These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,178 reserved CVEs with public mentions, ranked by all-time mention count.
Page 17 of 48
CVE-2016-5088 is an information disclosure vulnerability in SAP Adaptive Server Enterprise (ASE) affecting ASE 16.0 SP02 PL02 and earlier. During installation, the installer logs the SCC repository password in cleartext to an installation properties file under the SYBASE home directory. Because this file is publicly readable, an unprivileged local user can recover the stored SCC repository credential and use it to access the SCC repository.
CVE-2016-5088First seen Aug 20, 2026
CVE-2017-18181 is an arbitrary file deletion vulnerability in the nas_sharing.cgi CGI component of Western Digital My Cloud personal cloud storage devices prior to firmware version 2.30.172. The vulnerable CGI binary accepts a path parameter that can be used to target files on the device for deletion without proper restriction or authorization enforcement. As a result, an attacker can cause deletion of arbitrary files on the underlying system, which can affect device integrity and availability and may contribute to broader device compromise when combined with other weaknesses.
CVE-2017-18181First seen Aug 20, 2026
CVE-2017-18182 is a hardcoded credential vulnerability in Western Digital My Cloud personal cloud storage devices prior to firmware 2.30.172. The issue is present in the nas_sharing.cgi CGI component, which contains a built-in administrative account credential. Because the credential is embedded in the binary rather than provisioned securely at deployment time, an attacker who knows or recovers it can authenticate as an administrator without possessing legitimate user-assigned credentials. This results in a complete authorization bypass on affected devices.
CVE-2017-18182First seen Aug 20, 2026
CVE-2014-4681 is a denial-of-service vulnerability affecting the Wing HTTP server component in Wing FTP Server 4.3.7 and earlier on Windows. The flaw is caused by improper filtering of requests for certain reserved or special file names. By requesting one of these names, a remote attacker can trigger a condition that causes the embedded web server to become unavailable.
CVE-2014-4681First seen Aug 20, 2026
CVE-2014-2876 is an unauthenticated information disclosure vulnerability affecting NetSupport Manager and NetSupport Client. By sending a specially crafted request to a host running the NetSupport application, a remote attacker can retrieve sensitive host configuration information. The issue is exposed when NetSupport authentication is not configured, allowing unauthenticated access to information that should not be disclosed. Reported exposed data includes host settings and encrypted passwords, which can support follow-on compromise or facilitate additional attack paths.
CVE-2014-2876First seen Aug 20, 2026
CVE-2011-1037 is a broken authentication and session management vulnerability in the web-based administrative console of Avocent Cyclades ACS Web Manager. The flaw affects the application's authentication and session handling logic, allowing an unauthenticated user to bypass normal access controls and reach administrative console content. The issue exposes application pages and sensitive information intended only for authenticated administrative users, although the available information indicates the flaw does not enable access to dynamic functionality for changing settings through this issue alone.
CVE-2011-1037First seen Aug 20, 2026
CVE-2021-35470 is a multiple authenticated stored cross-site scripting vulnerability in the WordPress plugin Inline Related Posts affecting versions up to and including 3.0.4. Multiple plugin parameters can be used by an authenticated administrator to inject malicious JavaScript that is stored by the application. The payload is subsequently executed in the browsers of users who view a post containing the affected inline references.
CVE-2021-35470First seen Aug 20, 2026
CVE-2020-28003 is an arbitrary code execution issue in WinZip affecting the application's trial-mode content retrieval behavior. When operating in trial mode, WinZip fetches and renders remote HTML content over HTTP rather than HTTPS. Because the content is delivered without transport integrity, a network-positioned attacker can tamper with the response and supply malicious HTML and script content. This allows arbitrary JavaScript to execute within the WinZip process context when the application displays the attacker-modified content.
CVE-2020-28003First seen Aug 20, 2026
First seen Aug 20, 2026
First seen Aug 20, 2026
CVE-2026-53965 is a denial-of-service vulnerability in the MCP PHP SDK client HttpTransport implementation. The flaw arises from unbounded buffering of Server-Sent Events data when processing an SSE response stream that withholds the event delimiter, allowing the internal buffer to grow without limit. A malicious or compromised remote MCP server can maintain an incomplete event stream and force continued memory accumulation in the client process. This can exhaust available memory and terminate the PHP process.
CVE-2026-53965First seen Aug 20, 2026
First seen Aug 20, 2026
First seen Aug 20, 2026
First seen Aug 19, 2026
First seen Aug 19, 2026
CVE-2026-55209 is a set of memory-safety vulnerabilities in resdata affecting the parsing of GRDECL files. Reported issues include a classic buffer overflow, improper validation of array index values, a NULL pointer dereference, and an out-of-bounds read. The flaws are triggered when the application processes a crafted GRDECL input file, indicating insufficient bounds checking and input validation in the GRDECL parsing logic. Successful exploitation can lead to memory corruption or process termination depending on which code path is reached.
CVE-2026-55209First seen Aug 18, 2026
CVE-2026-55211 is an out-of-bounds read vulnerability in surfio affecting versions prior to 0.0.19. The flaw is caused by improper validation of size fields while parsing irap files. A specially crafted irap file can cause the parser to read beyond the bounds of the intended memory region during file processing. The issue arises when malformed size metadata is trusted without sufficient bounds checking before memory access operations are performed.
CVE-2026-55211First seen Aug 18, 2026
CVE-2026-55158 is a command injection vulnerability in conflibot that can be triggered through crafted pull request branch names when the action is used in GitHub Actions workflows under the pull_request_target event. Affected versions construct git-related shell commands using attacker-controlled branch name data, allowing untrusted input to reach shell execution. In vulnerable deployments, a malicious pull request can cause arbitrary commands to run on the GitHub Actions runner. The issue is addressed in fixed releases by replacing shell-based command execution with safer argument-array invocation mechanisms and by referencing pull requests through refs/pull/<number>/head rather than attacker-controlled branch names.
CVE-2026-55158First seen Aug 17, 2026
First seen Aug 17, 2026
First seen Aug 17, 2026
First seen Aug 16, 2026
First seen Aug 16, 2026
First seen Aug 16, 2026
First seen Aug 16, 2026
First seen Aug 15, 2026