These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,109 reserved CVEs with public mentions, ranked by all-time mention count.
Page 10 of 45
CVE-2026-65140 affects Slurm Workload Manager (slurm-wlm), a cluster resource management and job scheduling system. Affected distribution listings include Ubuntu 22.04, 24.04, and 26.04 LTS and Debian 12, 13, and 14. The specific weakness, vulnerable function, affected package version ranges, and exploitation mechanism are currently unavailable.
CVE-2026-65140First seen Sep 4, 2026
CVE-2026-65109First seen Sep 4, 2026
First seen Sep 4, 2026
First seen Sep 11, 2026
First seen Sep 4, 2026
CVE-2026-65107 is a remotely reachable denial-of-service vulnerability affecting Slurm Workload Manager packages on Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS, and Debian 12, 13, and 14. Exploitation requires neither privileges nor user interaction. The underlying defect, affected function, precise package-version ranges, and triggering input are not identified.
CVE-2026-65107First seen Sep 4, 2026
First seen Sep 4, 2026
CVE-2025-58363 is a path traversal vulnerability in LF Edge eKuiper administrative plugin-installation endpoints. Unsanitized, user-controlled plugin resource names are used in filesystem deletion operations, allowing traversal outside the intended plugin-resource location. An authenticated or otherwise authorized caller of the eKuiper management API can cause deletion of files or directories accessible to the eKuiper process.
CVE-2025-58363First seen Sep 10, 2026
CVE-2026-55480 is an unpatched vulnerability affecting the cups package on Debian Linux. The associated package-detection configuration lists Debian Linux 12.0, 13.0, and 14.0. Detection relies on vendor-reported package presence rather than demonstrated exploitation. The vulnerable function, underlying flaw, and affected package versions are not specified. No known exploits are identified.
CVE-2026-55480First seen Oct 6, 2026
CVE-2017-1135 is a vulnerability in the RadAsyncUpload component of Telerik UI for ASP.NET AJAX, where user input is used directly without validation, resulting in an insecure direct object reference. This flaw allows attackers to upload arbitrary files to a restricted location on the server, potentially leading to remote code execution. The vulnerability is related to cryptographic weaknesses and unrestricted file upload issues, and is associated with other vulnerabilities such as CVE-2019-18935 and the Blue Mockingbird campaign.
CVE-2017-1135First seen Oct 5, 2026
CVE-2026-92705 is an arbitrary code execution vulnerability in Aegisub's handling of ASS subtitle files containing associated Automation script references. Opening a crafted subtitle file can cause arbitrary code to execute through those references. Aegisub 3.5.0 addresses the vulnerability by requiring confirmation before loading associated scripts, aligning extension validation with filesystem path interpretation, and sanitizing embedded NUL characters in project metadata.
CVE-2026-92705First seen Oct 5, 2026
CVE-2026-12074 is a path traversal vulnerability in Natural Language Toolkit (NLTK)'s FramenetCorpusReader.frame() method. Attacker-controlled input can cause XML files outside the intended corpus root to be read, bypassing the nltk.pathsec sandbox even when ENFORCE=True. Related doc() and lexical-unit loading code paths may also be reachable through a malicious or attacker-modified FrameNet corpus index. The vulnerability is fixed in NLTK 3.10.0.
CVE-2026-12074First seen Aug 1, 2026
CVE-2026-61813 concerns a weak libcurl TLS hostname-verification setting when fetching resources over HTTPS. The Debian modsecurity-apache package is identified as affected on Debian Linux 12.0, 13.0, and 14.0. Inadequate hostname verification can allow acceptance of a TLS certificate that does not authenticate the intended server hostname. The precise setting, vulnerable function, and affected package-version boundaries are not available.
CVE-2026-61813First seen Oct 1, 2026
CVE-2026-53615 is an integer overflow vulnerability in the DOS partition-table parser of libblkid, part of util-linux. Processing a crafted block-device image may trigger the vulnerability and cause denial of service. The specific vulnerable function and affected upstream version range are not established.
