These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,106 reserved CVEs with public mentions, ranked by all-time mention count.
Page 13 of 45
NLTK before 3.10.3 incompletely validates JVM arguments supplied through the per-call options parameter of nltk.internals.java(). User-controlled java_options passed by GenericStanfordParser, StanfordTagger, StanfordTokenizer, or StanfordSegmenter can bypass the intended JVM-option validation, allowing injection of arbitrary JVM flags.
CVE-2026-12841First seen Sep 2, 2026
CVE-2026-61476 is a medium-severity vulnerability affecting QEMU packages. The available technical information does not identify the vulnerable function or flaw class. Upstream fixes are present in QEMU v11.0.4 and v11.1.0-rc2. Amazon Linux identifies its affected qemu packages in Amazon Linux 2 Core and Amazon Linux 2023 as awaiting fixes; Amazon Linux 2 Core qemu-guest-agent and qemu-kvm packages are not affected.
CVE-2026-61476First seen Aug 30, 2026
CVE-2026-61405First seen Aug 30, 2026
CVE-2026-58581First seen Aug 30, 2026
CVE-2026-58582 is a medium-severity vulnerability in QEMU. Technical details identifying the affected component or vulnerable function are not currently available. Upstream fixes are included in QEMU v11.0.4 and v11.1.0-rc2.
CVE-2026-58582First seen Aug 30, 2026
CVE-2026-27110 is an improper access-control vulnerability in Dell AppSync versions 4.6.0.4 and 4.6.1.0. A remotely accessible low-privileged authenticated attacker can exploit the flaw without user interaction to bypass protection mechanisms and obtain unauthorized access. The vulnerability has a CVSS v3.1 base score of 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
CVE-2026-27110First seen Aug 31, 2026
CVE-2026-28258 is an improper authorization vulnerability in Dell AppSync versions 4.6.0.4 and 4.6.1.0. Insufficient authorization enforcement allows a remotely authenticated low-privileged attacker to access functionality or resources without the intended authorization, resulting in unauthorized access.
CVE-2026-28258First seen Aug 31, 2026
CVE-2026-28257 is an improper authorization vulnerability in Dell AppSync versions 4.6.0.4 and 4.6.1.0. An authenticated remote attacker with low privileges can exploit insufficient authorization enforcement to obtain unauthorized access. The vulnerability is rated CVSS v3.1 7.6 (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L).
CVE-2026-28257First seen Aug 31, 2026
CVE-2026-77682First seen Aug 22, 2026
CVE-2026-81501First seen Aug 28, 2026
CVE-2026-81500First seen Aug 28, 2026
First seen Aug 11, 2026
CVE-2026-44701 is a low-severity cross-site scripting vulnerability in devcode-it/openstamanager. The application accepts unsanitized user-group name input and renders it in the interface without context-appropriate HTML encoding. A privileged user who can create or modify groups can inject arbitrary HTML into group-related views.
CVE-2026-44701First seen Aug 26, 2026
First seen Aug 26, 2026
CVE-2026-63124 is an infinite-loop denial-of-service vulnerability in io.netty.incubator:netty-incubator-codec-bhttp prior to 0.0.23.Final. The Binary HTTP parser can fail to advance or terminate when parsing a known-length field section that ends exactly at a complete field-line boundary. A crafted Binary HTTP input can cause BinaryHttpParser or BinaryHttpDecoder to repeatedly process the boundary condition without making progress. The issue is associated with CWE-835 (loop with unreachable exit condition) and CWE-400 (uncontrolled resource consumption).
CVE-2026-63124First seen Aug 21, 2026
CVE-2023-43020 is a denial-of-service vulnerability in IBM Db2 for Linux, UNIX and Windows, including Db2 Connect Server. A low-privileged authenticated user can submit a specially crafted database query that causes a high availability impact. Affected supported releases include Db2 10.5.0.11, 11.1.4.7, and 11.5.x on supported Linux, AIX, Windows, HP-UX, and Solaris platforms. Earlier unsupported Db2 releases may also be affected.
CVE-2023-43020First seen Aug 22, 2026
CVE-2024-50604 is an improper validation of integrity check value vulnerability in RUCKUS FastIron firmware used by the RUCKUS ICX switch product line. The issue is described as insufficient validation for a software component integrity check, indicating that the firmware does not adequately verify integrity metadata associated with software components. In the documented attack scenario, this weakness can be combined with CVE-2024-50607, a directory traversal vulnerability, to enable malware injection on vulnerable ICX switches. The affected scope includes multiple ICX firmware branches across the 08.0.95r, 09.0.10j, 10.0.10f, and 10.0.20b release lines.
CVE-2024-50604First seen Aug 22, 2026
CVE-2024-50607 is a directory traversal vulnerability in RUCKUS FastIron firmware used by the RUCKUS ICX switch product line. The flaw is classified as a path traversal issue and affects multiple ICX firmware branches. Available information indicates that, in combination with CVE-2024-50604, the vulnerability can be used by an authenticated attacker with physical access to facilitate malware injection on vulnerable switches. Specific details about the affected function or code path are currently not available.
CVE-2024-50607First seen Aug 22, 2026
CVE-2017-17768First seen Aug 22, 2026
CVE-2026-2574 is a memory-safety vulnerability in glib-networking affecting the OpenSSL backend used for TLS connections. A malicious TLS server can exploit the flaw when a client connects and the server advertises a specially crafted client certificate authority list during the handshake. This malformed input can cause the client to read memory outside the bounds of an allocated buffer and then free memory incorrectly. The issue is therefore characterized by an out-of-bounds read coupled with invalid memory deallocation in TLS handshake processing, which can crash the client and may expose a limited amount of heap memory.
CVE-2026-2574First seen Aug 23, 2026
CVE-2026-78332 is a stored cross-site scripting vulnerability in the contacts component of NethServer WebTop. It affects WebTop version 1.5.6 and earlier. The flaw allows malicious content to be stored in contact data and later rendered in another user's browser, resulting in execution of attacker-supplied JavaScript when the affected contact is viewed. The issue was fixed in WebTop 1.5.7.
CVE-2026-78332First seen Aug 24, 2026
CVE-2026-78331 is a stored cross-site scripting vulnerability in the calendar component of NethServer WebTop. The issue affects WebTop version 1.5.6 and earlier and allows malicious content to be stored within calendar data. When another user later views the crafted calendar event, attacker-supplied JavaScript executes in that user's browser within the context of the application.
CVE-2026-78331First seen Aug 24, 2026
CVE-2021-27745 is a server-side request forgery vulnerability in HCL Digital Experience associated with the Quickr Document Picker component. The issue affects an internal proxy entry point exposed by that enterprise application, allowing attacker-supplied requests to be relayed by the server. In vulnerable deployments, an unauthenticated remote attacker can cause the HCL Digital Experience server to initiate outbound requests to attacker-chosen destinations, resulting in SSRF through the affected application path.
CVE-2021-27745First seen Aug 23, 2026
CVE-2020-14282 is a broken access control vulnerability in HCL Digital Experience affecting versions 8.5, 9.0, and 9.5. The flaw allows anonymous, unauthenticated users to access limited access-control data and may expose system files and folders that should not be available without authorization. The exposed access is described as read-only, and anonymous users cannot use it to grant permissions or modify access settings. The issue stems from improper enforcement of authorization restrictions on resources that should require authenticated access.
CVE-2020-14282First seen Aug 23, 2026
First seen Jul 5, 2026