These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,197 reserved CVEs with public mentions, ranked by all-time mention count.
Page 21 of 48
First seen Aug 4, 2026
First seen Aug 4, 2026
First seen Aug 4, 2026
First seen Aug 4, 2026
CVE-2026-50276 is a denial-of-service vulnerability in Datadog's Ruby tracing library, dd-trace-rb. When W3C baggage propagation is enabled, the library parses incoming baggage HTTP headers during extraction without enforcing the configured limits on item count or total byte size. The limits intended to constrain baggage processing were applied only when injecting outbound baggage, not when extracting inbound baggage. As a result, an attacker can supply a baggage header containing an excessive number of comma-separated key-value pairs or a very large value, causing the tracer to create hash-map entries for each parsed item on every request. This leads to unbounded resource consumption during request processing in instrumented HTTP services.
CVE-2026-50276First seen Jun 12, 2026
First seen Aug 1, 2026
First seen Aug 1, 2026
First seen Aug 1, 2026
CVE-2023-20099 is a vulnerability affecting Cisco Secure Web Appliance that can allow a remote attacker to bypass security protections enforced by the appliance. Publicly available information in the provided material does not include the vulnerable component, root cause, or affected function, so a more specific technical characterization is currently not available.
CVE-2023-20099First seen Jul 30, 2026
CVE-2026-0062First seen Jul 30, 2026
CVE-2023-23361 is a vulnerability affecting QNAP QTS, QuTS hero, and QuTScloud. Available information indicates that exploitation may allow remote arbitrary code execution or denial of service. Specific technical details about the vulnerable component, root cause, and affected function are not currently available.
CVE-2023-23361First seen Jul 30, 2026
CVE-2023-23360 is a vulnerability affecting QNAP QTS, QuTS hero, and QuTScloud. Available information indicates that exploitation may allow remote arbitrary code execution or denial of service. Specific technical details about the vulnerable component, root cause, and affected function are not currently available.
CVE-2023-23360First seen Jul 30, 2026
First seen Jul 31, 2026
CVE-2025-64542 is a DOM-based cross-site scripting vulnerability in Adobe Experience Manager (AEM). The available information identifies the issue as CWE-79 and places it among multiple AEM XSS flaws addressed by Adobe. In the vulnerable condition, attacker-controlled input can be processed by client-side application logic in a way that causes script execution within a user’s browser session in the context of the affected AEM application. Adobe’s advisory groups this issue with vulnerabilities that may lead to arbitrary code execution, arbitrary file system read, and privilege escalation on affected AEM instances, but the specific vulnerable component or function for CVE-2025-64542 is not currently available from the provided information.
CVE-2025-64542First seen Mar 19, 2026
CVE-2023-21119First seen Jul 30, 2026
CVE-2026-21735First seen Jul 30, 2026
CVE-2024-43711 is a critical input validation vulnerability in Adobe Experience Manager affecting versions earlier than AEM Cloud Service Release 2024.11 and 6.5.22. The flaw stems from insufficient validation of attacker-controlled input and may allow a remote attacker to trigger remote code execution. Available reporting identifies the issue as an input validation weakness but does not provide the specific vulnerable component or function.
CVE-2024-43711First seen Jul 23, 2026
CVE-2023-23358 is a vulnerability affecting QNAP QTS, QuTS hero, and QuTScloud. Available information indicates that exploitation may allow remote arbitrary code execution or denial of service. Specific technical details about the vulnerable component, root cause, and affected function have not been provided.
CVE-2023-23358First seen Jul 30, 2026
CVE-2023-3281 is a vulnerability affecting Palo Alto Networks Cortex XSOAR Kafka Integration v3 before version 2.0.16. The issue can be exploited to compromise the confidentiality of data. Publicly available information confirms the affected component and fixed version, but does not provide sufficient technical detail about the vulnerable code path or root cause to characterize the flaw more precisely.
CVE-2023-3281First seen Jul 30, 2026
CVE-2024-31330First seen Jul 30, 2026
CVE-2024-26048First seen Jul 30, 2026
CVE-2025-46787First seen Jul 30, 2026
First seen Jul 30, 2026
CVE-2026-20121First seen Jul 30, 2026
CVE-2026-20143First seen Jul 30, 2026