These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,131 reserved CVEs with public mentions, ranked by all-time mention count.
Page 8 of 46
CVE-2024-6992 is a high-severity out-of-bounds memory-access vulnerability in ANGLE, the graphics-translation component used by Google Chrome and Chromium. In affected versions before Chrome 127.0.6533.72, a remote attacker could trigger heap corruption through a crafted HTML page.
CVE-2024-6992First seen Jul 30, 2026
CVE-2026-15264 is an Important-severity vulnerability in QEMU. Available metadata identifies fixes in QEMU 11.1.0-rc3 and 11.0.4, but does not disclose the affected component, vulnerable function, root cause, or a technically reliable exploit path. The reported CVSS v3.1 vector indicates a local, low-complexity attack requiring low privileges and causing high confidentiality, integrity, and availability impact across a changed security scope.
CVE-2026-15264First seen Aug 30, 2026
CVE-2026-63323First seen Aug 30, 2026
CVE-2026-16288 is a QEMU vulnerability described as a Secure Boot bypass. The available information does not identify the affected component, vulnerable function, or precise bypass mechanism. QEMU addressed the issue in upstream releases 11.1.0-rc2 and 11.0.4.
CVE-2026-16288First seen Aug 30, 2026
CVE-2026-59185 is a high-severity cross-tenant authorization bypass in Identrail's GitHub App connection-completion workflow before version 1.0.2. The workflow validates that a pending connection state belongs to the authenticated caller's tenant, workspace, and project, but accepts a client-controlled GitHub App installation identifier without verifying that the installation belongs to the organization authorized for that workspace. The supplied identifier is persisted as the workspace's GitHub connection. Identrail can subsequently use its GitHub App credentials to mint an installation token for that linked installation. The feature-flagged V2 connector path reportedly contains the same unbound installation-identifier flaw and additionally resolves pending connectors by state without fully rechecking caller scope. The weakness is classified as CWE-639 and CWE-862.
CVE-2026-59185First seen Sep 10, 2026
CVE-2026-43603 is a NULL pointer dereference in the AMD GPU Linux kernel driver. The driver may fail to validate an internal data reference before using it when an application invokes a graphics-memory-management clear operation under certain compute-processing conditions. A local user can trigger a kernel failure that crashes the affected system.
CVE-2026-43603First seen Sep 9, 2026
CVE-2026-63320 is a QEMU vulnerability affecting Amazon Linux 2 and Amazon Linux 2023 QEMU packages. It permits unauthenticated network exploitation with an availability-only impact. The underlying vulnerable component and flaw class have not been specified.
CVE-2026-63320First seen Aug 30, 2026
CVE-2026-65928First seen Aug 30, 2026
CVE-2026-45710 is an unauthenticated denial-of-service vulnerability in Mailpit JSON-body API handlers. The affected handlers accept request bodies without enforcing a maximum size; attacker-supplied oversized JSON arrays are parsed and processed, resulting in disproportionate process-memory allocation and additional linear processing and database-update work. The issue affects message read-status updates, message deletion, message-tag updates, and message-release functionality.
CVE-2026-45710First seen Jul 2, 2026
CVE-2023-42219 is an Exim vulnerability associated with DNS resolution handling. It was reported as a limited information-disclosure issue when Exim relies on an untrusted DNS resolver. Available information does not identify the vulnerable function or disclose further technical exploitation mechanics. Some reporting inconsistently identifies this issue as CVE-2023-42119; the advisory mapping associates CVE-2023-42219 with Exim bug 3033.
CVE-2023-42219First seen Apr 14, 2026
CVE-2026-80256 is a Windows-only path traversal vulnerability in wcurl. wcurl percent-decodes output filenames, including percent-encoded backslashes. An attacker-controlled output filename can therefore introduce Windows directory separators after decoding and cause a newly created file to be written outside the directory selected by the user. The behavior affects wcurl bundled with curl 8.14.0 through 8.21.0 and standalone wcurl 2024.12.08 through 2026.01.05.
CVE-2026-80256First seen Sep 2, 2026
First seen Aug 2, 2026
CVE-2022-30267 affects a Distributed Control System that does not authenticate firmware images with cryptographic signatures. Firmware integrity is checked only through insecure checksum mechanisms, which do not establish image origin or provide robust protection against modification. As a result, the system can accept firmware whose authenticity has not been adequately verified.
