These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,109 reserved CVEs with public mentions, ranked by all-time mention count.
Page 45 of 45
CVE-2023-32198 is an improper certificate validation vulnerability in Steve. During TLS connections, Steve does not verify the remote server certificate by default, contrary to expected Go TLS certificate validation behavior. This allows a malicious intermediary to present an untrusted or spoofed certificate without being rejected, enabling interception and modification of traffic between Steve and the remote service. In Rancher deployments, the issue is particularly relevant under specific configuration conditions involving remote UI content retrieval.
CVE-2023-32198First seen Jun 4, 2026
CVE-2025-30083 is a cross-site scripting vulnerability in the codingms/additional-tca extension for TYPO3. According to the provided advisory, improperly encoded user input can be used by an authenticated TYPO3 backend user to create malicious output in an HTML context within the TYPO3 backend. The issue is therefore an authenticated backend-context XSS caused by insufficient output encoding of user-controlled data.
CVE-2025-30083First seen Jun 4, 2026
CVE-2015-2309 affects the Symfony HttpFoundation Request class. When at least one trusted proxy is configured, unsafe request-handling methods can incorrectly trust client-supplied HTTP header values. As a result, header-derived properties exposed by methods such as getPort(), isSecure(), getHost(), and getClientIps() may be influenced by attacker-controlled input rather than only by values inserted by trusted infrastructure. The issue is specifically tied to proxy trust handling in deployments that rely on forwarded headers to reconstruct the original client request context.
CVE-2015-2309First seen Jun 4, 2026
CVE-2014-4931 is a code injection vulnerability in Symfony FrameworkBundle's translation caching mechanism. According to the provided advisory context, attacker-controlled locale values, such as unsanitized _locale parameters supplied via URLs, can be written into generated cache files. If those locale values are not properly sanitized before reaching the translation caching logic, an attacker can inject arbitrary PHP code into the cache content, which may then be executed by the application.
CVE-2014-4931First seen Jun 4, 2026
CVE-2013-7035 is a cross-site scripting vulnerability in React affecting 0.5.x before 0.5.2 and 0.4.x before 0.4.2. According to the provided advisory, the issue is caused by improper sanitization of input used to create keys. If an application derives a React key from attacker-controlled input, the unsanitized value can be incorporated in a way that enables script execution in the victim's browser context.
CVE-2013-7035First seen Jun 4, 2026
CVE-2014-6061 is an authentication-related flaw in the Symfony HttpFoundation component affecting applications that rely on HTTP Basic or Digest authentication. The vulnerability stems from improper parsing of the HTTP Authorization header by HttpFoundation in certain server configurations. As a result, authentication handling may be performed incorrectly when the framework processes malformed or ambiguously parsed Authorization header data. Based on the provided advisory, the issue was fixed in Symfony versions 2.3.19, 2.4.9, and 2.5.4, with a corresponding patch published in Symfony pull request #11829.
CVE-2014-6061First seen Jun 4, 2026
CVE-2024-22031 is a privilege escalation vulnerability in Rancher caused by improper handling of project identity across clusters when projects share the same object name. According to the provided advisory, a user with permission to create projects on one cluster can create a project using the same name as an existing project in another cluster and thereby gain access to the other project. The issue appears to stem from namespace or object-name collision behavior across clusters, allowing authorization boundaries between clusters to be bypassed when duplicate project names exist.
CVE-2024-22031First seen Jun 4, 2026
Symfony HttpKernel contains an access control flaw affecting deployments where Edge Side Includes (ESI) support is enabled behind a trusted proxy. In affected versions, clients can directly request fragment/ESI URLs, such as the fragment endpoint, instead of having those requests mediated exclusively by the trusted proxy as intended. This can expose protected fragment endpoints or allow invocation of internal fragment functionality that should only be reachable through proxy-driven fragment rendering.
CVE-2014-5245First seen Jun 4, 2026
CVE-2025-66475 is a critical signature wrapping vulnerability affecting OneLogin php-saml through its xmlseclibs dependency. Based on the provided advisory, the flaw is in XML signature validation handling and can be exploited in SAML processing, allowing a maliciously crafted signed XML/SAML message to bypass intended signature protections. The issue affects deployments using vulnerable php-saml releases that depend on an unpatched xmlseclibs version.
CVE-2025-66475First seen Jun 4, 2026