These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,178 reserved CVEs with public mentions, ranked by all-time mention count.
Page 7 of 48
CVE-2026-67416First seen Aug 19, 2026
CVE-2026-67420First seen Aug 19, 2026
CVE-2026-67421First seen Aug 19, 2026
First seen Aug 19, 2026
CVE-2014-8273 is a race-condition vulnerability in chipset firmware write-protection handling for BIOS flash access. The issue occurs between the point at which an interrupt handler detects an attempt to set BIOS write-enable in violation of the lock bit and the point at which the handler clears the write-enable bit again. During this timing window, an attacker can perform unauthorized BIOS writes before protection is reasserted. The weakness is a synchronization failure in security-critical logic protecting firmware flash, enabling bypass of intended BIOS lock enforcement and potentially allowing persistent modification of platform firmware.
CVE-2014-8273First seen Jan 25, 2026
CVE-2026-73554 is a critical authentication bypass vulnerability in Dolt MCP affecting versions 0.3.1 through 0.3.6 when deployed with remote HTTP transport and JWT authentication enabled. The flaw arises from two conditions in the request handling chain: JWT rejection logic writes an HTTP 401 response for an invalid token but does not terminate execution because the middleware omits a return statement, and session validation in the underlying mcp-go implementation accepts forged session identifiers matching an expected format without verifying that the session was actually created by the server. By combining an invalid JWT with a crafted session identifier, an unauthenticated attacker can bypass intended access controls, reach the MCP tool dispatcher, and invoke database operations through the server context despite failed authentication. A notable characteristic is that the server may still return HTTP 401 Unauthorized while including the result of the unauthorized operation in the response body.
CVE-2026-73554First seen Aug 16, 2026
CVE-2024-7952 is a high-severity exposure of sensitive information to an unauthorized actor vulnerability affecting Rockwell Automation DataMosaix Private Cloud version 7.07 and earlier. The flaw is classified as CWE-200. Successful exploitation can expose customer data to actors who are not authorized to access it. Specific vulnerable functions or code paths are not available from the provided information.
CVE-2024-7952First seen Apr 24, 2026
CVE-2024-6993 is an inappropriate implementation vulnerability in the Canvas component of Google Chrome and Chromium. Publicly available information identifies the affected subsystem but does not provide sufficient technical detail about the specific vulnerable function, root cause mechanics, or trigger conditions. The issue was addressed by Google as part of a broader Chrome security update.
CVE-2024-6993First seen Jul 30, 2026
CVE-2024-6992 is an out-of-bounds memory access vulnerability in ANGLE, the graphics abstraction layer used by Chromium-based browsers including Google Chrome. The flaw arises from improper bounds checking during memory access in ANGLE, which can cause the component to read from or access memory outside the intended buffer boundaries. In the browser context, such memory-safety flaws in graphics processing paths can be triggered by crafted content that exercises vulnerable rendering functionality.
CVE-2024-6992First seen Jul 30, 2026
CVE-2018-1579 is an authentication bypass vulnerability affecting Palo Alto Networks PAN-OS GlobalProtect portal and gateway functionality. The issue allows an unauthenticated remote attacker to bypass normal authentication controls on exposed VPN infrastructure under affected conditions. Public reporting associates the vulnerability with intrusion activity in which attackers used vulnerable VPN appliances as an initial access vector into enterprise environments.
CVE-2018-1579First seen Aug 14, 2026
First seen Jul 10, 2026
First seen Aug 14, 2026
First seen Apr 9, 2026
First seen Aug 5, 2026
First seen Aug 3, 2026
CVE-2026-25290 is a denial-of-service vulnerability in PHP’s pdo_pgsql driver. The flaw is reachable when an application explicitly enables emulated prepared statements and passes a query parameter containing a byte sequence that is invalid for the active PostgreSQL connection character encoding. In this condition, PostgreSQL’s client library may fail silently and return a NULL escaped string rather than a valid escaped value. PDO’s query handling logic then attempts to read the length of that NULL value, resulting in a null-pointer dereference and an immediate crash of the PHP process. The issue affects the interaction between PDO’s emulated prepare path and libpq error handling for malformed multibyte input.
CVE-2026-25290First seen Jul 7, 2026
First seen Aug 2, 2026
CVE-2023-20713First seen May 26, 2026
First seen Jul 31, 2026
CVE-2026-57152First seen Jul 27, 2026
CVE-2024-34735 is a high-severity elevation-of-privilege vulnerability in the Android Framework component. It is listed in the Android Security Bulletin for August 2024 as one of the Framework issues addressed by the 2024-08-01 security patch level. Available information indicates the flaw can lead to local elevation of privilege on affected Android devices. Specific details about the vulnerable function, root cause, and exploitation mechanism are not publicly available in the provided material.
CVE-2024-34735First seen Mar 18, 2026
CVE-2026-15916 is a vulnerability in Drupal CMS that was addressed as part of a set of security fixes released in July 2026. Available information indicates the flaw allows remote code injection in the browser context through cross-site scripting (XSS). The issue affects vulnerable Drupal releases prior to the fixed versions and may enable attacker-supplied script content to be executed in a victim user's session. Specific details about the affected component or function are not currently available.
CVE-2026-15916First seen Jul 16, 2026
CVE-2026-53625First seen Jul 27, 2026
CVE-2026-47678 is one of multiple vulnerabilities fixed in GLPI 10.0.26 and 11.0.8. Affected versions prior to those releases contain a flaw that, in the broader set of patched issues, may contribute to cross-site scripting, SQL injection, security control bypass, data confidentiality and integrity compromise, or privilege escalation. Specific technical details for this individual CVE, including the vulnerable component or function, are currently not available.
CVE-2026-47678First seen Jul 27, 2026
First seen May 26, 2026