These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,106 reserved CVEs with public mentions, ranked by all-time mention count.
Page 15 of 45
CVE-2026-57187 is a heap use-after-free vulnerability in Asterisk's PJSIP handling of TCP/SDP state when a connection-oriented SIP session is closed during SDP processing. According to the advisory, an authenticated attacker can trigger the flaw by sending a SIP INVITE over a connection-oriented transport such as TCP and then disconnecting before Asterisk sends its 200 OK response. This can result in dereferencing freed heap memory during the lifetime management of resources associated with SDP processing. The issue is mapped to CWE-416 and also associated with improper resource lifetime control. The advisory notes that the crash has only been reproducible when Asterisk is built with Address Sanitizer enabled.
CVE-2026-57187First seen Jun 26, 2026
First seen Jul 1, 2026
CVE-2026-52717 is an incorrect memory management vulnerability in the ffmpeg plugin shipped with GStreamer via the gst-libav1.0 package. According to the provided advisory context, the flaw can result in heap memory corruption during processing in the plugin. Specific vulnerable functions, code paths, and trigger conditions were not provided in the available content.
CVE-2026-52717First seen Jun 19, 2026
First seen Jun 17, 2026
CVE-2025-55662 is a divide-by-zero vulnerability in GPAC/MP4Box affecting gpac/gpac prior to fix commit ff8249a407685d00ceb5f4d2a798b9cad195140e. The flaw is in gf_opus_parse_packet_header() in media_tools/av_parsers.c while processing an MP4 file containing an Opus audio track with malformed packet or header parameters. Specifically, critical Opus packet fields such as nb_frames are not validated before being used in arithmetic; the available reporting notes logic equivalent to computing values derived from header->nb_frames without first ensuring the field is non-zero and otherwise valid. When MP4Box reaches the Opus dump path on a crafted file, this can trigger a division by zero and terminate the process with a floating-point exception, with published traces pointing to media_tools/av_parsers.c:11479 and call paths including gf_inspect_dump_opus_internal() and dump_isom_opus().
CVE-2025-55662First seen Jun 13, 2026
CVE-2025-61620 is described in the provided content only as a denial-of-service vulnerability in vLLM involving chat template handling. The content states it affects the same general attack surface as later template-rendering issues, but does not provide specific technical details such as the vulnerable function, affected versions, exact trigger condition, or patch information for this CVE.
CVE-2025-61620First seen Apr 20, 2026
CVE-2023-47399 affects Nagios XI and allows the Nagios XI database user (`nagiosxi`) to update or delete records in the `xi_auditlog` table. Based on the provided advisory context, the issue is not a memory corruption or code execution flaw but an authorization and integrity weakness in database privilege design: the application database account was granted full CRUD capabilities over audit log records when audit data should be append-only or otherwise protected from modification and deletion. This undermines the trustworthiness of Nagios XI audit logging because actions recorded for administrative and security-relevant events can be altered or removed by an attacker who gains the ability to act through that database user or abuse application functionality that uses it.
CVE-2023-47399First seen May 31, 2026
CVE-2023-47405 is a vulnerability in Nagios XI affecting at least version 5.11.1 in which the installer creates multiple MySQL database accounts with weak default credentials. According to the provided advisory context, a fresh installation creates at least three database users—nagiosxi, nagiosql, and ndoutils—using the password "n@gweb". This results in predictable, low-entropy credentials being present by default for backend database access.
CVE-2023-47405First seen May 31, 2026
Nagios XI before 5.11.4 stored sensitive credentials and tokens in plaintext in the `xi_options` database table. According to the provided context, this affected credentials supplied in Inbound/Outbound Transfer settings and exposed NRDP, NSCA, SMTP, and related transfer credentials without encryption or adequate protection at rest. The issue is an insecure storage flaw in which application secrets that should be protected were persisted directly in database records in recoverable plaintext form.
CVE-2023-47402First seen May 31, 2026
CVE-2023-47400 is a high-severity remote code execution vulnerability in the Nagios XI Custom Includes feature affecting Nagios XI v5.11.1. According to the provided context, the protection model for Custom Includes could be bypassed by overwriting or removing the .htaccess file that was intended to prevent execution of uploaded content, and then uploading a PHP payload disguised with an allowed filename or extension pattern such as "exploit.jpg.php". Once the uploaded file was reachable over the web interface, the attacker could request it directly and cause the embedded PHP code to execute on the Nagios XI server. The issue is therefore an unrestricted or insufficiently restricted file upload condition combined with ineffective server-side execution controls in the upload location.
CVE-2023-47400First seen May 31, 2026
CVE-2023-47401 is a critical remote code execution vulnerability in Nagios XI, affecting the migration feature in versions including 5.11.1. According to the provided content, the migration page at /nagiosxi/admin/migrate.php passes attacker-supplied IP address, username, and password values to a PHP migration script executed via sudo as root. A high-privileged attacker can inject attacker-controlled Ansible playbook or vault content into this workflow. Because the injected YAML can invoke Ansible functionality such as lookup("pipe", ...), arbitrary shell commands can be executed on the Nagios XI server with root privileges. The issue is described as an Ansible vault file injection flaw in the migration feature and was mitigated in Nagios XI 5.11.4.
CVE-2023-47401First seen May 31, 2026
CVE-2023-47411 is a destructive vulnerability in Nagios XI affecting the backup_xi.sh backup script. According to the provided context, the flaw is caused by unsafe handling of attacker-controlled name and directory parameters in backup_xi.sh. An attacker who can control inputs passed to this script can influence the path operated on by a root-executed recursive deletion routine, resulting in behavior described as directly equivalent to executing `rm -rf /`. The issue therefore allows attacker-influenced filesystem path control in a privileged maintenance script, turning a backup-related operation into arbitrary recursive deletion of filesystem content as root. The advisory context states this issue was mitigated in Nagios XI version 5.11.4.
