These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,130 reserved CVEs with public mentions, ranked by all-time mention count.
Page 46 of 46
CVE-2013-7035 is a cross-site scripting vulnerability in React affecting 0.5.x before 0.5.2 and 0.4.x before 0.4.2. According to the provided advisory, the issue is caused by improper sanitization of input used to create keys. If an application derives a React key from attacker-controlled input, the unsanitized value can be incorporated in a way that enables script execution in the victim's browser context.
CVE-2013-7035First seen Jun 4, 2026
CVE-2014-6061 is an authentication-related flaw in the Symfony HttpFoundation component affecting applications that rely on HTTP Basic or Digest authentication. The vulnerability stems from improper parsing of the HTTP Authorization header by HttpFoundation in certain server configurations. As a result, authentication handling may be performed incorrectly when the framework processes malformed or ambiguously parsed Authorization header data. Based on the provided advisory, the issue was fixed in Symfony versions 2.3.19, 2.4.9, and 2.5.4, with a corresponding patch published in Symfony pull request #11829.
CVE-2014-6061First seen Jun 4, 2026
CVE-2024-22031 is a privilege escalation vulnerability in Rancher caused by improper handling of project identity across clusters when projects share the same object name. According to the provided advisory, a user with permission to create projects on one cluster can create a project using the same name as an existing project in another cluster and thereby gain access to the other project. The issue appears to stem from namespace or object-name collision behavior across clusters, allowing authorization boundaries between clusters to be bypassed when duplicate project names exist.
CVE-2024-22031First seen Jun 4, 2026
Symfony HttpKernel contains an access control flaw affecting deployments where Edge Side Includes (ESI) support is enabled behind a trusted proxy. In affected versions, clients can directly request fragment/ESI URLs, such as the fragment endpoint, instead of having those requests mediated exclusively by the trusted proxy as intended. This can expose protected fragment endpoints or allow invocation of internal fragment functionality that should only be reachable through proxy-driven fragment rendering.
CVE-2014-5245First seen Jun 4, 2026
CVE-2025-66475 is a critical signature wrapping vulnerability affecting OneLogin php-saml through its xmlseclibs dependency. Based on the provided advisory, the flaw is in XML signature validation handling and can be exploited in SAML processing, allowing a maliciously crafted signed XML/SAML message to bypass intended signature protections. The issue affects deployments using vulnerable php-saml releases that depend on an unpatched xmlseclibs version.
CVE-2025-66475First seen Jun 4, 2026