These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,130 reserved CVEs with public mentions, ranked by all-time mention count.
Page 7 of 46
CVE-2026-15705 is a vulnerability affecting QEMU packages associated with a denial-of-service condition exploitable through local access with high privileges. It is addressed by QEMU security updates, including Oracle Linux 9 advisory ELSA-2026-500245. The underlying defect, vulnerable function, triggering input, and complete affected-version range are currently unavailable.
CVE-2026-15705First seen Sep 8, 2026
Copernik XML Factory through version 0.1.1 fails to prevent XInclude resource resolution when applications enable XInclude using the stock JDK XML provider. The defect affects factories returned by XmlFactories.newDocumentBuilderFactory() and XmlFactories.newSAXParserFactory(), and XMLReader instances hardened through XmlFactories.harden(). Parsing attacker-controlled XML under these conditions can disclose local files and trigger server-side request forgery, violating the library's documented security guarantee. The Apache Xerces and Android providers are unaffected.
CVE-2026-61586First seen Oct 2, 2026
CVE-2026-104201 is an input-validation vulnerability in radsecproxy, a RADIUS protocol proxy. Incomplete validation of MS-PPPE packets can cause denial of service or potentially arbitrary code execution. Debian released a security update for its stable distribution, trixie. The specific vulnerable function and affected upstream version range are not identified.
CVE-2026-104201First seen Oct 2, 2026
CVE-2026-48004First seen Jun 1, 2026
CVE-2026-63321 affects QEMU packages. Details of the underlying vulnerability mechanism, vulnerable component or function, and complete affected-version range are currently unavailable.
CVE-2026-63321First seen Aug 30, 2026
CVE-2026-49265 is a timing side-channel vulnerability in OAuthLib's PKCE authorization-code verifier comparison. The plain PKCE comparison uses Python string equality instead of a constant-time comparison, potentially exposing a timing oracle. An attacker who intercepts an authorization code and can perform repeated, precisely timed token requests may infer the code verifier character by character and redeem the code. Exploitation could lead to access-token theft and account takeover, but is constrained by authorization-code single-use semantics and network jitter.
CVE-2026-49265First seen Sep 29, 2026
CVE-2026-65929 affects QEMU packages and is addressed by a QEMU security update to version 1:10.0.13+ds-0+deb13u1 and by Oracle Linux 9 advisory ELSA-2026-500245. Details of the vulnerability mechanism, affected functions, and exploitation behavior are currently unavailable.
CVE-2026-65929First seen Aug 30, 2026
CVE-2026-103952 is an out-of-bounds write vulnerability in Tenable Nessus versions earlier than 10.12.5. An authenticated, privileged attacker could exploit it to cause denial of service. The affected function and triggering input are not specified. Nessus 10.12.5 includes a fix.
CVE-2026-103952First seen Oct 1, 2026
CVE-2026-103950 is a type confusion vulnerability affecting Tenable Nessus versions earlier than 10.12.5. An authenticated, privileged attacker could exploit it to compromise Nessus confidentiality, integrity, or availability. The affected function and triggering input are not specified.
CVE-2026-103950First seen Oct 1, 2026
CVE-2026-103946 is an SQL injection vulnerability in Tenable Nessus versions earlier than 10.12.5. An authenticated user can exploit the vulnerability to read or modify data stored by Nessus. The affected function, injection parameter, and vulnerable endpoint are not identified. Nessus 10.12.5 fixes the vulnerability.
CVE-2026-103946First seen Oct 1, 2026
CVE-2026-103947 is an integrity-verification vulnerability in Tenable Nessus versions earlier than 10.12.5. Nessus does not sufficiently verify the integrity of certain downloaded content before using it, potentially allowing an authenticated, privileged attacker to compromise the system. The affected content types and vulnerable functions are not specified.
CVE-2026-103947First seen Oct 1, 2026
CVE-2026-103951 is an out-of-bounds write vulnerability in Tenable Nessus versions earlier than 10.12.5. An authenticated, privileged attacker could exploit it to compromise Nessus confidentiality, integrity, or availability. The vulnerable function and triggering input are not identified. Nessus 10.12.5 resolves the vulnerability.
