These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,200 reserved CVEs with public mentions, ranked by all-time mention count.
Page 22 of 48
First seen Jul 30, 2026
CVE-2026-20121First seen Jul 30, 2026
CVE-2026-20143First seen Jul 30, 2026
flyto-core contains a server-side request forgery vulnerability in multiple HTTP-capable modules that issue outbound requests to fully user-controlled URLs without invoking the project's SSRF validation routine, validate_url_with_env_config. The flaw affects modules that perform direct HTTP requests while relying only on non-enforcing metadata indicating SSRF protection rather than actually applying destination validation before network access. Reported affected modules include core.api.http_get, core.api.http_post, GraphQL request modules, monitoring and notification modules, certain AI and browser-related modules, and inline base_url handling paths. The root cause is an inconsistent, per-module SSRF protection model with no centralized guarded outbound HTTP client, allowing vulnerable modules to bypass intended destination restrictions entirely. Successful exploitation allows an authenticated workflow author to direct the application to access loopback, RFC1918, cloud metadata, and other internal network resources and receive the remote response content back through the application.
CVE-2026-55787First seen Jul 7, 2026
CVE-2023-23359 is a vulnerability affecting QNAP QTS, QuTS hero, and QuTScloud. Available information indicates that exploitation may allow remote arbitrary code execution or denial of service. Specific technical details about the vulnerable component, root cause, and affected function are currently not available.
CVE-2023-23359First seen Jul 30, 2026
CVE-2026-20120First seen Jul 30, 2026
CVE-2025-36350 is an information disclosure vulnerability affecting AMD processors and addressed through Microsoft's July 2025 Windows security updates. Available reporting identifies it as one of two AMD information-disclosure issues remediated by applying a Windows patch. Specific technical details about the vulnerable component, root cause, and triggering conditions are not currently available from the provided material.
CVE-2025-36350First seen Jun 14, 2026
CVE-2024-54035 is an improper authorization vulnerability in Adobe Connect. The flaw allows a remote, unauthenticated attacker to exploit insufficient authorization controls and escalate privileges without requiring user interaction. The issue affects Adobe Connect versions prior to 12.7 and 11.4.9.
CVE-2024-54035First seen Jul 23, 2026
CVE-2025-64552 is a stored cross-site scripting vulnerability in Adobe Experience Manager. Available reporting identifies it as CWE-79 and places it among multiple AEM XSS issues addressed by Adobe. The vulnerability allows attacker-controlled content to be stored and later rendered in a victim’s browser without proper neutralization, causing execution of injected script in the context of the affected AEM application. Advisory language indicates that exploitation of the affected AEM vulnerabilities could lead to arbitrary code execution, arbitrary file system read, and privilege escalation, but the specific vulnerable component or function for CVE-2025-64552 is not currently available from the provided information.
CVE-2025-64552First seen Mar 19, 2026
First seen Jul 30, 2026
CVE-2024-51538First seen Jul 30, 2026
CVE-2026-21958First seen Jan 21, 2026
First seen Jul 29, 2026
First seen Jul 29, 2026
CVE-2026-54632 is a denial-of-service vulnerability in SIPSorcery affecting handling of malformed UDP traffic on the RTP/ICE socket. A specially crafted malformed UDP packet can trigger an unhandled exception during packet processing, including STUN parsing associated with ICE connectivity checks. Because the exception is not safely contained in the UDP receive path, the affected RTP or WebRTC media session can be terminated instead of the malformed packet being discarded.
CVE-2026-54632First seen Jul 28, 2026
CVE-2026-55093 is an integer overflow vulnerability in the Rust package tract-nnef, specifically in tract_nnef::tensors::read_tensor while parsing NNEF .dat tensors during model loading. The vulnerable code derives tensor dimensions from attacker-controlled 32-bit shape values and computes both the element count and the backing allocation size using unchecked usize multiplication. In release builds, these arithmetic operations can wrap, allowing a crafted tensor shape to produce a very small allocation while the resulting Tensor metadata reports an extremely large logical length. Subsequent slice construction over that undersized buffer can cause out-of-bounds reads during model build, including through constant-folding paths that materialize the malformed tensor before inference. The issue affects releases before 0.21.16 in the 0.21 branch, versions 0.22.0 through 0.22.1, and version 0.23.0. It is fixed in 0.21.16, 0.22.2, and 0.23.1.
CVE-2026-55093First seen Jun 19, 2026
CVE-2026-44203 is a reflected cross-site scripting vulnerability in OpenAM's OAuth2/OpenID Connect authorization flow. Available reporting indicates attacker-controlled input is reflected into HTML responses without proper output encoding in at least two authorization-related contexts: the form_post response handling path and the consent page rendered for a wap display mode. In the form_post case, the state parameter can be reflected through the FormPostResponse.ftl template before authentication. In the consent-page case, attacker-supplied authorize request values may be rendered into HTML without sufficient escaping. Successful exploitation causes arbitrary JavaScript to execute in the security context of the OpenAM origin.
CVE-2026-44203First seen Jun 23, 2026
First seen Jul 25, 2026
First seen Jul 23, 2026
First seen Jul 23, 2026
First seen Jul 23, 2026
First seen Jul 23, 2026
First seen Jul 23, 2026
CVE-2026-57496 is a path traversal vulnerability in netlicensing-mcp that affects requests handled through the product endpoint. An authenticated client can supply traversal sequences that cause the application to access the token endpoint instead of the intended product resource. This endpoint confusion bypasses token-specific redaction controls and exposes sensitive token data in plaintext, including API key values and shop URL information. The issue indicates insufficient validation and normalization of user-controlled path segments before they are incorporated into upstream REST path construction.
CVE-2026-57496First seen Jul 22, 2026
CVE-2026-57148 is an improper authentication vulnerability in praisonai-platform caused by use of a hardcoded default JWT signing secret together with a production configuration that remains permissive by default. In affected default deployments, if the platform secret is unset or left at the known default value, an attacker can generate forged JWTs that are accepted as valid by the application. Because the forged tokens can encode arbitrary user identity and authorization context, the flaw enables authentication bypass and impersonation of legitimate users, including high-privilege workspace owners. The issue stems from insecure default credential material and insufficient fail-closed validation around JWT secret configuration in production deployments.
CVE-2026-57148First seen Jul 21, 2026