These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,193 reserved CVEs with public mentions, ranked by all-time mention count.
Page 20 of 48
CVE-2026-45694 is a reflected cross-site scripting vulnerability in the LibreNMS Proxmox application handler. Attacker-controlled GET parameters are incorporated into a JavaScript assignment to document.title without safe encoding, allowing script injection in the rendered response. The issue specifically affects handling of Proxmox-related request parameters, where insufficient output encoding permits untrusted input to break out of the intended JavaScript context and execute in the victim's browser.
CVE-2026-45694First seen Aug 4, 2026
First seen Aug 12, 2026
First seen Aug 11, 2026
First seen Aug 11, 2026
CVE-2026-61551First seen Aug 10, 2026
CVE-2026-61552First seen Aug 10, 2026
CVE-2026-61550First seen Aug 10, 2026
First seen Aug 10, 2026
First seen Aug 8, 2026
First seen Aug 7, 2026
First seen Aug 6, 2026
First seen Aug 6, 2026
CVE-2026-54241 is a security vulnerability in libde265, an open source implementation of the H.265/HEVC video codec. The issue is triggered when the library processes a malformed media file. Available information does not identify the specific vulnerable function or root cause, but the flaw is part of a set of libde265 parsing issues affecting media decoding.
CVE-2026-54241First seen Jun 13, 2026
CVE-2026-54240 is one of multiple security issues affecting libde265, an open source implementation of the H.265/HEVC video codec. The available information indicates that the vulnerability can be triggered when libde265 processes a malformed media file. Specific details about the vulnerable function, root cause, and exact flaw class are not currently available. Reported outcomes for the affected set of issues include denial of service, memory exhaustion, and potentially arbitrary code execution.
CVE-2026-54240First seen Jun 13, 2026
First seen Aug 4, 2026
First seen Aug 4, 2026
First seen Aug 4, 2026
First seen Aug 4, 2026
First seen Aug 4, 2026
CVE-2026-50276 is a denial-of-service vulnerability in Datadog's Ruby tracing library, dd-trace-rb. When W3C baggage propagation is enabled, the library parses incoming baggage HTTP headers during extraction without enforcing the configured limits on item count or total byte size. The limits intended to constrain baggage processing were applied only when injecting outbound baggage, not when extracting inbound baggage. As a result, an attacker can supply a baggage header containing an excessive number of comma-separated key-value pairs or a very large value, causing the tracer to create hash-map entries for each parsed item on every request. This leads to unbounded resource consumption during request processing in instrumented HTTP services.
CVE-2026-50276First seen Jun 12, 2026
First seen Aug 1, 2026
First seen Aug 1, 2026
First seen Aug 1, 2026
CVE-2023-20099 is a vulnerability affecting Cisco Secure Web Appliance that can allow a remote attacker to bypass security protections enforced by the appliance. Publicly available information in the provided material does not include the vulnerable component, root cause, or affected function, so a more specific technical characterization is currently not available.
CVE-2023-20099First seen Jul 30, 2026
CVE-2026-0062First seen Jul 30, 2026