These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,200 reserved CVEs with public mentions, ranked by all-time mention count.
Page 28 of 48
First seen May 20, 2026
First seen May 20, 2026
First seen May 20, 2026
First seen Jun 8, 2026
CVE-2026-44235First seen Jun 12, 2026
CVE-2026-44236First seen Jun 12, 2026
First seen May 20, 2026
First seen May 20, 2026
First seen May 20, 2026
First seen May 20, 2026
First seen May 20, 2026
First seen May 20, 2026
First seen May 20, 2026
First seen May 20, 2026
First seen May 20, 2026
First seen May 20, 2026
First seen May 20, 2026
First seen May 20, 2026
First seen May 20, 2026
CVE-2026-32179 is a remote vulnerability in Microsoft QUIC (MsQuic) caused by improper input validation leading to an integer underflow while decoding/parsing ACK frames. The issue affects MsQuic packages including Microsoft.Native.Quic.MsQuic.OpenSSL and Microsoft.Native.Quic.MsQuic.Schannel. A remote attacker can send a crafted QUIC ACK frame that triggers the underflow during ACK frame parsing. The available advisory characterizes the issue as a remote elevation of privilege vulnerability.
CVE-2026-32179First seen Apr 21, 2026
CVE-2026-45057 affects the Rust crate matrix-sdk-ui before version 0.16.1. The flaw is in the message edit validation logic for Matrix replacement events: when an encrypted event is replaced, the SDK did not enforce that the replacement event was also encrypted. This incomplete validation allows a crafted unencrypted replacement event to be accepted in place of an encrypted original event, contrary to the expected validation rules for encrypted message edits. As a result, a malicious homeserver administrator, or another actor with equivalent control over event delivery or modification, can cause clients using vulnerable versions of matrix-sdk-ui to display spoofed edited messages as though they were authored by the victim user.
CVE-2026-45057First seen Jun 4, 2026
CVE-2014-6072 affects the Symfony Web Profiler import/export functionality in Symfony versions prior to 2.3.19, 2.4.9, and 2.5.4. The issue is described by the vendor as a cross-site request forgery (CSRF) vulnerability in the Web Profiler. When the Web Profiler is enabled and its import feature is exposed, an attacker can cause a victim with access to the profiler to submit a forged request that imports attacker-controlled profiler data, including a PHP serialized string. The available supporting content also references public research and exploit material describing this as a profiler-related injection issue. The vulnerable functionality was removed from the Web interface in fixed releases and replaced with CLI commands.
CVE-2014-6072First seen May 24, 2026
matrix-sdk-crypto before 0.16.1 fails to verify the sender's user ID when decrypting an Olm-encrypted to-device message that contains the sender_device_keys property. Because sender binding is incomplete in this code path, a malicious actor can cause the recipient to accept a forged sender identity for an encrypted to-device message. The issue affects the Matrix Rust SDK crypto crate distributed via crates.io and is tracked as GHSA-wfq4-36m3-9g42.
CVE-2026-45056First seen Jun 4, 2026
First seen Jun 12, 2026
First seen Jun 11, 2026