These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,197 reserved CVEs with public mentions, ranked by all-time mention count.
Page 29 of 48
First seen Jun 8, 2026
First seen Jun 3, 2026
First seen Jun 3, 2026
First seen Jun 3, 2026
First seen Jun 3, 2026
First seen Jun 3, 2026
CVE-2026-26847 is an improper authentication/authorization flaw in Collibra Platform Agent in which privileged REST endpoints exposed under /rest/* do not properly enforce access controls. According to the provided context, a remote, unauthenticated attacker can access sensitive application functionality and obtain information useful for further exploitation, including identifying suitable filesystem locations or application paths. CERT/CC indicates this issue is one of two chainable vulnerabilities in Collibra Platform Agent and can be combined with a Zip Slip path traversal flaw in the restore handler to achieve remote code execution.
CVE-2026-26847First seen Jun 2, 2026
CVE-2026-26848 is a Zip Slip vulnerability in the Collibra Platform Agent restore functionality exposed via POST /rest/restore. When the application processes a supplied ZIP archive, file paths inside the archive are not properly validated or canonicalized before extraction. An attacker can include directory traversal sequences such as ../ in archive entry names so that extracted files are written outside the intended restore directory. According to the advisory context, this flaw is one of two chainable vulnerabilities in Collibra Platform Agent and can be used as part of an attack path leading to remote code execution.
CVE-2026-26848First seen Jun 2, 2026
CVE-2025-44202 is a critical vulnerability in Vioma Condeon CMS versions up to and including 1.9.1, where a publicly accessible memory dump file is exposed via the web server. This file contains sensitive information such as valid session cookies (SESS_BE), password hashes, SQL statements, and file paths. Attackers can retrieve the memory dump by sending a GET request to /condeon/core, enabling them to hijack authenticated sessions and access sensitive data across all tenants hosted on the platform.
CVE-2025-44202First seen Jun 2, 2026
CVE-2025-44200 is a mass assignment vulnerability in Vioma Condeon CMS versions up to and including 1.9.1. The flaw allows authenticated attackers to manipulate the CustomerID field via the form[user_customer] POST parameter, enabling them to escalate privileges and gain administrative access to other customers' CMS instances. By creating a user, granting it admin permissions, and changing the CustomerID, attackers can achieve cross-tenant lateral movement and full administrative compromise of any Vioma-hosted Condeon CMS installation.
CVE-2025-44200First seen Jun 2, 2026
First seen Jun 1, 2026
First seen Jun 1, 2026
First seen Jun 1, 2026
First seen Jun 1, 2026
First seen May 31, 2026
First seen May 31, 2026
CVE-2015-5676 affects the FreeBSD pkg(7) bootstrap utility. When the signature_type option in pkg.conf(5) is set to an unsupported method, the bootstrap logic incorrectly behaves as though signature_type were set to "none" rather than rejecting the configuration or failing closed. This causes package signature verification to be bypassed during bootstrap, enabling acceptance of an untrusted pkg(8) package. The issue is specifically in the handling of unsupported signature methods by the bootstrap utility.
CVE-2015-5676First seen May 26, 2026
First seen May 27, 2026
First seen May 26, 2026
First seen May 26, 2026
First seen May 26, 2026
First seen May 26, 2026
CVE-2023-22245 is a critical out-of-bounds write vulnerability affecting Adobe Substance 3D Stager through a vulnerable third-party dependency. According to the provided advisory context, successful exploitation could lead to arbitrary code execution in the context of the current user. The specific vulnerable library, function, and code path are not identified in the provided content.
CVE-2023-22245First seen May 25, 2026
CVE-2021-28582 is a critical buffer overflow vulnerability in Adobe Photoshop for Windows and macOS. According to the provided Adobe advisory context, the flaw can be triggered in affected Photoshop versions and may result in arbitrary code execution in the context of the current user. The supplied material identifies the weakness as CWE-788 and indicates that Adobe addressed it in Photoshop 2020 version 21.2.8 / 21.2.9 and Photoshop 2021 version 22.4.0 / 22.4.2, depending on advisory wording. No vulnerable function or parsing component is specified in the provided content.
CVE-2021-28582First seen May 25, 2026
First seen May 26, 2026