CVE-2022-30267First seen Mar 18, 2026
First seen Aug 26, 2026
CVE-2014-8273 is a race condition in chipset BIOS write protection enforcement. When an attempt is made to enable BIOS writes despite a protection lock, an interrupt handler detects the condition and resets the write-enable state. The reset is not atomic with detection, creating a timing window in which an attacker can issue BIOS write operations before the write-enable bit is cleared.
CVE-2014-8273First seen Jan 25, 2026
CVE-2025-33143 is an uncontrolled recursion vulnerability in IBM Db2 for Linux, UNIX, and Windows, including Db2 Connect Server. An authenticated user can submit a specially crafted SQL statement that triggers uncontrolled recursive processing, resulting in denial of service. IBM Tivoli Business Service Manager versions 6.2.0.0 through 6.2.0.6 are affected where they include the vulnerable Db2 JDBC driver in the XMLToolkit component.
CVE-2025-33143First seen Aug 22, 2026
CVE-2025-6243 is a credential-management vulnerability in RUCKUS Network Director (RND). The platform contains a built-in user account, sshuser, that has root privileges, and both the public and private SSH keys for that account are stored in the account's home directory. Possession of the private key enables SSH authentication as the built-in privileged user. Because the account is pre-existing and highly privileged, the flaw effectively exposes a built-in administrative access path that can be used to obtain shell access on the affected RND server.
CVE-2025-6243First seen Jan 17, 2026
First seen Feb 4, 2026
CVE-2026-28311 is a critical remote code execution vulnerability in SolarWinds Serv-U file transfer software. It is one of the most severe flaws addressed in Serv-U version 2026.3. Successful exploitation can allow an attacker to execute arbitrary or malicious commands on an affected Serv-U system remotely. Available reporting indicates the broader Serv-U vulnerability set includes access control and privilege-related weaknesses, but specific technical details for the vulnerable component, function, or root cause of CVE-2026-28311 are not currently available.
CVE-2026-28311First seen Jul 22, 2026
First seen Jul 31, 2026
CVE-2025-8094 is a high-severity improper handling of permissions vulnerability in the GitLab Community Edition and Enterprise Edition project API. Under certain conditions, authenticated users with maintainer privileges could manipulate shared infrastructure resources beyond their intended access level through the project API. The flaw stems from insufficient permission enforcement in API operations governing access to shared CI/CD-related infrastructure resources, allowing a maintainer to act outside the intended authorization boundary. GitLab addressed the issue by refining permission checks within the project API to enforce proper access controls.
CVE-2025-8094First seen Jun 12, 2026
CVE-2026-55614 is a high-severity HTTP request smuggling vulnerability in OpenWrt's uhttpd web server on keep-alive connections. The flaw is caused by case-sensitive matching of the Transfer-Encoding header, which can lead to inconsistent interpretation of message framing when different HTTP components in the request path parse the same request differently. This parser discrepancy can desynchronize request boundaries and allow a crafted request to be interpreted as multiple requests or to cause a subsequent request on the same connection to be misframed.
CVE-2026-55614First seen Jun 30, 2026
CVE-2026-55613 is a moderate HTTP request desynchronization vulnerability in OpenWrt's uhttpd web server affecting ubus POST request handling on keep-alive connections. The flaw is triggered when a ubus POST body encounters a parse error, causing request parsing state to become desynchronized rather than cleanly terminating or isolating the malformed request. This can break message boundary handling between successive HTTP requests on the same connection and create a request smuggling condition in front-end/back-end or client/server parsing flows.
CVE-2026-55613First seen Jun 30, 2026
CVE-2026-55612 is a high-severity HTTP request smuggling vulnerability in OpenWrt's uhttpd web server. The flaw affects request processing on keep-alive connections and is caused by an invalid reset of parser state related to chunk-length handling during HTTP message framing. This can cause uhttpd to misinterpret request boundaries when processing chunked request bodies, leading to front-end/back-end desynchronization conditions. In deployments where uhttpd is reachable by an attacker, a crafted sequence of HTTP requests can be used to smuggle a second request across a persistent connection and have it processed out of sync with the visible request stream.
CVE-2026-55612First seen Jun 30, 2026
CVE-2026-53920 is a high-severity information disclosure vulnerability in OpenWrt's odhcpd DHCPv6 service. The flaw is triggered when odhcpd processes a truncated DHCPv6 IA_NA or IA_PD option, leading to disclosure of stack memory. The issue affects the DHCPv6 Identity Association handling path in a default-enabled core network service and is reachable by a network-adjacent attacker able to send crafted DHCPv6 traffic to the target device.
CVE-2026-53920First seen Jun 30, 2026