These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,178 reserved CVEs with public mentions, ranked by all-time mention count.
Page 3 of 48
CVE-2026-42617 is a heap memory corruption vulnerability in ntfs-3g affecting the ntfs_ir_to_ib() function. The flaw occurs while copying index data from an NTFS index root to an index block when the software processes a corrupt or maliciously crafted NTFS filesystem image. Improper handling of attacker-controlled filesystem metadata can corrupt heap memory during index structure conversion or population, creating conditions for process instability and potential control-flow hijacking. Because ntfs-3g commonly operates with elevated privileges in filesystem handling contexts, successful exploitation may result in execution of attacker-controlled code with root privileges.
CVE-2026-42617First seen Jul 15, 2026
CVE-2026-42618 is a single-byte heap buffer overflow in the ntfs_decompress() function in ntfs-3g. The flaw is triggered when the software decompresses maliciously crafted compressed file data from an NTFS filesystem or image. Improper bounds handling during decompression can cause a one-byte write past the end of a heap-allocated buffer, resulting in heap memory corruption while parsing attacker-controlled NTFS compressed data.
CVE-2026-42618First seen Jul 15, 2026
CVE-2026-46571 is an out-of-bounds read vulnerability in NTFS-3G, a userspace NTFS driver and utilities suite used with FUSE. The flaw occurs while processing symlink reparse data from a corrupt or maliciously crafted NTFS filesystem. Improper bounds validation during parsing of this filesystem metadata can cause the software to read memory outside the intended buffer. The issue is one of several NTFS metadata parsing flaws fixed in NTFS-3G 2026.7.7.
CVE-2026-46571First seen Jul 15, 2026
CVE-2026-46572 is a heap buffer overflow vulnerability in ntfs-3g affecting the function ntfs_ib_cut_tail(). The flaw is triggered during node-split handling when the software processes maliciously crafted or corrupt NTFS index data. Improper bounds handling during manipulation of index block tail data can cause a write beyond the bounds of a heap-allocated buffer. Because ntfs-3g parses attacker-controlled NTFS filesystem metadata, a crafted NTFS image or filesystem can reach the vulnerable code path and corrupt process memory.
CVE-2026-46572First seen Jul 15, 2026
CVE-2026-3886 is a local privilege escalation vulnerability in QEMU, disclosed as ZDI-26-332. The flaw exists in the virtio-gpu driver, specifically in processing associated with calc_image_hostmem, where improper validation of user-supplied data can trigger an integer overflow prior to buffer allocation. This miscalculation can lead to an undersized allocation followed by memory corruption conditions that are exploitable by an attacker. A successful exploit allows arbitrary code execution in the context of the host system from a low-privileged position in the guest.
CVE-2026-3886First seen Jun 9, 2026
First seen Apr 30, 2026
CVE-2026-35328 is a vulnerability in libtls involving processing of the TLS supported_versions extension. According to the provided context, malformed or otherwise problematic handling of this extension can cause the affected code path to enter an infinite loop during TLS processing.
CVE-2026-35328First seen Apr 22, 2026
First seen Aug 22, 2026
CVE-2022-24087 is a critical improper input validation vulnerability in Adobe Commerce and Magento Open Source. It was assigned after researchers identified a bypass for earlier fixes associated with CVE-2022-24086. The flaw allows arbitrary code execution and is exploitable without authentication, indicating that crafted unauthenticated input processed by the application can reach vulnerable code paths and result in execution of attacker-controlled code on the target system.
CVE-2022-24087First seen Mar 18, 2026
CVE-2026-53629 is a blind SQL injection vulnerability in GLPI affecting the history log filter functionality, referred to as LogBleed. The vulnerable code path is associated with Log::convertFiltersValuesToSqlCriteria() and SQL criteria handling in DBmysqlIterator::analyseCrit(). Attacker-controlled input supplied through the affected_fields filter can be incorporated into SQL logic without sufficient neutralization, enabling time-based blind SQL injection. Available information indicates the issue was reproducible on GLPI 10.0.25 and rejected in GLPI 10.0.26, indicating the flaw was fixed in that release.
CVE-2026-53629First seen Jul 27, 2026
CVE-2026-63078 is a patched zero-day vulnerability in Apache Traffic Server involving HTTP desynchronization. Available reporting indicates the issue was exposed through a crafted request sequence that triggered inconsistent request parsing and handling, and it has been associated with a desync trigger involving unusual method and header combinations. The flaw appears to fall within the request smuggling/desynchronization class, where malformed or ambiguously interpreted requests can cause a front-end and back-end component, or different parsing paths within the server, to disagree about request boundaries or semantics. Public technical detail about the exact vulnerable code path, affected versions, and fixed release mapping is currently not available.
CVE-2026-63078First seen Aug 5, 2026
First seen Jul 31, 2026
First seen Jul 15, 2026
CVE-2023-28355 is an improper validation of integrity check value vulnerability in the CODESYS Control Runtime used in Schneider Electric devices that embed the CODESYS Runtime System V3. The PLC application code executed by the runtime relies on a checksum mechanism that is not sufficient to reliably detect PLC application code modified in memory or boot application files that have been manipulated. As a result, the integrity verification mechanism can be bypassed by altered application content, allowing unauthorized modifications to persist without dependable detection by the runtime.
CVE-2023-28355First seen Jan 22, 2026
CVE-2026-13135 is a moderate-severity vulnerability in Synology MailPlus Server on DiskStation Manager (DSM) caused by improper restriction of a communication channel to intended endpoints. The flaw allows a remote attacker to reach or access internal services that should not be exposed through the affected MailPlus Server deployment. Available reporting identifies the issue as ZDI-CAN-28485 and maps it to CWE-923. The vulnerability affects MailPlus Server deployments on DSM 7.3, 7.2.2, and 7.2.1 prior to the fixed releases.
