These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,130 reserved CVEs with public mentions, ranked by all-time mention count.
Page 45 of 46
CVE-2026-49259 is a stored cross-site scripting vulnerability in NukeViet CMS 4.x through 4.5.08. A low-privileged authenticated user can inject malicious JavaScript through profile display name fields. The flaw is triggered when the attacker’s crafted display name is later incorporated into the Reply functionality for comments, where user-controlled data is passed into an inline JavaScript handler without safe JavaScript-context encoding. Because the application relies on HTML entity encoding rather than proper JavaScript string encoding, an attacker can break out of the intended context and execute script in the victim’s browser when the Reply link is clicked.
CVE-2026-49259First seen Jul 14, 2026
CVE-2026-54700 affects org.connectbot.sshlib:sshlib. According to the provided advisory, the library contains an input validation flaw in SSH protocol parsing in which attacker-controlled inner length fields and repeated-element count fields are not properly bounded against the containing stream. A malicious or compromised SSH server can supply malformed SSH packets whose declared internal sizes cause the client to attempt excessive heap allocation during parsing. The issue is described as affecting length-prefixed fields as well as repeated-element counts, with additional fixes covering transport and agent frame length validation and SSH padding constraints. The vulnerability is therefore an improper input validation issue in packet parsing that can be triggered by malicious protocol data from the remote endpoint.
CVE-2026-54700First seen Jul 9, 2026
EGroupware contains a local file inclusion issue in its mail compose functionality due to unsafe handling of URI schemes embedded in HTML email bodies. According to the provided advisory, attacker-controlled HTML content can include inline image or similar resource references using file:// URIs, and the application subsequently retrieves the referenced resource via file_get_contents() without enforcing a strict HTTP/HTTPS-only allowlist. This allows an authenticated user with access to the mail feature to cause the server to read arbitrary local files accessible to the web server process and include their contents as inline MIME attachments in outgoing email.
CVE-2026-45016First seen Jul 8, 2026
CVE-2026-54641 is an authorization flaw in io.openremote:openremote-manager affecting multi-tenant realm isolation. According to the provided advisory, three read methods in UserResourceImpl—get, getUserClientRoles, and getUserRealmRoles—do not properly enforce realm-access authorization before returning user information. As a result, a realm administrator in one tenant with read:admin privileges can query user records belonging to other realms, including the master realm. The exposed data includes user profile information, account enabled/disabled status, and assigned Keycloak client and realm roles.
CVE-2026-54641First seen Jul 7, 2026
CVE-2026-54640 is an XML External Entity (XXE) vulnerability in OpenRemote's openremote-agent, specifically in the KNXProtocol asset import handling path. According to the provided advisory, this is an incomplete fix related to CVE-2026-40882: the KNXProtocol asset import handler, including KNXProtocol.startAssetImport(), remains vulnerable because the XML parsing path does not fully disable DTD processing and external entity resolution. The advisory specifically notes exposure in both Saxon/XSLT processing and XMLInputFactory usage. A successful attacker can supply crafted XML during asset import to cause the parser to resolve external entities, enabling arbitrary file disclosure and potentially server-side request forgery (SSRF).
CVE-2026-54640First seen Jul 7, 2026
flyto-core contains an unauthenticated command execution vulnerability in the HTTP MCP POST /mcp endpoint. The issue is exposed through tools/call execute_module, which allows invocation of sandbox.execute_shell and results in arbitrary OS command execution by the flyto-core server process. The advisory indicates the vulnerable request handling does not properly enforce authentication on /mcp routes and does not adequately apply module filtering/denylisting to prevent access to dangerous sandbox functionality.
CVE-2026-55786First seen Jul 7, 2026
GeoNetwork contains a reflected cross-site scripting vulnerability in its AngularJS-based error page. Based on the provided advisory, the issue is triggered via client-side template injection in reflected input, allowing attacker-controlled content from a crafted URL to be interpreted in the browser and executed as arbitrary JavaScript. The vulnerable condition affects GeoNetwork deployments prior to the fixed supported releases 4.2.15 and 4.4.10; the 3.x and 4.0.x branches are unmaintained and will not receive a fix.
CVE-2026-39379First seen Jul 2, 2026
GeoNetwork contains an authorization bypass in its Elasticsearch-backed search API. According to the provided advisory, when a search request body omits the query field, the application fails to apply the expected ACL/access-control filtering to indexed metadata records. This logic flaw allows requests to return records that should remain restricted, including group-limited, draft, ownership-restricted, and portal-filtered metadata. The issue is therefore an access-control enforcement failure in the search path rather than a memory-safety or injection flaw.