CVE-2023-47411First seen May 31, 2026
CVE-2023-47412 is an authorization flaw in the Nagios XI usermacros component affecting Nagios XI v5.11.1. According to the provided advisory context, any authenticated user could send crafted HTTP requests directly to the usermacros endpoint to access functionality intended to manage user and system macros. The issue allowed low-privileged authenticated users to view or modify user macros and system macros without proper privilege enforcement. The advisory further states that an authenticated user could overwrite the /usr/local/nagios/etc/resource.cfg macros file through these requests. Where macro redaction was disabled, sensitive macro values could also be disclosed directly.
CVE-2023-47412First seen May 31, 2026
CVE-2023-47410 is a stored cross-site scripting vulnerability in Nagios XI, affecting the admin user management page in versions including 5.11.1. According to the provided context, the flaw is caused by unsafe concatenation/insertion of usernames into inline JavaScript in the Manage Users / Admin’s User Management interface. A malicious username containing JavaScript can be stored by the application and later rendered in the administrative page without proper output encoding, causing the payload to execute in the victim administrator’s browser when the page is viewed. The issue was mitigated by Nagios in version 5.11.4.
CVE-2023-47410First seen May 31, 2026
CVE-2023-47409 affects Nagios XI's migration process. Migration job files stored encrypted Ansible vault data containing credentials for remote hosts, but the vault passwords were generated predictably using PHP uniqid(). The advisory states that these encrypted migration job files were not deleted after completion, allowing an attacker with local root access on the Nagios XI server to recover the files and brute-force the vault passwords offline. Successful recovery exposes privileged credentials for remote machines involved in migration operations.
CVE-2023-47409First seen May 31, 2026
CVE-2023-47414 is a local privilege escalation vulnerability in Nagios XI, affecting the send_to_nls.php functionality that generates rsyslog configuration files. According to the provided content, attacker-controlled input was not sanitized before being written into new rsyslog configuration content. This allowed a local attacker to inject arbitrary rsyslog directives, including omprog, into generated rsyslog files. Because rsyslog would subsequently process that injected configuration, the attacker could cause execution of attacker-controlled commands in the security context of the syslog user. The issue was reported in Nagios XI v5.11.1 and was mitigated in Nagios XI v5.11.4.
CVE-2023-47414First seen May 31, 2026
CVE-2023-47406 is an information disclosure issue in Nagios XI affecting the Scheduled Backups FTP connectivity test functionality. According to the provided context, the feature exhibits a discrepancy in error-message timing depending on whether a target port is open or closed. An attacker can abuse these timing differences to infer port state and perform time-based port scanning against the Nagios XI server itself, including localhost, and potentially internal network hosts reachable from the server. The issue was reported in Nagios XI v5.11.1 and was mitigated in version 5.11.4.
CVE-2023-47406First seen May 31, 2026
CVE-2023-47407 is an information exposure vulnerability in Nagios XI affecting at least version 5.11.1. Sensitive files on the Nagios XI host were readable by all local users. Specifically, /usr/local/nagiosxi/html/config.inc.php contained plaintext database credentials and was world-readable, and /usr/local/nagiosxi/etc/htpasswd.users was also world-readable and exposed SHA1 password hashes for Nagios XI accounts. The issue is caused by overly permissive filesystem permissions on credential-bearing files, allowing unauthorized local users to read secrets that should be restricted to privileged service accounts or administrators.
CVE-2023-47407First seen May 31, 2026
Nagios XI before 5.11.4 contains an arbitrary file editing issue in the Graph Templates editor. According to the provided advisory context, an administrator using the Graph Editor/Graph Templates page could edit unintended files in the parent directory, including PHP files such as index.php, ajax.php, and zoom.php. The flaw stems from insufficient restriction of file paths accessible through the editor, allowing modification of files outside the intended template scope.
CVE-2023-47413First seen May 31, 2026
CVE-2023-47408 is a high-severity command injection vulnerability in the Nagios XI Host Configuration page affecting Nagios XI v5.11.1. According to the provided context, an administrator can inject commands on the Nagios XI server by entering shell commands surrounded by backticks into host/service argument input fields such as $ARG1$ and $ARG2$. The flaw is described as occurring in the Host Configuration workflow, where attacker-controlled argument values are later processed in a way that results in command execution on the Nagios server.
CVE-2023-47408First seen May 31, 2026
CVE-2023-47403 is an authorization flaw in Nagios XI affecting the Missing Objects page. According to the provided context, the page and its associated functionality were accessible to all authenticated users, regardless of whether they held administrator privileges. This indicates missing authorization checks on functionality intended to be restricted to administrators. As a result, a low-privileged authenticated user could access the Missing Objects page and perform actions reserved for administrative users.
CVE-2023-47403First seen May 31, 2026
CVE-2026-40710 is a use of hard-coded credentials vulnerability in Dell Container Storage Modules. According to the provided advisory context, default authentication credentials were exposed in public source code, allowing an attacker who knows or can obtain those credentials to authenticate to affected components. The issue stems from embedded default credentials rather than environment-specific secrets management, creating a condition where unauthorized parties can access sensitive system components.
CVE-2026-40710First seen May 28, 2026
First seen May 5, 2026
First seen May 3, 2026
CVE-2026-35333 is a vulnerability in libradius affecting the processing of RADIUS attributes. According to the provided context, malformed or otherwise crafted RADIUS attributes can trigger either an infinite loop condition or an out-of-bounds read during attribute parsing. The out-of-bounds read may lead to process instability or a crash. Specific vulnerable functions, affected versions, and protocol field details are not available in the provided information.
CVE-2026-35333First seen Apr 22, 2026