content. This allows arbitrary JavaScript to execute within the WinZip process context when the application displays the attacker-modified content.
CVE-2020-28003First seen Aug 20, 2026
First seen Aug 20, 2026
First seen Aug 20, 2026
First seen Aug 19, 2026
First seen Aug 19, 2026
First seen Aug 17, 2026
First seen Aug 17, 2026
First seen Aug 16, 2026
First seen Aug 16, 2026
First seen Aug 16, 2026
First seen Aug 16, 2026
First seen Aug 15, 2026