These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,109 reserved CVEs with public mentions, ranked by all-time mention count.
Page 7 of 45
CVE-2026-103951 is an out-of-bounds write vulnerability in Tenable Nessus versions earlier than 10.12.5. An authenticated, privileged attacker could exploit it to compromise Nessus confidentiality, integrity, or availability. The vulnerable function and triggering input are not identified. Nessus 10.12.5 resolves the vulnerability.
CVE-2026-103951First seen Oct 1, 2026
CVE-2026-103955 affects Tenable Nessus versions earlier than 10.12.5. Inadequate limits on resource consumption could allow an authenticated, privileged attacker to cause a denial of service. The vulnerable function and specific resource-exhaustion mechanism are not identified.
CVE-2026-103955First seen Oct 1, 2026
CVE-2026-103948 is an improper handling of inconsistent length values vulnerability in Tenable Nessus versions earlier than 10.12.5. An authenticated, privileged attacker could exploit the flaw to compromise Nessus confidentiality, integrity, or availability. The affected function and specific triggering input are not identified.
CVE-2026-103948First seen Oct 1, 2026
CVE-2026-103953 is a memory-management vulnerability in Tenable Nessus versions earlier than 10.12.5. An authenticated, privileged attacker could exploit it to cause denial of service. The specific vulnerable function and memory-management failure mechanism are not identified.
CVE-2026-103953First seen Oct 1, 2026
CVE-2026-103954 is an out-of-bounds read vulnerability in Tenable Nessus versions earlier than 10.12.5. An authenticated, privileged attacker could exploit it to disclose limited information from Nessus. The specific vulnerable function and triggering input are not identified. Nessus 10.12.5 fixes the vulnerability.
CVE-2026-103954First seen Oct 1, 2026
CVE-2026-63322 is a vulnerability affecting QEMU. Available severity information characterizes it as a local, low-complexity issue requiring high privileges and causing an availability-only impact. The underlying vulnerable component and flaw class have not been specified.
CVE-2026-63322First seen Aug 30, 2026
CVE-2026-71197 is a server-side request forgery vulnerability in the OpenStack Glance image service's web-download import functionality. Glance applies host filters to import URIs without first resolving DNS, allowing an authenticated attacker to bypass filtering with an attacker-controlled domain and DNS rebinding. The issue affects deployments using web-download import in Glance versions 16.0.0 through 30.2.0, 31.0.0 through 31.1.0, and 32.0.0 prior to 32.0.1.
CVE-2026-71197First seen Sep 3, 2026
CVE-2026-71196 is a server-side request forgery vulnerability in OpenStack Glance web-download image import. In affected deployments, insecure default URI filtering can allow an authenticated Glance user to cause the service to retrieve arbitrary internal URLs, including cloud metadata-service endpoints. The issue is part of the related OSSA-2026-038 Glance SSRF vulnerabilities.
CVE-2026-71196First seen Sep 3, 2026
CVE-2026-42394First seen Sep 25, 2026
CVE-2026-58099 is a use-after-free vulnerability in kqueue knote copying. When knotes are copied from a parent kqueue to a child, marker knotes are not correctly excluded before being marked in-flux and the kqueue lock is released. A concurrent thread can free a marker knote while the lock is dropped, after which the copying code decrements the in-flux state through freed memory.
CVE-2026-58099First seen Sep 29, 2026
CVE-2026-82987 is an unauthenticated input-injection vulnerability in ViewSonic vCast software on Android-based ViewBoard smart displays. Exposed vCast service endpoints accept arbitrary attacker-supplied input through HTTP requests, enabling unauthenticated users to send input commands to an affected device.
CVE-2026-82987First seen Sep 24, 2026
CVE-2026-96368 is one of 19 additional vulnerabilities affecting the Drupal Webform module that were remediated in the same Webform update as CVE-2026-96355. Specific vulnerable functionality, attack method, preconditions, and security impact for this CVE are not available.
CVE-2026-96368First seen Sep 24, 2026
CVE-2024-34735 is a high-severity elevation-of-privilege vulnerability in the Android Framework. It affects Android 12, Android 12L, and Android 13 devices that have not received the August 2024 security update.
