These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,106 reserved CVEs with public mentions, ranked by all-time mention count.
Page 14 of 45
First seen Jul 5, 2026
First seen Jul 5, 2026
HCL Launch contains a vulnerability in which a manually edited keystore password used by the agent relay component is stored in clear text after restart. This results in insufficient protection of sensitive credentials at rest, allowing a local user with access to the affected system to read the stored password directly. The issue is a cleartext storage weakness affecting credential handling rather than a memory disclosure or cryptographic bypass.
CVE-2020-14267First seen Aug 23, 2026
CVE-2021-27666 is a high-severity information disclosure vulnerability in the Android telecommunication/modem component. Successful exploitation can lead to remote disclosure of sensitive information. The available information indicates that the issue is remotely reachable and does not require additional execution privileges. Specific details about the vulnerable function or code path are not available from the provided material.
CVE-2021-27666First seen Aug 22, 2026
CVE-2015-1509 is a reflected cross-site scripting vulnerability in Intland Software codeBeamer, reported in version 7.3.2-201410071117. The flaw allows arbitrarily supplied request parameters to be reflected by a web-accessible application component without sufficient sanitization or output encoding, enabling attacker-controlled script content to execute in a victim user's browser within the application's security context.
CVE-2015-1509First seen Aug 20, 2026
CVE-2015-1508 is a blind time-based SQL injection vulnerability in Brainworks Software XpanceNET affecting version 7.3.27 and earlier. The flaw is present in the UserID parameter, including in password-change request functionality, where insufficient neutralization of attacker-controlled input allows crafted SQL expressions to be processed by the backend database. Because the issue is blind and time-based, successful exploitation is inferred through response timing differences rather than direct error messages or query output. Depending on the privileges available to the application’s database context, the vulnerability can enable unauthorized interaction with the underlying database.
CVE-2015-1508First seen Aug 20, 2026
CVE-2014-6285 is a privilege escalation vulnerability in SAP Adaptive Server Enterprise (ASE) caused by an SQL injection flaw in replication support code. ASE contains an implementation flaw that allows SQL statements supplied through replication-related functionality to be executed without normal security checks. The issue affects users granted replication-related privileges and enables injected SQL to run in a more privileged context than intended. As a result, an authenticated user can abuse the vulnerable code path to elevate privileges within the database server, including escalation to administrative database roles.
CVE-2014-6285First seen Aug 20, 2026
CVE-2016-4013 is a SQL injection vulnerability in SAP Adaptive Server Enterprise (ASE) 16.0 SP02 introduced through Data Store Access Management (DSAM) support in CREATE DATABASE and ALTER DATABASE processing. When DSAM is configured, these statements perform additional logic to add specially named segments. A flaw in that implementation allows a low-privileged user to embed T-SQL code into the affected database-management workflow, causing attacker-controlled SQL to be executed with elevated privileges. The issue can lead to full compromise of the ASE server.
CVE-2016-4013First seen Aug 20, 2026
CVE-2016-6196 is an unrestricted file creation vulnerability in SAP Adaptive Server Enterprise. The flaw affects handling of the TRANSFER TABLE statement and allows a user who is permitted to execute that statement, including a table owner, to create files as the database server process owner. By abusing this capability, an attacker can place attacker-controlled files on the host and potentially create and load shared libraries into the database server process, resulting in code execution within the database server context.
CVE-2016-6196First seen Aug 20, 2026
CVE-2015-1413 is a cross-site scripting vulnerability in Magnolia CMS affecting version 5.3.6 Enterprise Edition and Community Edition, and possibly other versions. The flaw allows attacker-controlled script content to be injected into application output and executed in the browser of a user interacting with the vulnerable application. Successful exploitation occurs within the security context of the targeted user's session and can enable unauthorized client-side actions against the CMS.