CVE-2026-46487First seen Jul 2, 2026
OpenAM Community Edition contains an unauthenticated authentication bypass in its RADIUS authentication module. The flaw allows an attacker to spoof a RADIUS Access-Accept response, causing OpenAM to treat the authentication as successful and create a valid session for an arbitrary RADIUS username. Based on the available information, exploitation does not require knowledge of the RADIUS shared secret and results in successful impersonation of a RADIUS-mapped user.
CVE-2026-46560First seen Jun 26, 2026
CVE-2026-45049 is an information exposure vulnerability in OpenAM Community Edition affecting the CDSSO CDCServlet component used in cross-domain single sign-on flows. Under affected configurations, the servlet can be abused so that a logged-in user's raw OpenAM session token is included in a POST request to an attacker-controlled URL. This exposes a bearer-style session artifact outside the intended trust boundary. Based on the available information, exploitation requires inducing an authenticated victim to visit a crafted URL and is relevant to deployments with CDSSO enabled, particularly where the non-default protective configuration is absent.
CVE-2026-45049First seen Jun 24, 2026
CVE-2026-44179 is a remote code execution vulnerability in xwiki-pro-macros affecting the excerpt-include macro. According to the provided advisory, the issue is caused by improper escaping of the included page title combined with execution of excerpt content with the macro's rights. This allows attacker-controlled content or parameters associated with the included page/excerpt processing path to be interpreted in a way that results in server-side code execution within the XWiki installation.
CVE-2026-44179First seen Jun 23, 2026
NL Portal Backend Libraries contain unauthenticated GraphQL form-definition resolvers that accept a caller-supplied Objecten-API URL and cause the backend to fetch that URL on the configured Objecten-API host while forwarding a privileged Objecten-API token. This creates a constrained server-side request forgery condition combined with missing authorization on the resolver. According to the provided advisory, affected functionality includes `getFormDefinitionByObjectenApiUrl` and deprecated `getFormDefinitionById`. The issue is constrained because outbound requests are limited to the configured Objecten-API host, and arbitrary object reads are further limited by typed deserialization, but an attacker can still influence the request target on that host and induce authenticated backend requests.
CVE-2026-55414First seen Jun 20, 2026
CVE-2026-54711 is an information exposure vulnerability in PGHoard where database connection information, including the username and password sourced from .pgpass, is written to debug-level logs. The issue results in sensitive credential material being recorded in log output during normal debugging or verbose operation, creating a secondary disclosure channel for secrets that should not be logged.
CVE-2026-54711First seen Jun 19, 2026
CVE-2026-54683 is an authorization flaw in NL Portal Backend Libraries documenten-api caused by an incomplete fix for CVE-2026-49463. In affected versions, any authenticated user could retrieve document contents through the REST endpoint GET /api/documentapi/*/document/*/content or through the GraphQL getDocumentContent query without a per-document authorization check. As a result, access control was enforced only at the authentication level, not at the individual document level, allowing users to access documents outside their permitted scope if they knew or could obtain a target document identifier. The issue was fully resolved in version 3.0.3.
CVE-2026-54683First seen Jun 19, 2026
SwiftNIO contains an out-of-bounds memory corruption vulnerability in ByteBuffer index and length handling. According to the provided advisory, affected helper functions perform unsafe UInt32(truncatingIfNeeded:) conversions on attacker-influenced index, offset, or length values. When values larger than UInt32.max are supplied, truncation can wrap the value and cause incorrect buffer position or size calculations, leading to out-of-bounds writes or reads and corruption of buffer contents or outbound packets.
CVE-2026-43671First seen Jun 13, 2026
CVE-2014-5244 is a denial-of-service vulnerability in the Symfony HttpFoundation component. The issue is triggered when Request::getHost() performs hostname validation on a maliciously long HTTP Host header. Processing an arbitrarily long hostname causes excessive computation during validation, allowing an attacker to consume application resources with crafted requests. The affected branches include Symfony HttpFoundation / Symfony 2.0.x, 2.1.x, 2.2.x, and vulnerable releases prior to the fixed versions in the maintained branches.