CVE-2026-103951First seen Oct 1, 2026
CVE-2026-103955 affects Tenable Nessus versions earlier than 10.12.5. Inadequate limits on resource consumption could allow an authenticated, privileged attacker to cause a denial of service. The vulnerable function and specific resource-exhaustion mechanism are not identified.
CVE-2026-103955First seen Oct 1, 2026
CVE-2026-103948 is an improper handling of inconsistent length values vulnerability in Tenable Nessus versions earlier than 10.12.5. An authenticated, privileged attacker could exploit the flaw to compromise Nessus confidentiality, integrity, or availability. The affected function and specific triggering input are not identified.
CVE-2026-103948First seen Oct 1, 2026
CVE-2026-103953 is a memory-management vulnerability in Tenable Nessus versions earlier than 10.12.5. An authenticated, privileged attacker could exploit it to cause denial of service. The specific vulnerable function and memory-management failure mechanism are not identified.
CVE-2026-103953First seen Oct 1, 2026
CVE-2026-103954 is an out-of-bounds read vulnerability in Tenable Nessus versions earlier than 10.12.5. An authenticated, privileged attacker could exploit it to disclose limited information from Nessus. The specific vulnerable function and triggering input are not identified. Nessus 10.12.5 fixes the vulnerability.
CVE-2026-103954First seen Oct 1, 2026
CVE-2026-63322 is a vulnerability affecting QEMU. Available severity information characterizes it as a local, low-complexity issue requiring high privileges and causing an availability-only impact. The underlying vulnerable component and flaw class have not been specified.
CVE-2026-63322First seen Aug 30, 2026
CVE-2026-71197 is a server-side request forgery vulnerability in the OpenStack Glance image service's web-download import functionality. Glance applies host filters to import URIs without first resolving DNS, allowing an authenticated attacker to bypass filtering with an attacker-controlled domain and DNS rebinding. The issue affects deployments using web-download import in Glance versions 16.0.0 through 30.2.0, 31.0.0 through 31.1.0, and 32.0.0 prior to 32.0.1.
CVE-2026-71197First seen Sep 3, 2026
CVE-2026-71196 is a server-side request forgery vulnerability in OpenStack Glance web-download image import. In affected deployments, insecure default URI filtering can allow an authenticated Glance user to cause the service to retrieve arbitrary internal URLs, including cloud metadata-service endpoints. The issue is part of the related OSSA-2026-038 Glance SSRF vulnerabilities.
CVE-2026-71196First seen Sep 3, 2026
CVE-2026-42394First seen Sep 25, 2026
CVE-2026-58099 is a use-after-free vulnerability in kqueue knote copying. When knotes are copied from a parent kqueue to a child, marker knotes are not correctly excluded before being marked in-flux and the kqueue lock is released. A concurrent thread can free a marker knote while the lock is dropped, after which the copying code decrements the in-flux state through freed memory.
CVE-2026-58099First seen Sep 29, 2026
CVE-2026-82987 is an unauthenticated input-injection vulnerability in ViewSonic vCast software on Android-based ViewBoard smart displays. Exposed vCast service endpoints accept arbitrary attacker-supplied input through HTTP requests, enabling unauthenticated users to send input commands to an affected device.
CVE-2026-82987First seen Sep 24, 2026
CVE-2026-96368 is one of 19 additional vulnerabilities affecting the Drupal Webform module that were remediated in the same Webform update as CVE-2026-96355. Specific vulnerable functionality, attack method, preconditions, and security impact for this CVE are not available.
CVE-2026-96368First seen Sep 24, 2026
CVE-2024-34735 is a high-severity elevation-of-privilege vulnerability in the Android Framework. It affects Android 12, Android 12L, and Android 13 devices that have not received the August 2024 security update.
CVE-2024-34735First seen Mar 18, 2026
CVE-2024-6993 is an inappropriate implementation vulnerability in the Canvas component of Google Chrome and Chromium. Technical details identifying the affected function, root cause, and exploitation mechanism have not been publicly provided in the available information.
CVE-2024-6993First seen Jul 30, 2026