These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,132 reserved CVEs with public mentions, ranked by all-time mention count.
Page 37 of 46
First seen Jun 18, 2026
First seen Jun 17, 2026
First seen Jun 17, 2026
First seen Jun 8, 2026
CVE-2026-32179 is a remote vulnerability in Microsoft QUIC (MsQuic) caused by improper input validation leading to an integer underflow while decoding/parsing ACK frames. The issue affects MsQuic packages including Microsoft.Native.Quic.MsQuic.OpenSSL and Microsoft.Native.Quic.MsQuic.Schannel. A remote attacker can send a crafted QUIC ACK frame that triggers the underflow during ACK frame parsing. The available advisory characterizes the issue as a remote elevation of privilege vulnerability.
CVE-2026-32179First seen Apr 21, 2026
CVE-2014-6072 affects the Symfony Web Profiler import/export functionality in Symfony versions prior to 2.3.19, 2.4.9, and 2.5.4. The issue is described by the vendor as a cross-site request forgery (CSRF) vulnerability in the Web Profiler. When the Web Profiler is enabled and its import feature is exposed, an attacker can cause a victim with access to the profiler to submit a forged request that imports attacker-controlled profiler data, including a PHP serialized string. The available supporting content also references public research and exploit material describing this as a profiler-related injection issue. The vulnerable functionality was removed from the Web interface in fixed releases and replaced with CLI commands.
CVE-2014-6072First seen May 24, 2026
First seen Jun 12, 2026
First seen Jun 11, 2026
First seen Jun 11, 2026
Brocade BigIron RX switch devices are affected by an access control list (ACL) bypass vulnerability. According to the provided advisory context, packets crafted with source port 179 can bypass configured ACL rules on affected devices. This indicates improper enforcement of access restrictions for traffic matching that source-port condition, allowing traffic that should have been filtered to traverse the device. The issue is referenced by Brocade software defect 355173 and affects vulnerable BigIron RX software releases prior to the fixed versions.
CVE-2011-4884First seen Jun 10, 2026
CVE-2023-45732 is a local privilege escalation vulnerability in com.proxyman.NSProxy.HelperTool (version 1.4.0) distributed with Proxyman.app up to version 4.11.0 on macOS. The HelperTool, a privileged service for managing system proxy settings via XPC, insufficiently enforces code-signing and legacy authorization checks. A local attacker can leverage an older, less-protected Proxyman.app (1.3.4) to communicate with the HelperTool and change system proxy settings, redirecting network traffic to an attacker-controlled host. The attack is facilitated by injecting a dynamic library into the old Proxyman app, which then manipulates the proxy settings via the HelperTool's XPC interface. The vulnerability is exploitable on macOS 13 Ventura and earlier.
CVE-2023-45732First seen Jun 9, 2026
First seen Jun 8, 2026
First seen Jun 3, 2026
First seen Jun 3, 2026
First seen Jun 3, 2026
First seen Jun 3, 2026
First seen Jun 3, 2026
CVE-2026-26847 is an improper authentication/authorization flaw in Collibra Platform Agent in which privileged REST endpoints exposed under /rest/* do not properly enforce access controls. According to the provided context, a remote, unauthenticated attacker can access sensitive application functionality and obtain information useful for further exploitation, including identifying suitable filesystem locations or application paths. CERT/CC indicates this issue is one of two chainable vulnerabilities in Collibra Platform Agent and can be combined with a Zip Slip path traversal flaw in the restore handler to achieve remote code execution.
CVE-2026-26847First seen Jun 2, 2026
CVE-2026-26848 is a Zip Slip vulnerability in the Collibra Platform Agent restore functionality exposed via POST /rest/restore. When the application processes a supplied ZIP archive, file paths inside the archive are not properly validated or canonicalized before extraction. An attacker can include directory traversal sequences such as ../ in archive entry names so that extracted files are written outside the intended restore directory. According to the advisory context, this flaw is one of two chainable vulnerabilities in Collibra Platform Agent and can be used as part of an attack path leading to remote code execution.
CVE-2026-26848First seen Jun 2, 2026
CVE-2025-44202 is a critical vulnerability in Vioma Condeon CMS versions up to and including 1.9.1, where a publicly accessible memory dump file is exposed via the web server. This file contains sensitive information such as valid session cookies (SESS_BE), password hashes, SQL statements, and file paths. Attackers can retrieve the memory dump by sending a GET request to /condeon/core, enabling them to hijack authenticated sessions and access sensitive data across all tenants hosted on the platform.
CVE-2025-44202First seen Jun 2, 2026
CVE-2025-44200 is a mass assignment vulnerability in Vioma Condeon CMS versions up to and including 1.9.1. The flaw allows authenticated attackers to manipulate the CustomerID field via the form[user_customer] POST parameter, enabling them to escalate privileges and gain administrative access to other customers' CMS instances. By creating a user, granting it admin permissions, and changing the CustomerID, attackers can achieve cross-tenant lateral movement and full administrative compromise of any Vioma-hosted Condeon CMS installation.
CVE-2025-44200First seen Jun 2, 2026
First seen Jun 1, 2026
First seen Jun 1, 2026
First seen Jun 1, 2026
First seen Jun 1, 2026