CVE-2024-34735First seen Mar 18, 2026
CVE-2024-6993 is an inappropriate implementation vulnerability in the Canvas component of Google Chrome and Chromium. Technical details identifying the affected function, root cause, and exploitation mechanism have not been publicly provided in the available information.
CVE-2024-6993First seen Jul 30, 2026
CVE-2024-6992 is a high-severity out-of-bounds memory-access vulnerability in ANGLE, the graphics-translation component used by Google Chrome and Chromium. In affected versions before Chrome 127.0.6533.72, a remote attacker could trigger heap corruption through a crafted HTML page.
CVE-2024-6992First seen Jul 30, 2026
CVE-2026-15264 is an Important-severity vulnerability in QEMU. Available metadata identifies fixes in QEMU 11.1.0-rc3 and 11.0.4, but does not disclose the affected component, vulnerable function, root cause, or a technically reliable exploit path. The reported CVSS v3.1 vector indicates a local, low-complexity attack requiring low privileges and causing high confidentiality, integrity, and availability impact across a changed security scope.
CVE-2026-15264First seen Aug 30, 2026
CVE-2026-63323First seen Aug 30, 2026
CVE-2026-16288 is a QEMU vulnerability described as a Secure Boot bypass. The available information does not identify the affected component, vulnerable function, or precise bypass mechanism. QEMU addressed the issue in upstream releases 11.1.0-rc2 and 11.0.4.
CVE-2026-16288First seen Aug 30, 2026
CVE-2026-59185 is a high-severity cross-tenant authorization bypass in Identrail's GitHub App connection-completion workflow before version 1.0.2. The workflow validates that a pending connection state belongs to the authenticated caller's tenant, workspace, and project, but accepts a client-controlled GitHub App installation identifier without verifying that the installation belongs to the organization authorized for that workspace. The supplied identifier is persisted as the workspace's GitHub connection. Identrail can subsequently use its GitHub App credentials to mint an installation token for that linked installation. The feature-flagged V2 connector path reportedly contains the same unbound installation-identifier flaw and additionally resolves pending connectors by state without fully rechecking caller scope. The weakness is classified as CWE-639 and CWE-862.
CVE-2026-59185First seen Sep 10, 2026
CVE-2026-43603 is a NULL pointer dereference in the AMD GPU Linux kernel driver. The driver may fail to validate an internal data reference before using it when an application invokes a graphics-memory-management clear operation under certain compute-processing conditions. A local user can trigger a kernel failure that crashes the affected system.
CVE-2026-43603First seen Sep 9, 2026
CVE-2026-63320 is a QEMU vulnerability affecting Amazon Linux 2 and Amazon Linux 2023 QEMU packages. It permits unauthenticated network exploitation with an availability-only impact. The underlying vulnerable component and flaw class have not been specified.
CVE-2026-63320First seen Aug 30, 2026
CVE-2026-65928First seen Aug 30, 2026
CVE-2026-45710 is an unauthenticated denial-of-service vulnerability in Mailpit JSON-body API handlers. The affected handlers accept request bodies without enforcing a maximum size; attacker-supplied oversized JSON arrays are parsed and processed, resulting in disproportionate process-memory allocation and additional linear processing and database-update work. The issue affects message read-status updates, message deletion, message-tag updates, and message-release functionality.
CVE-2026-45710First seen Jul 2, 2026
CVE-2023-42219 is an Exim vulnerability associated with DNS resolution handling. It was reported as a limited information-disclosure issue when Exim relies on an untrusted DNS resolver. Available information does not identify the vulnerable function or disclose further technical exploitation mechanics. Some reporting inconsistently identifies this issue as CVE-2023-42119; the advisory mapping associates CVE-2023-42219 with Exim bug 3033.
CVE-2023-42219First seen Apr 14, 2026
CVE-2026-80256 is a Windows-only path traversal vulnerability in wcurl. wcurl percent-decodes output filenames, including percent-encoded backslashes. An attacker-controlled output filename can therefore introduce Windows directory separators after decoding and cause a newly created file to be written outside the directory selected by the user. The behavior affects wcurl bundled with curl 8.14.0 through 8.21.0 and standalone wcurl 2024.12.08 through 2026.01.05.
CVE-2026-80256First seen Sep 2, 2026