CVE-2026-53615First seen Jun 18, 2026
CVE-2026-12876 is an uncontrolled resource consumption vulnerability in NLTK's RecursiveDescentParser and SteppingRecursiveDescentParser. Processing ambiguous or left-recursive context-free grammars can cause unbounded CPU consumption or Python recursion-stack exhaustion. An attacker who can supply a grammar or input to an affected parser can cause denial of service in the parsing process.
CVE-2026-12876First seen Sep 4, 2026
CVE-2026-73857 concerns dereferencing an uninitialized parser context pointer in the mod_security XML request body processor, with potential denial-of-service consequences. Debian Linux 12.0, 13.0, and 14.0 are listed as affected, although affected mod_security versions are not specified. The listed mod_security packages for Amazon Linux 2 Core, Amazon Linux 2023, and Amazon Linux 2027 Preview are explicitly marked not affected.
CVE-2026-73857First seen Oct 1, 2026
CVE-2026-48002 affects QEMU packages and is addressed by an Echo security update. It is also referenced in Oracle Linux 9 security advisory ELSA-2026-500220. The underlying flaw, affected function, and exploitation mechanism are currently not available.
CVE-2026-48002First seen Aug 24, 2026
CVE-2026-73856 is a response body inspection bypass in ModSecurity involving non-canonical Content-Type casing. Responses using such casing may evade body inspection, undermining response-side security enforcement. The affected ModSecurity versions and vulnerable function are not specified. The mod_security packages in Amazon Linux 2 Core, Amazon Linux 2023, and Amazon Linux 2027 Preview are identified as not affected.
CVE-2026-73856First seen Oct 1, 2026
CVE-2026-61812 is a security-filter evasion vulnerability in ModSecurity's HTML decoder. Missing support for HTML entities can allow encoded input to evade security filtering. An unauthenticated remote attacker could exploit the incomplete decoding to bypass filtering and affect integrity. The affected package is identified as mod_security on Amazon Linux and modsecurity-apache on Debian; Amazon Linux identifies httpd itself as unaffected.
CVE-2026-61812First seen Oct 1, 2026
CVE-2026-39043 affects gst-plugins-good1.0, part of the GStreamer media framework. It is addressed by a security update covering multiple vulnerabilities in plugins, codecs, and demuxers involving malformed media files. These vulnerabilities may cause denial of service or potentially arbitrary code execution. The specific defect, vulnerable function, and individual impact of CVE-2026-39043 are not established.
CVE-2026-39043First seen Jun 21, 2026
CVE-2026-8343 affects QEMU packages and is included in Oracle Linux 9 security advisory ELSA-2026-500220. The underlying flaw, vulnerable function, and exploitation mechanism are currently not available.
CVE-2026-8343First seen Aug 24, 2026
CVE-2026-16043 affects QEMU packages and is addressed by QEMU package updates, including Oracle Linux 9 security update ELSA-2026-500245. Technical details about the underlying flaw, vulnerable subsystem, and exploitation mechanism are currently not available.
CVE-2026-16043First seen Sep 8, 2026
CVE-2026-15578 affects QEMU packages and is associated with an availability impact. The vulnerable function, underlying weakness, triggering input, and affected version range are currently unavailable.
CVE-2026-15578First seen Sep 8, 2026
CVE-2026-12061 is a regular expression denial-of-service vulnerability in NLTK's ReviewsCorpusReader. The FEATURES regular expression exhibits quadratic backtracking when processing a crafted, long review line without brackets. This can hang reviews(), features(), and sents(), exhausting CPU resources and stalling applications that process attacker-controlled reviews corpora. NLTK 3.10.0 fixes the issue by bounding the per-label word run in the regular expression.
CVE-2026-12061First seen Aug 1, 2026
CVE-2026-39044 affects the GStreamer gst-plugins-good1.0 package. It belongs to a group of vulnerabilities in GStreamer plugins, codecs, and demuxers involving malformed media files that may cause denial of service or potentially arbitrary code execution when opened. The specific affected component, vulnerable function, root cause, and individual impact of CVE-2026-39044 are not established.
CVE-2026-39044First seen Jun 21, 2026