These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,178 reserved CVEs with public mentions, ranked by all-time mention count.
Page 6 of 48
HCL Launch contains a vulnerability in which a manually edited keystore password used by the agent relay component is stored in clear text after restart. This results in insufficient protection of sensitive credentials at rest, allowing a local user with access to the affected system to read the stored password directly. The issue is a cleartext storage weakness affecting credential handling rather than a memory disclosure or cryptographic bypass.
CVE-2020-14267First seen Aug 23, 2026
CVE-2026-8408 is a cross-site request forgery vulnerability in IBM WebSphere Application Server affecting the Administrative Console. The issue is caused by improper validation of user-supplied input in administrative requests, allowing a remote attacker to induce an authenticated and privileged administrator to submit a specially crafted request. Successful exploitation depends on convincing the target to visit attacker-controlled content during a limited timing window, after which unauthorized administrative actions can be executed in the context of the victim’s active session.
CVE-2026-8408First seen Jul 8, 2026
CVE-2021-27748 is a server-side request forgery vulnerability affecting HCL Digital Experience in on-premise deployments and containerized deployments. The flaw allows the application to be induced to make attacker-controlled outbound requests from the server side. The available advisory information identifies the issue as an SSRF condition but does not provide vulnerable function-level details. Successful exploitation could enable misuse of the application as a proxy to reach internal or otherwise restricted network resources and services from the context of the HCL Digital Experience server.
CVE-2021-27748First seen Aug 14, 2026
CVE-2021-27666 is a high-severity information disclosure vulnerability in the Android telecommunication/modem component. Successful exploitation can lead to remote disclosure of sensitive information. The available information indicates that the issue is remotely reachable and does not require additional execution privileges. Specific details about the vulnerable function or code path are not available from the provided material.
CVE-2021-27666First seen Aug 22, 2026
IBM Application Performance Management (APM) 8.1.4 Base Private and Advanced Private are affected by multiple vulnerabilities due to the use of IBM Db2 and bundled third-party components (PCRE, zlib, protobuf-java, snappy-java, Netty, gRPC, ClusterLabs libqb, etc.). These vulnerabilities include remote code execution, denial of service, information disclosure, and privilege escalation. The issues stem from flaws in the underlying libraries and components, such as buffer overflows, improper input validation, and side-channel attacks. The vulnerabilities affect IBM Db2 for Linux, UNIX, and Windows (versions 10.5, 11.1, and 11.5) and related APM products.
CVE-2023-43020First seen Aug 22, 2026
CVE-2026-59285 is an unsafe deserialization vulnerability in Spring for GraphQL affecting pagination support. The issue arises when a Spring for GraphQL application processes paginated GraphQL queries and deserializes attacker-controlled JSON data through Jackson 2.x in an unsafe manner. Under the documented conditions, a maliciously crafted GraphQL request can trigger deserialization of attacker-influenced types and lead to remote code execution. The vulnerability is specifically associated with applications that expose paginated GraphQL fields and have deserializable classes present that can be abused as part of a gadget chain or equivalent deserialization path.
CVE-2026-59285First seen Aug 20, 2026
CVE-2026-53614First seen Aug 14, 2026
CVE-2026-53613First seen Aug 14, 2026
CVE-2026-53612First seen Aug 14, 2026
CVE-2026-47874 is a critical authentication bypass vulnerability affecting VMware vCenter. An attacker with network access to a vulnerable vCenter instance can bypass authentication controls and obtain unauthorized access to the system. The issue affects the vCenter authentication boundary rather than requiring prior valid credentials, making it remotely reachable in exposed deployments. The available information identifies the flaw as an authentication bypass in vCenter but does not provide function-level or code-path details.
CVE-2026-47874First seen Aug 2, 2026
CVE-2015-1509 is a reflected cross-site scripting vulnerability in Intland Software codeBeamer, reported in version 7.3.2-201410071117. The flaw allows arbitrarily supplied request parameters to be reflected by a web-accessible application component without sufficient sanitization or output encoding, enabling attacker-controlled script content to execute in a victim user's browser within the application's security context.
CVE-2015-1509First seen Aug 20, 2026
CVE-2015-1508 is a blind time-based SQL injection vulnerability in Brainworks Software XpanceNET affecting version 7.3.27 and earlier. The flaw is present in the UserID parameter, including in password-change request functionality, where insufficient neutralization of attacker-controlled input allows crafted SQL expressions to be processed by the backend database. Because the issue is blind and time-based, successful exploitation is inferred through response timing differences rather than direct error messages or query output. Depending on the privileges available to the application’s database context, the vulnerability can enable unauthorized interaction with the underlying database.
CVE-2015-1508First seen Aug 20, 2026
CVE-2014-6285 is a privilege escalation vulnerability in SAP Adaptive Server Enterprise (ASE) caused by an SQL injection flaw in replication support code. ASE contains an implementation flaw that allows SQL statements supplied through replication-related functionality to be executed without normal security checks. The issue affects users granted replication-related privileges and enables injected SQL to run in a more privileged context than intended. As a result, an authenticated user can abuse the vulnerable code path to elevate privileges within the database server, including escalation to administrative database roles.
