These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,131 reserved CVEs with public mentions, ranked by all-time mention count.
Page 34 of 46
CVE-2024-31330First seen Jul 30, 2026
CVE-2024-26048First seen Jul 30, 2026
CVE-2025-46787First seen Jul 30, 2026
First seen Jul 30, 2026
CVE-2026-20143First seen Jul 30, 2026
flyto-core contains a server-side request forgery vulnerability in multiple HTTP-capable modules that issue outbound requests to fully user-controlled URLs without invoking the project's SSRF validation routine, validate_url_with_env_config. The flaw affects modules that perform direct HTTP requests while relying only on non-enforcing metadata indicating SSRF protection rather than actually applying destination validation before network access. Reported affected modules include core.api.http_get, core.api.http_post, GraphQL request modules, monitoring and notification modules, certain AI and browser-related modules, and inline base_url handling paths. The root cause is an inconsistent, per-module SSRF protection model with no centralized guarded outbound HTTP client, allowing vulnerable modules to bypass intended destination restrictions entirely. Successful exploitation allows an authenticated workflow author to direct the application to access loopback, RFC1918, cloud metadata, and other internal network resources and receive the remote response content back through the application.
CVE-2026-55787First seen Jul 7, 2026
CVE-2023-23359 is a vulnerability affecting QNAP QTS, QuTS hero, and QuTScloud. Available information indicates that exploitation may allow remote arbitrary code execution or denial of service. Specific technical details about the vulnerable component, root cause, and affected function are currently not available.
CVE-2023-23359First seen Jul 30, 2026
CVE-2025-36350 is an information disclosure vulnerability affecting AMD processors and addressed through Microsoft's July 2025 Windows security updates. Available reporting identifies it as one of two AMD information-disclosure issues remediated by applying a Windows patch. Specific technical details about the vulnerable component, root cause, and triggering conditions are not currently available from the provided material.
CVE-2025-36350First seen Jun 14, 2026
CVE-2024-54035 is an improper authorization vulnerability in Adobe Connect. The flaw allows a remote, unauthenticated attacker to exploit insufficient authorization controls and escalate privileges without requiring user interaction. The issue affects Adobe Connect versions prior to 12.7 and 11.4.9.
CVE-2024-54035First seen Jul 23, 2026
First seen Jul 30, 2026
CVE-2024-51538First seen Jul 30, 2026
CVE-2026-21958First seen Jan 21, 2026
First seen Jul 29, 2026
First seen Jul 29, 2026
First seen Jul 25, 2026
First seen Jul 23, 2026
First seen Jul 23, 2026
First seen Jul 23, 2026
First seen Jul 23, 2026
First seen Jul 23, 2026
CVE-2026-57496 is a path traversal vulnerability in netlicensing-mcp that affects requests handled through the product endpoint. An authenticated client can supply traversal sequences that cause the application to access the token endpoint instead of the intended product resource. This endpoint confusion bypasses token-specific redaction controls and exposes sensitive token data in plaintext, including API key values and shop URL information. The issue indicates insufficient validation and normalization of user-controlled path segments before they are incorporated into upstream REST path construction.
CVE-2026-57496First seen Jul 22, 2026
CVE-2026-57116 is an authentication flaw in PraisonAI AgentOS caused by an incomplete fix for a prior advisory. Exposed FastAPI routes handling agent discovery and chat invocation remain accessible without authentication, allowing remote unauthenticated clients to enumerate deployed agents and invoke them. The issue affects the security boundary around AgentOS and AgentApp by failing to consistently enforce bearer authentication on sensitive API endpoints. In reachable deployments, this permits unauthorized interaction with agent functionality and any downstream capabilities exposed through those agents.
CVE-2026-57116First seen Jul 21, 2026
CVE-2025-60034 is a vulnerability in the Bosch MAP 5000 family caused by the SSH service being configured to permit insecure cryptographic algorithms. The weakness allows use of deprecated or otherwise insufficiently strong cryptographic mechanisms during SSH sessions, reducing the security guarantees normally provided by the protocol. As a result, an attacker in a suitable network position may be able to attack SSH communications and undermine confidentiality or integrity protections, with potential downstream consequences including unauthorized access and exposure of sensitive data.
CVE-2025-60034First seen Jul 23, 2026
CVE-2025-4995 is a cryptographic weakness in the TLS server implementation of Bosch MAP 5000. The product uses outdated TLS cryptographic settings, specifically weak Diffie-Hellman key exchange parameters, during TLS session establishment. This weakness reduces the effective security of encrypted connections and can allow an attacker positioned on the network path to undermine the protection expected from TLS. The issue affects the confidentiality and integrity of communications by making it feasible to passively decrypt traffic or actively intercept and manipulate supposedly secured sessions.
CVE-2025-4995First seen Jul 23, 2026
First seen Jul 23, 2026