These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,130 reserved CVEs with public mentions, ranked by all-time mention count.
Page 6 of 46
CVE-2025-68405 is a stack overflow vulnerability in QNAP products, including affected releases of QTS, QuTS hero, QuTS cloud, and QVP. The flaw can be exploited by an authenticated administrator and may trigger unexpected system behavior or a denial-of-service condition. The available information identifies the issue as a stack overflow but does not provide the specific vulnerable component, function, or code path.
CVE-2025-68405First seen Jun 17, 2026
CVE-2025-15660 is a critical vulnerability in Synology MailPlus Server on DiskStation Manager (DSM). The issue is associated with CWE-338, Use of Cryptographically Weak PRNG, and has been identified as ZDI-CAN-28554. Successful exploitation allows an adjacent attacker to read arbitrary files, write arbitrary files, and trigger denial-of-service conditions, resulting in compromise of data confidentiality and integrity as well as service availability. Publicly available context does not provide the specific vulnerable function or code path.
CVE-2025-15660First seen Jun 29, 2026
CVE-2026-53922 is a moderate-severity vulnerability in OpenWrt's odhcpd affecting DHCPv6 Identity Association handling. The flaw is described as a size_t underflow in the DHCPv6 IA processing path, reachable before authentication by a network-adjacent attacker sending crafted DHCPv6 traffic. The vulnerable condition occurs while parsing or handling DHCPv6 IA-related data, where insufficient bounds validation allows an unsigned size calculation to wrap, leading to invalid memory access during request processing. OpenWrt addressed the issue in an odhcpd update that also incorporated additional DHCPv6 input-validation and bounds-checking hardening.
CVE-2026-53922First seen Jun 30, 2026
CVE-2026-39218 is a heap buffer overflow vulnerability in FFmpeg's DASH demuxer. The flaw was reportedly introduced in 2017 and affects FFmpeg media parsing functionality within the DASH demuxing path. A crafted DASH media input can trigger out-of-bounds writes to heap memory during demuxer processing, leading to memory corruption. As a parser-side memory safety flaw in a widely deployed media framework, the vulnerability is relevant anywhere FFmpeg processes attacker-controlled or untrusted DASH content, whether directly through command-line use or indirectly through applications and services embedding FFmpeg.
CVE-2026-39218First seen Jun 6, 2026
CVE-2026-35330 is a vulnerability in libsimaka involving the processing of certain EAP-SIM/AKA attributes. According to the provided context, malformed or specially crafted attributes can trigger either an infinite loop or a heap-based buffer overflow during parsing or handling of EAP-SIM/AKA data. The heap corruption condition may potentially lead to remote code execution. Specific vulnerable functions, affected versions, and patch details are not available in the provided content.
CVE-2026-35330First seen Apr 22, 2026
First seen Jun 18, 2026
CVE-2026-45354 is a high-severity pre-authentication DSI protocol desynchronization vulnerability in Netatalk, an implementation of the Apple Filing Protocol (AFP). The issue affects Netatalk versions 1.5.0 through 4.4.2. Based on the available context, the flaw occurs in handling of the DSI protocol before authentication is completed, allowing protocol state to become desynchronized. No vulnerable function or code path is identified in the provided material.
CVE-2026-45354First seen May 15, 2026
CVE-2026-45356 is a high-severity integer underflow vulnerability in Netatalk's Spotlight RPC handling, specifically in a count decrement operation. The issue affects Netatalk versions 3.1.0 through 4.4.2. The available context identifies the flaw as occurring during Spotlight RPC count decrement processing, indicating that malformed or attacker-controlled RPC input can cause an integer value to wrap below zero, leading to unsafe subsequent memory handling or logic errors.
CVE-2026-45356First seen May 15, 2026
CVE-2026-45355 is a high-severity vulnerability in Netatalk affecting versions 3.1.0 through 4.4.2. The issue is described as an integer underflow that leads to a heap out-of-bounds read. Based on the available information, improper handling of a length, count, or similar arithmetic value causes an underflow condition, which subsequently results in reads beyond the bounds of an allocated heap buffer during processing of attacker-supplied data.
CVE-2026-45355First seen May 15, 2026
First seen Mar 18, 2026
First seen Mar 18, 2026
CVE-2026-84471 is a medium-severity, network-reachable denial-of-service vulnerability affecting OpenVPN. It is fixed upstream in OpenVPN 2.7.7. The available information does not identify the vulnerable function or the precise malformed input or protocol condition that triggers the failure.
CVE-2026-84471First seen Sep 4, 2026
CVE-2026-107226 is a cookie-origin enforcement vulnerability in AsyncHttpClient affecting its cookie store and applications that use it, including affected Chainguard druid packages. The cookie store accepts cookies from plaintext HTTP responses that can plant, overwrite, or delete Secure cookies subsequently used in HTTPS requests. Cookie ordering can also give attacker-controlled plaintext cookies precedence over HTTPS-origin cookies. An attacker controlling a plaintext HTTP response can consequently influence cookies used by an HTTPS application, potentially enabling session fixation, CSRF-token replacement, or deletion of security-relevant cookies.