CVE-2014-5244First seen Jun 4, 2026
SwiftNIO contains a CRLF injection vulnerability in outbound HTTP/1.1 request and response start line components caused by insufficient validation in NIOHTTPRequestHeadersValidator and NIOHTTPResponseHeadersValidator. According to the provided advisory, validation was missing or inadequate for request URIs, custom HTTP methods, and response reason phrases, allowing attacker-controlled carriage return and line feed characters to be injected into HTTP/1.1 start lines. This can corrupt HTTP message framing and enable downstream protocol interpretation issues.
CVE-2026-28970First seen Jun 13, 2026
CVE-2025-30081 is a cross-site scripting (XSS) vulnerability in the Clickstorm SEO extension for TYPO3. According to the provided advisory, the flaw allows a logged-in TYPO3 backend user to inject improperly encoded input into HTML output rendered in the TYPO3 backend. The issue stems from insufficient output encoding of user-controlled input before it is included in backend HTML, enabling script-capable content to be executed in another user's browser within the backend context.
CVE-2025-30081First seen Jun 4, 2026
SwiftNIO's NIOHTTP1 HTTPDecoder accepts unbounded HTTP/1 header blocks. When processing HTTP/1 requests or responses, the decoder can accumulate header data without sufficient limits, allowing a remote peer to send excessively large or numerous headers. This can exhaust memory in applications using NIOHTTP1 and, in some downstream frameworks, may also trigger a process crash when framework-level header count limits are exceeded after the decoder has already accumulated the data.
CVE-2026-28980First seen Jun 13, 2026
CVE-2026-28975 affects swift-nio-extras in the NIOHTTPRequestDecompressor component. When decompression protection is configured using the .ratio(N) limit, the implementation can be bypassed by an attacker supplying a falsified inflated Content-Length header. The vulnerable logic relies on the header-supplied Content-Length value when enforcing the decompression ratio limit, rather than tracking the actual compressed bytes received. As a result, a highly compressed request body can be accepted and decompressed without the intended protection being applied.
CVE-2026-28975First seen Jun 13, 2026
A configuration-validation flaw in the Radius Kubernetes controller allows a tampered Deployment annotation, radapp.io/status, to reference a container resource outside the current tenant or namespace. When the controller processes the manipulated annotation, it can issue deletion of the referenced Radius-managed container resource without properly validating tenant or namespace ownership. In multi-tenant Radius installations, this creates a cross-tenant authorization failure where one tenant's Deployment metadata can influence deletion of another tenant's resource. The issue is described as affecting deletion logic tied to controller handling of annotated Deployment state.
CVE-2026-53999First seen Jun 13, 2026
CVE-2023-32198 is an improper certificate validation vulnerability in Steve. During TLS connections, Steve does not verify the remote server certificate by default, contrary to expected Go TLS certificate validation behavior. This allows a malicious intermediary to present an untrusted or spoofed certificate without being rejected, enabling interception and modification of traffic between Steve and the remote service. In Rancher deployments, the issue is particularly relevant under specific configuration conditions involving remote UI content retrieval.
CVE-2023-32198First seen Jun 4, 2026
CVE-2025-30083 is a cross-site scripting vulnerability in the codingms/additional-tca extension for TYPO3. According to the provided advisory, improperly encoded user input can be used by an authenticated TYPO3 backend user to create malicious output in an HTML context within the TYPO3 backend. The issue is therefore an authenticated backend-context XSS caused by insufficient output encoding of user-controlled data.
CVE-2025-30083First seen Jun 4, 2026
CVE-2015-2309 affects the Symfony HttpFoundation Request class. When at least one trusted proxy is configured, unsafe request-handling methods can incorrectly trust client-supplied HTTP header values. As a result, header-derived properties exposed by methods such as getPort(), isSecure(), getHost(), and getClientIps() may be influenced by attacker-controlled input rather than only by values inserted by trusted infrastructure. The issue is specifically tied to proxy trust handling in deployments that rely on forwarded headers to reconstruct the original client request context.
CVE-2015-2309First seen Jun 4, 2026
CVE-2014-4931 is a code injection vulnerability in Symfony FrameworkBundle's translation caching mechanism. According to the provided advisory context, attacker-controlled locale values, such as unsanitized _locale parameters supplied via URLs, can be written into generated cache files. If those locale values are not properly sanitized before reaching the translation caching logic, an attacker can inject arbitrary PHP code into the cache content, which may then be executed by the application.
CVE-2014-4931First seen Jun 4, 2026