CVE-2026-13135First seen Jun 29, 2026
CVE-2025-68405 is a stack overflow vulnerability in QNAP products, including affected releases of QTS, QuTS hero, QuTS cloud, and QVP. The flaw can be exploited by an authenticated administrator and may trigger unexpected system behavior or a denial-of-service condition. The available information identifies the issue as a stack overflow but does not provide the specific vulnerable component, function, or code path.
CVE-2025-68405First seen Jun 17, 2026
CVE-2025-15660 is a critical vulnerability in Synology MailPlus Server on DiskStation Manager (DSM). The issue is associated with CWE-338, Use of Cryptographically Weak PRNG, and has been identified as ZDI-CAN-28554. Successful exploitation allows an adjacent attacker to read arbitrary files, write arbitrary files, and trigger denial-of-service conditions, resulting in compromise of data confidentiality and integrity as well as service availability. Publicly available context does not provide the specific vulnerable function or code path.
CVE-2025-15660First seen Jun 29, 2026
CVE-2026-53922 is a moderate-severity vulnerability in OpenWrt's odhcpd affecting DHCPv6 Identity Association handling. The flaw is described as a size_t underflow in the DHCPv6 IA processing path, reachable before authentication by a network-adjacent attacker sending crafted DHCPv6 traffic. The vulnerable condition occurs while parsing or handling DHCPv6 IA-related data, where insufficient bounds validation allows an unsigned size calculation to wrap, leading to invalid memory access during request processing. OpenWrt addressed the issue in an odhcpd update that also incorporated additional DHCPv6 input-validation and bounds-checking hardening.
CVE-2026-53922First seen Jun 30, 2026
CVE-2026-61548 is a high-severity stack-based buffer overflow in rsyslog's optional mmpstrucdata module affecting rsyslog versions 7.5.4 through before 8.2606.0. The flaw occurs during parsing of RFC 5424 structured-data parameter values. In affected versions, parseSD_PARAM() allocates a fixed 32,768-byte stack buffer for a parameter value and passes it to parsePARAM_VALUE() without supplying the destination buffer size. parsePARAM_VALUE() then copies attacker-controlled parameter data into that buffer without proper bounds checking, with the write bounded only by the length of the structured-data input. A sufficiently large structured-data parameter value can therefore overwrite stack memory and crash the rsyslog process. The issue is present only when the optional mmpstrucdata plugin is installed, explicitly loaded, and used to process attacker-controlled RFC 5424 messages.
CVE-2026-61548First seen Jul 20, 2026
CVE-2026-33630 is a remotely triggerable memory-safety flaw in c-ares query-completion handling affecting the `ares_getaddrinfo()` resolution path over TCP. The vulnerability arises because a query callback can be invoked while the query remains linked in internal lookup structures. If the callback path, or subsequent protocol-driven processing, causes the associated query or owning `host_query` object to be freed, c-ares may later re-enter completion logic and access or free the same object again, resulting in a use-after-free or double-free condition. The issue can be triggered through application re-entry from a callback, such as cancellation during callback execution, and also through a fully remote path requiring no application cooperation. In the remote scenario, a malicious or on-path DNS server can manipulate response sequencing so that deferred retries and completions are re-entered against already-freed state, including by forcing fallback to TCP and then delivering crafted responses that drive the vulnerable completion flow. The flaw was reported as reproducible against c-ares 1.34.6 and the development branch, and was fixed in c-ares 1.34.7 by detaching each query from lookup structures before invoking callbacks and routing deferred retries and completions through a single iterative drain path.
CVE-2026-33630First seen Jul 6, 2026
CVE-2026-39218 is a heap buffer overflow vulnerability in FFmpeg's DASH demuxer. The flaw was reportedly introduced in 2017 and affects FFmpeg media parsing functionality within the DASH demuxing path. A crafted DASH media input can trigger out-of-bounds writes to heap memory during demuxer processing, leading to memory corruption. As a parser-side memory safety flaw in a widely deployed media framework, the vulnerability is relevant anywhere FFmpeg processes attacker-controlled or untrusted DASH content, whether directly through command-line use or indirectly through applications and services embedding FFmpeg.
CVE-2026-39218First seen Jun 6, 2026
First seen Jul 1, 2026
CVE-2026-35330 is a vulnerability in libsimaka involving the processing of certain EAP-SIM/AKA attributes. According to the provided context, malformed or specially crafted attributes can trigger either an infinite loop or a heap-based buffer overflow during parsing or handling of EAP-SIM/AKA data. The heap corruption condition may potentially lead to remote code execution. Specific vulnerable functions, affected versions, and patch details are not available in the provided content.
CVE-2026-35330First seen Apr 22, 2026
First seen Jun 18, 2026
CVE-2026-47321 is a denial-of-service vulnerability in Apache MINA’s compression handling, specifically in the CompressionFilter use of Zlib.inflate for incoming data. According to the provided content, affected versions did not enforce limits on the size of decompressed output before allocating buffers for inflated data. An attacker can send a very small compressed input that expands into an extremely large output block, potentially with compression ratios greater than 1,000:1. This unbounded decompression amplification can exhaust application memory and crash the server. The issue is described as affecting Apache MINA’s zip libraries / Zlib inflate path and was tracked as ZDRES-231.
CVE-2026-47321First seen Jun 3, 2026