These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,107 reserved CVEs with public mentions, ranked by all-time mention count.
Page 19 of 45
First seen Oct 2, 2026
First seen Oct 2, 2026
First seen Oct 2, 2026
First seen Oct 2, 2026
First seen Oct 2, 2026
First seen Oct 2, 2026
First seen Oct 2, 2026
First seen Oct 2, 2026
CVE-2026-47452First seen Oct 1, 2026
CVE-2026-47454First seen Oct 1, 2026
CVE-2026-47455 is a corrected vulnerability affecting NVIDIA products. Technical details, affected components, attack conditions, and vulnerability class have not been publicly specified.
CVE-2026-47455First seen Oct 1, 2026
CVE-2026-47450 is a corrected vulnerability in NVIDIA products. Individual technical details, including the vulnerable component, affected versions, attack method, and CVE-specific impact, are not available.
CVE-2026-47450First seen Oct 1, 2026
CVE-2026-47453First seen Oct 1, 2026
CVE-2026-47449 is a corrected vulnerability associated with NVIDIA GPU Display Driver for Windows and Linux and NVIDIA vGPU Software. Technical details, including the vulnerable component, flaw type, affected versions, and exploitation method, are not available.
CVE-2026-47449First seen Oct 1, 2026
CVE-2026-47448First seen Oct 1, 2026
CVE-2026-47456 is a corrected vulnerability affecting NVIDIA products, including NVIDIA GPU Display Driver for Windows and Linux and NVIDIA vGPU Software. Technical details, including the vulnerable component, flaw type, attack vector, prerequisites, and CVE-specific impact, are not publicly available in the available information.
CVE-2026-47456First seen Oct 1, 2026
CVE-2026-47451First seen Oct 1, 2026
HCL CAMWorks contains an insecure binary compilation vulnerability that may permit a local attacker with high privileges to reverse engineer application binaries. The weakness may expose information embedded in the binaries and enable code tampering.
CVE-2025-59850First seen Oct 1, 2026
Axios for Node.js does not interpret CIDR-form entries in the NO_PROXY environment variable. Requests addressed to systems within a CIDR range intended to bypass configured HTTP(S) proxies can therefore be routed through those proxies rather than directly to their destination.
CVE-2026-101899First seen Oct 1, 2026
CVE-2026-101896 is an uncontrolled resource-consumption vulnerability in @angular/router when Angular Server-Side Rendering runs on Node.js/V8. During router URL parsing, numeric URL matrix-parameter or outlet names can cause oversized V8 array backing-store allocations. Repeated numeric matrix parameters can amplify memory use until the Node.js old-space heap is exhausted.
CVE-2026-101896First seen Oct 1, 2026
First seen Sep 30, 2026
First seen Sep 30, 2026
Engine.IO servers that permit transport upgrades improperly handle an upgrade request whose EIO protocol-revision parameter differs from, or is omitted relative to, the revision negotiated when the Engine.IO session was established. The protocol mismatch produces parser and heartbeat-state inconsistency that can result in an uncaught exception in the Node.js process.
CVE-2026-102599First seen Sep 30, 2026
CVE-2026-102342 is an improper neutralization vulnerability in the Rust Ammonia HTML sanitization library. When sanitization policies permit SVG animate or set elements, attacker-supplied SVG can use those elements to assign a javascript: URL to an anchor href attribute. The resulting stored cross-site scripting payload executes attacker-controlled JavaScript in the application origin when a user clicks the crafted SVG link.
CVE-2026-102342First seen Sep 30, 2026
CVE-2026-101303 is a network-isolation bypass in FreeBSD classic, non-VNET jails. The IPv6 UDP send path for unconnected sockets does not apply the jail policy that rewrites an IPv6 loopback destination to the jail's primary IPv6 address. Consequently, a process in an affected jail can use IPv6 UDP sendto(2) to send datagrams to services bound to the host's IPv6 loopback address.
CVE-2026-101303First seen Sep 29, 2026