These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,132 reserved CVEs with public mentions, ranked by all-time mention count.
Page 38 of 46
First seen May 31, 2026
First seen May 31, 2026
CVE-2015-5676 affects the FreeBSD pkg(7) bootstrap utility. When the signature_type option in pkg.conf(5) is set to an unsupported method, the bootstrap logic incorrectly behaves as though signature_type were set to "none" rather than rejecting the configuration or failing closed. This causes package signature verification to be bypassed during bootstrap, enabling acceptance of an untrusted pkg(8) package. The issue is specifically in the handling of unsupported signature methods by the bootstrap utility.
CVE-2015-5676First seen May 26, 2026
First seen May 27, 2026
First seen May 26, 2026
First seen May 26, 2026
First seen May 26, 2026
CVE-2023-22245 is a critical out-of-bounds write vulnerability affecting Adobe Substance 3D Stager through a vulnerable third-party dependency. According to the provided advisory context, successful exploitation could lead to arbitrary code execution in the context of the current user. The specific vulnerable library, function, and code path are not identified in the provided content.
CVE-2023-22245First seen May 25, 2026
CVE-2021-28582 is a critical buffer overflow vulnerability in Adobe Photoshop for Windows and macOS. According to the provided Adobe advisory context, the flaw can be triggered in affected Photoshop versions and may result in arbitrary code execution in the context of the current user. The supplied material identifies the weakness as CWE-788 and indicates that Adobe addressed it in Photoshop 2020 version 21.2.8 / 21.2.9 and Photoshop 2021 version 22.4.0 / 22.4.2, depending on advisory wording. No vulnerable function or parsing component is specified in the provided content.
CVE-2021-28582First seen May 25, 2026
First seen May 26, 2026
First seen May 26, 2026
First seen May 26, 2026
CVE-2020-9709 is a privilege escalation vulnerability in Adobe Photoshop affecting Photoshop CC 2019 and Photoshop 2020 on Windows and macOS. The provided advisory identifies it as a security bypass / privilege escalation issue, but does not include technical details such as the vulnerable component, function, root cause, or exploitation method. Adobe addressed it as part of APSB20-45.
CVE-2020-9709First seen May 25, 2026
First seen May 25, 2026
First seen May 24, 2026
First seen May 24, 2026
First seen May 24, 2026
First seen May 18, 2026
First seen May 17, 2026
First seen May 17, 2026
First seen May 17, 2026
First seen May 13, 2026
First seen May 13, 2026
First seen May 10, 2026
First seen May 10, 2026