CVE-2014-6285First seen Aug 20, 2026
CVE-2016-4013 is a SQL injection vulnerability in SAP Adaptive Server Enterprise (ASE) 16.0 SP02 introduced through Data Store Access Management (DSAM) support in CREATE DATABASE and ALTER DATABASE processing. When DSAM is configured, these statements perform additional logic to add specially named segments. A flaw in that implementation allows a low-privileged user to embed T-SQL code into the affected database-management workflow, causing attacker-controlled SQL to be executed with elevated privileges. The issue can lead to full compromise of the ASE server.
CVE-2016-4013First seen Aug 20, 2026
CVE-2016-6196 is an unrestricted file creation vulnerability in SAP Adaptive Server Enterprise. The flaw affects handling of the TRANSFER TABLE statement and allows a user who is permitted to execute that statement, including a table owner, to create files as the database server process owner. By abusing this capability, an attacker can place attacker-controlled files on the host and potentially create and load shared libraries into the database server process, resulting in code execution within the database server context.
CVE-2016-6196First seen Aug 20, 2026
CVE-2015-1413 is a cross-site scripting vulnerability in Magnolia CMS affecting version 5.3.6 Enterprise Edition and Community Edition, and possibly other versions. The flaw allows attacker-controlled script content to be injected into application output and executed in the browser of a user interacting with the vulnerable application. Successful exploitation occurs within the security context of the targeted user's session and can enable unauthorized client-side actions against the CMS.
CVE-2015-1413First seen Aug 20, 2026
CVE-2022-30267 is an operational technology firmware authenticity weakness affecting a Distributed Control System. The device does not cryptographically sign firmware images and relies only on insecure checksum-based integrity checks during firmware validation. As a result, the firmware update mechanism does not adequately verify the authenticity and trusted origin of firmware before accepting it. This creates a condition in which modified or malicious firmware can be treated as valid if it satisfies the weak checksum mechanism, undermining the trust model for firmware distribution and installation.
CVE-2022-30267First seen Mar 18, 2026
CVE-2026-59986 is a vulnerability affecting librabbitmq, an AMQP client library. Available information indicates that it is one of two security flaws addressed by Debian in librabbitmq for Debian 13. The issue may allow denial of service and, in the broader advisory context covering the affected librabbitmq vulnerabilities, potentially arbitrary code execution. Specific technical details such as the vulnerable function, root cause, and exact trigger condition are currently not available.
CVE-2026-59986First seen Aug 18, 2026
CVE-2026-55869 is a vulnerability in SRT, a latency-aware UDP streaming library. Available reporting associates this issue with Debian Security Advisory DSA-6450-1 and indicates that affected SRT versions may allow either denial of service or bypass of encryption protections. Specific technical details such as the vulnerable function, root cause, and exact trigger conditions are not currently available from the provided information.
CVE-2026-55869First seen Aug 19, 2026
CVE-2026-61547 is a vulnerability in librabbitmq, an AMQP client library. Available information indicates that this flaw is one of two security issues addressed in Debian Security Advisory DSA-6447-1 for Debian 13. The vulnerability may allow denial of service and could potentially lead to arbitrary code execution. Specific technical details about the root cause, affected functions, and trigger conditions are currently not available.
CVE-2026-61547First seen Aug 18, 2026
CVE-2026-55868 is one of two vulnerabilities addressed by Debian Security Advisory DSA-6450-1 in SRT, a latency-aware UDP streaming library. Available information confirms that the issue affects Debian 13 packages built from the srt source package and that exploitation may contribute to denial of service or bypass of encryption protections. Specific technical details about the vulnerable code path, root cause, and trigger conditions for CVE-2026-55868 are currently not available from the provided material.
CVE-2026-55868First seen Aug 19, 2026
CVE-2026-55107 is a sandbox escape vulnerability in the Kobako Ruby gem affecting versions 0.1.0 through 0.9.0. A guest mruby script executing inside the Kobako sandbox can abuse dispatcher behavior involving method_missing and public_send on bound Service objects to execute arbitrary Ruby in the host process. The flaw breaks the intended isolation boundary between untrusted mruby code and the embedding Ruby runtime, allowing attacker-controlled sandboxed code to invoke host-side functionality that should not be reachable from the sandbox.
CVE-2026-55107First seen Aug 18, 2026
CVE-2026-56101 is an OpenBSD vulnerability described as an inverted TKIP MIC-failure countermeasure test. The available public information indicates a logic flaw in the handling or evaluation of the TKIP MIC-failure countermeasure condition in OpenBSD’s wireless security processing. No retrievable public CVE record was available at the time of review, and no additional technical details about the affected code path, function, trigger conditions, or exact security consequences were provided.
CVE-2026-56101First seen Aug 19, 2026
CVE-2026-67418First seen Aug 19, 2026
CVE-2026-67419First seen Aug 19, 2026