These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,132 reserved CVEs with public mentions, ranked by all-time mention count.
Page 35 of 46
First seen Jul 23, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 22, 2026
First seen Jul 20, 2026
First seen Jul 17, 2026
First seen Jul 17, 2026
First seen Jul 17, 2026
First seen Jul 17, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
CVE-2026-49273 is a remote code execution vulnerability in MantisBT affecting the administrative Manage Configuration functionality implemented in adm_config_set.php. The flaw is caused by unsafe use of eval() on attacker-controlled configuration input, combined with PHP class and function hoisting behavior, allowing crafted input to be interpreted as executable PHP code. Successful exploitation occurs through the web interface and results in execution of arbitrary code within the context of the MantisBT application.
CVE-2026-49273First seen Jul 15, 2026
CVE-2026-52847 is a reflected cross-site scripting vulnerability in MantisBT affecting the admin/install.php component. The flaw arises from improper neutralization of user-supplied input before it is reflected in the generated response, allowing attacker-controlled content to be injected into a victim’s browser in the context of the application. The issue is reachable without authentication and can be triggered by convincing a target to visit a crafted request to the vulnerable installation endpoint.
CVE-2026-52847First seen Jul 15, 2026
CVE-2026-52881 is a reflected cross-site scripting vulnerability in MantisBT affecting version 2.28.3 and earlier. The flaw is present in admin/install.php, where user-supplied parameters are incorporated into printf output without proper escaping or output encoding. This allows attacker-controlled input to be reflected into the generated HTML/response and executed in a victim’s browser when the crafted request is opened. The vulnerable condition is reachable without authentication.
CVE-2026-52881First seen Jul 15, 2026
First seen Jun 12, 2026
First seen Jul 15, 2026
First seen Jul 15, 2026
First seen Jul 15, 2026
First seen Jul 15, 2026
CVE-2026-45262 is an authenticated SQL injection vulnerability in the FacturaScripts REST API filter parameter. The issue stems from improper handling of parenthesized field names in the Where::sqlColumn() logic, which allows attacker-controlled input to be incorporated into SQL expressions without sufficient validation. An attacker with a low-privileged API key and GET access to at least one API resource can abuse crafted filter parameters to query arbitrary columns from other tables, bypass intended model-level field restrictions, and access sensitive data across resources. The flaw affects API routes that process filter keys, including standard resource endpoints and attached file handling, and can be leveraged as a cross-resource data exfiltration primitive that may lead to broader application compromise.
CVE-2026-45262First seen Jul 15, 2026