These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,186 reserved CVEs with public mentions, ranked by all-time mention count.
Page 11 of 48
CVE-2021-35404 is an authenticated OS command injection vulnerability in the Prolink PRC2402M router, observed on firmware version 20190909. The flaw is in the /cgi-bin/applogin.cgi CGI handler. When the api parameter is set to app, applogin.cgi invokes sys_login1, which retrieves user-controlled parameters including ipaddr, password, and lang. After validating the supplied password against the expected MD5 value, the code constructs a shell command using sprintf and executes it via do_system, a wrapper around system. Because the ipaddr and lang parameters are incorporated into the shell command without proper validation or sanitization, an authenticated attacker can inject shell metacharacters and execute arbitrary commands. The injected commands run in the context of the root user.
CVE-2021-35404First seen Apr 11, 2026
First seen Mar 18, 2026
A reflected cross-site scripting (XSS) vulnerability exists in Invision Community software, specifically in the /oauth/callback/index.php script. The vulnerability is present in certain 4.x versions before 4.7.21 and all 5.x versions before 5.0.8. It arises due to insufficient sanitization of user input passed via the 'state' POST parameter, allowing attackers to inject and execute arbitrary JavaScript in the context of a victim's browser if they can trick the victim into submitting a crafted request.
CVE-2025-48933First seen Mar 18, 2026
CVE-2026-19584 is a VQL injection vulnerability in Rapid7 Velociraptor affecting notebook backup restoration. Velociraptor’s default-enabled daily notebook backup feature can create backups containing notebook cell content. During restore, notebook cell content is interpolated into a template without access control checks, allowing attacker-controlled VQL embedded in a notebook cell to be evaluated in a higher-privilege context. A malicious user with NOTEBOOK_EDITOR permission can therefore plant a query in notebook content that is later executed with elevated permissions when the backup is restored.
CVE-2026-19584First seen Aug 24, 2026
First seen Aug 24, 2026
CVE-2024-21965 is an improper access control vulnerability in the AMD IOMMU. The flaw could allow an attacker to modify Secure Nested Paging (SNP) configuration settings. By altering these settings, an attacker may be able to write to guest memory that is intended to remain protected, undermining isolation guarantees for protected virtual machines and trusted execution environments.
CVE-2024-21965First seen Aug 23, 2026
CVE-2019-4328 is an XML External Entity vulnerability in HCL AppScan Enterprise affecting multiple XML-processing locations. The flaw is triggered when a user opens, imports, or uploads a specially crafted XML file. Improper handling of external entities allows attacker-controlled XML content to cause the application to resolve external entity references and access local resources available to the victim context. As a result, local file contents readable by the victim can be disclosed and transmitted to an attacker-controlled remote system.
CVE-2019-4328First seen Aug 23, 2026
CVE-2023-39904 is a cross-site scripting vulnerability in the web-based management interface of the RUCKUS ICX product line. The flaw allows a remote attacker to deliver crafted input, including via a crafted link, that is processed by the management interface in a way that can execute attacker-controlled script in the victim user's browser session. The issue affects administrative interaction with the device through the web interface and can be used in conjunction with user access to the management console.
CVE-2023-39904First seen Aug 23, 2026
CVE-2023-39906 is a cross-site request forgery vulnerability in the web-based management interface of the RUCKUS ICX product line. The flaw allows a remote attacker to induce an authenticated user of the management interface to submit unintended requests to the affected device, typically by luring the user to a crafted link or attacker-controlled web content while the user has an active session to the interface. Successful exploitation causes requests to be processed in the security context of the victim user’s authenticated session.
CVE-2023-39906First seen Aug 23, 2026
CVE-2023-39905 is a cross-site request forgery vulnerability in the web-based management interface of the RUCKUS ICX product line. The flaw allows a remote attacker to induce an authenticated user of the management interface to submit unintended requests to the affected device through crafted content, causing actions to be performed within the context of the victim's active session. The issue affects the administrative web interface rather than the switching plane itself.
CVE-2023-39905First seen Aug 23, 2026
First seen Aug 23, 2026
First seen Aug 23, 2026
First seen Aug 23, 2026
CVE-2021-27744 is a cross-site scripting vulnerability in a default portlet in HCL Digital Experience. The issue can be triggered via a crafted URL, indicating insufficient neutralization or encoding of untrusted input before it is reflected or rendered in a browser context. Affected HCL Digital Experience versions include 8.5, 9.0, and 9.5.
CVE-2021-27744First seen Aug 23, 2026
CVE-2021-27740 is an improper access control vulnerability in HCL Digital Experience affecting versions 8.5, 9.0, and 9.5. Anonymous users can obtain elevated access when creating projects through a specific interface, indicating that authorization checks for project-creation operations are insufficient or incorrectly enforced for unauthenticated users. The issue allows users without the intended privileges to perform project-creation actions that should be restricted.
CVE-2021-27740First seen Aug 23, 2026
CVE-2020-14261 is a content spoofing vulnerability affecting HCL Campaign in deployments where the HCL Marketing Platform login method is configured to use Web Access Control. The issue does not affect environments using the default login method. Successful exploitation allows an attacker to cause spoofed content to be presented within the affected application context, undermining trust in displayed content and enabling deceptive interactions.
CVE-2020-14261First seen Aug 23, 2026
CVE-2016-5887 is a cross-site scripting vulnerability in iNotes, the web-based mail interface associated with Domino. The flaw allows arbitrary JavaScript to be embedded and executed within the iNotes web UI, causing the application to render attacker-controlled script in the context of a trusted user session. Successful exploitation can alter intended application behavior and expose sensitive session data, including user credentials, to an attacker.
CVE-2016-5887First seen Aug 23, 2026
CVE-2016-5886 is a cross-site scripting vulnerability in iNotes, the web-based mail interface associated with Domino. The flaw allows arbitrary JavaScript to be embedded and executed within the iNotes web UI, causing the application to render attacker-controlled script in the context of a trusted user session. Successful exploitation can alter intended application functionality and expose sensitive session data, including user credentials, through script execution in the victim's browser.
CVE-2016-5886First seen Aug 23, 2026
CVE-2020-14266 is an information disclosure vulnerability in HCL Launch, formerly IBM UrbanCode Deploy. Under affected versions, keystore passwords can remain stored in plaintext after a manual edit rather than being re-encrypted. This exposes sensitive credential material to local users who can access the relevant configuration or stored data on the host. The flaw is a cleartext storage issue affecting protection of secrets at rest.
CVE-2020-14266First seen Aug 23, 2026
First seen Aug 23, 2026
First seen Aug 22, 2026
First seen Aug 22, 2026
First seen Aug 22, 2026
First seen Aug 22, 2026
First seen Aug 22, 2026