CVE-2015-1413First seen Aug 20, 2026
CVE-2026-73554 is a critical authentication bypass vulnerability in Dolt MCP affecting versions 0.3.1 through 0.3.6 when deployed with remote HTTP transport and JWT authentication enabled. The flaw arises from two conditions in the request handling chain: JWT rejection logic writes an HTTP 401 response for an invalid token but does not terminate execution because the middleware omits a return statement, and session validation in the underlying mcp-go implementation accepts forged session identifiers matching an expected format without verifying that the session was actually created by the server. By combining an invalid JWT with a crafted session identifier, an unauthenticated attacker can bypass intended access controls, reach the MCP tool dispatcher, and invoke database operations through the server context despite failed authentication. A notable characteristic is that the server may still return HTTP 401 Unauthorized while including the result of the unauthorized operation in the response body.
CVE-2026-73554First seen Aug 16, 2026
CVE-2018-1579 is an authentication bypass vulnerability affecting Palo Alto Networks PAN-OS GlobalProtect portal and gateway functionality. The issue allows an unauthenticated remote attacker to bypass normal authentication controls on exposed VPN infrastructure under affected conditions. Public reporting associates the vulnerability with intrusion activity in which attackers used vulnerable VPN appliances as an initial access vector into enterprise environments.
CVE-2018-1579First seen Aug 14, 2026
First seen Apr 9, 2026
First seen Aug 5, 2026
First seen Aug 3, 2026
CVE-2023-20713First seen May 26, 2026
First seen Jul 31, 2026
CVE-2026-57152First seen Jul 27, 2026
CVE-2026-47678 is one of multiple vulnerabilities fixed in GLPI 10.0.26 and 11.0.8. Affected versions prior to those releases contain a flaw that, in the broader set of patched issues, may contribute to cross-site scripting, SQL injection, security control bypass, data confidentiality and integrity compromise, or privilege escalation. Specific technical details for this individual CVE, including the vulnerable component or function, are currently not available.
CVE-2026-47678First seen Jul 27, 2026
First seen May 26, 2026
CVE-2026-24205 is a medium-severity race condition vulnerability affecting NVIDIA TensorRT-LLM. The flaw occurs when a user runs concurrent database requests, creating a timing-dependent condition in which shared state or resources may be accessed in an unsafe order. In concurrent execution scenarios, improper synchronization can cause inconsistent application behavior and may undermine the integrity or availability of the affected service.
CVE-2026-24205First seen May 27, 2026
CVE-2024-20452 is a critical buffer overflow vulnerability in the web-based management interface of Cisco Small Business SPA 300 and SPA 500 series IP phones. The flaw affects all software releases for the affected products regardless of configuration. A remote, unauthenticated attacker can trigger the vulnerability by sending a specially crafted HTTP request to a vulnerable device, leading to arbitrary command execution on the underlying operating system with root privileges.
CVE-2024-20452First seen May 26, 2026
CVE-2024-20453 is a high-severity vulnerability in the web-based management interface of Cisco Small Business SPA300 Series and SPA500 Series IP phones. The flaw is caused by inadequate validation of HTTP packets processed by the management interface. A remote attacker can send a crafted HTTP packet to a vulnerable device and trigger a denial-of-service condition. Cisco indicated that all software releases for the affected product lines are vulnerable regardless of configuration, and that this issue is independently exploitable from the other disclosed flaws affecting the same devices.
CVE-2024-20453First seen May 26, 2026
CVE-2026-52848First seen Jul 27, 2026
CVE-2026-55606 is a moderate-severity vulnerability in OpenWrt's odhcpd DHCP service. The flaw is a stack buffer over-read caused by an endianness mismatch when handling a DHCP Unique Identifier (DUID) length value. Improper interpretation of the DUID length can cause odhcpd to read beyond the intended bounds of a stack buffer while processing attacker-supplied DHCPv6 data. The issue is reachable by a network-adjacent attacker against the default-enabled odhcpd service in affected OpenWrt releases prior to the fixed 25.12.5 update.
CVE-2026-55606First seen Jun 30, 2026