CVE-2026-107226First seen Oct 8, 2026
CVE-2026-77459 is an authorization bypass in Argo CD that allows PreDelete and PostDelete resource hooks to bypass AppProject restrictions. The flaw permits deletion-hook operations to circumvent project-level authorization controls. Argo CD v3.3.15 fixes the vulnerability; the affected version range and underlying implementation details are not specified.
CVE-2026-77459First seen Oct 7, 2026
CVE-2026-45513 is a vulnerability in Google Android listed among issues addressed by October 2026 security updates. It is associated with devices having a security patch level earlier than 2026-10-01. The affected component, vulnerable function, underlying weakness, and CVE-specific consequences are currently not available.
CVE-2026-45513First seen Oct 7, 2026
CVE-2026-41510 affects Coraza versions 3.0.0 through 3.8.0. Incomplete argument-limit enforcement silently drops arguments from inspection, allowing parameter flooding to conceal malicious payloads from ARGS-targeted web application firewall rules. Incomplete parsing limits and JSON-flattening byte-budget enforcement also permit excessive resource consumption. Affected processing includes URL-encoded arguments, repeated keys, nested JSON array-length entries, and JSON response bodies processed through RESPONSE_ARGS. Version 3.8.0 contains an incomplete fix; version 3.8.1 completes the remediation.
CVE-2026-41510First seen Oct 6, 2026
CVE-2026-55279 is a vulnerability in Google Android listed in an advisory affecting devices with a security patch level earlier than 2026-10-01. The specific flaw, affected component, and exploitation mechanism are currently unavailable.
CVE-2026-55279First seen Oct 7, 2026
CVE-2026-45516 is a Google Android vulnerability included in October 2026 security advisories. The associated advisories cover Android devices with outdated security patch levels. The affected component, underlying weakness, and CVE-specific exploitation consequences are currently not available.
CVE-2026-45516First seen Oct 7, 2026
CVE-2013-0808 is a vulnerability exploited through embedded Encapsulated PostScript (EPS) objects in malicious Hancom Hangul HWP documents. Observed attacks used zlib-compressed EPS objects containing shellcode to download payloads disguised as images, decode them, and execute ROKRAT. The documents were delivered through spear-phishing campaigns targeting South Korean users. The underlying implementation flaw, vulnerable function, and affected software versions are not established.
CVE-2013-0808First seen Aug 14, 2026
CVE-2026-61702 affects CUPS and is addressed upstream in version 2.4.20. Affected distribution packages are identified for Slackware, Debian, and Amazon Linux. Details of the underlying flaw, vulnerable functions, and exploitation mechanism are currently not available.
CVE-2026-61702First seen Oct 6, 2026
CVE-2026-65165 affects Slurm Workload Manager (slurm-wlm), a cluster resource management and job scheduling system. The vulnerability involves issues with job steps and node-count discrepancies. The precise vulnerable functions, underlying defect, and CVE-specific exploitation outcomes are currently not available. Debian stable (trixie) includes a fix in package version 24.11.5-4+deb13u1.
CVE-2026-65165First seen Sep 4, 2026
CVE-2026-59179 is a path-traversal vulnerability in @openhop/server flow-file operations, affecting @openhop/server 0.3.5 and reportedly openhop CLI 0.3.6. FlowStore.filePath() passes an unvalidated flow ID to Node.js path.join() and appends a YAML extension. Fastify's find-my-way router decodes URL-encoded route parameters before application processing, allowing encoded traversal sequences to resolve outside the configured flow directory. Unauthenticated GET and DELETE flow operations can consequently read or permanently delete YAML files accessible to the server process.
CVE-2026-59179First seen Sep 10, 2026
CVE-2026-92392 is a vulnerability in curl scheduled to be fixed in curl 8.23.0 on October 14, 2026. As of October 8, 2026, its technical cause, vulnerable functions, affected versions, triggering conditions, and exploitation status have not been publicly disclosed. Technical disclosure is planned to coincide with the release.
CVE-2026-92392First seen Oct 7, 2026
CVE-2026-50204 affects Apache Airflow single-entity endpoints and was fixed in version 3.3.0. It is distinct from CVE-2026-68969, which involves sensitive-information exposure through bulk endpoints. Detailed root-cause and exploitation information for CVE-2026-50204 is currently not available.
CVE-2026-50204First seen Aug 13, 2026
CVE-2026-61404 affects QEMU and is addressed by adding a post_load check to its UEFI device. The precise validation failure, vulnerable code path, exploitation mechanism, and security consequences are currently not available.
CVE-2026-61404First seen Aug 30, 2026