These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,109 reserved CVEs with public mentions, ranked by all-time mention count.
Page 8 of 45
First seen Aug 2, 2026
CVE-2022-30267 affects a Distributed Control System that does not authenticate firmware images with cryptographic signatures. Firmware integrity is checked only through insecure checksum mechanisms, which do not establish image origin or provide robust protection against modification. As a result, the system can accept firmware whose authenticity has not been adequately verified.
CVE-2022-30267First seen Mar 18, 2026
First seen Aug 26, 2026
CVE-2014-8273 is a race condition in chipset BIOS write protection enforcement. When an attempt is made to enable BIOS writes despite a protection lock, an interrupt handler detects the condition and resets the write-enable state. The reset is not atomic with detection, creating a timing window in which an attacker can issue BIOS write operations before the write-enable bit is cleared.
CVE-2014-8273First seen Jan 25, 2026
CVE-2025-33143 is an uncontrolled recursion vulnerability in IBM Db2 for Linux, UNIX, and Windows, including Db2 Connect Server. An authenticated user can submit a specially crafted SQL statement that triggers uncontrolled recursive processing, resulting in denial of service. IBM Tivoli Business Service Manager versions 6.2.0.0 through 6.2.0.6 are affected where they include the vulnerable Db2 JDBC driver in the XMLToolkit component.
CVE-2025-33143First seen Aug 22, 2026
CVE-2025-6243 is a credential-management vulnerability in RUCKUS Network Director (RND). The platform contains a built-in user account, sshuser, that has root privileges, and both the public and private SSH keys for that account are stored in the account's home directory. Possession of the private key enables SSH authentication as the built-in privileged user. Because the account is pre-existing and highly privileged, the flaw effectively exposes a built-in administrative access path that can be used to obtain shell access on the affected RND server.
CVE-2025-6243First seen Jan 17, 2026
CVE-2026-10631 is an access control vulnerability affecting the EWS extension in Zimbra Collaboration Suite. Publicly available information identifies the issue only at a high level as an access control flaw in the EWS component, without disclosing the specific vulnerable function, request path, or authorization logic failure. The vulnerability was addressed in Zimbra Collaboration Suite 10.1.20 as part of a broader security update.
CVE-2026-10631First seen Jul 21, 2026
CVE-2026-50054 is an authorization vulnerability in Zimbra Collaboration Suite affecting mailbox delegation functionality. The flaw is described as an authorization issue in mailbox delegation, indicating that access control enforcement for delegated mailbox operations is insufficient or improperly implemented. Specific vulnerable functions, affected code paths, and exploitation details are not publicly available in the provided information. The issue was addressed in Zimbra Collaboration Suite 10.1.20 as part of a broader security update.
CVE-2026-50054First seen Jul 21, 2026
First seen Feb 4, 2026
CVE-2026-28311 is a critical remote code execution vulnerability in SolarWinds Serv-U file transfer software. It is one of the most severe flaws addressed in Serv-U version 2026.3. Successful exploitation can allow an attacker to execute arbitrary or malicious commands on an affected Serv-U system remotely. Available reporting indicates the broader Serv-U vulnerability set includes access control and privilege-related weaknesses, but specific technical details for the vulnerable component, function, or root cause of CVE-2026-28311 are not currently available.
CVE-2026-28311First seen Jul 22, 2026
First seen Jul 31, 2026
CVE-2025-8094 is a high-severity improper handling of permissions vulnerability in the GitLab Community Edition and Enterprise Edition project API. Under certain conditions, authenticated users with maintainer privileges could manipulate shared infrastructure resources beyond their intended access level through the project API. The flaw stems from insufficient permission enforcement in API operations governing access to shared CI/CD-related infrastructure resources, allowing a maintainer to act outside the intended authorization boundary. GitLab addressed the issue by refining permission checks within the project API to enforce proper access controls.
CVE-2025-8094First seen Jun 12, 2026
CVE-2026-55614 is a high-severity HTTP request smuggling vulnerability in OpenWrt's uhttpd web server on keep-alive connections. The flaw is caused by case-sensitive matching of the Transfer-Encoding header, which can lead to inconsistent interpretation of message framing when different HTTP components in the request path parse the same request differently. This parser discrepancy can desynchronize request boundaries and allow a crafted request to be interpreted as multiple requests or to cause a subsequent request on the same connection to be misframed.
CVE-2026-55614First seen Jun 30, 2026
CVE-2026-55613 is a moderate HTTP request desynchronization vulnerability in OpenWrt's uhttpd web server affecting ubus POST request handling on keep-alive connections. The flaw is triggered when a ubus POST body encounters a parse error, causing request parsing state to become desynchronized rather than cleanly terminating or isolating the malformed request. This can break message boundary handling between successive HTTP requests on the same connection and create a request smuggling condition in front-end/back-end or client/server parsing flows.
CVE-2026-55613First seen Jun 30, 2026
CVE-2026-55612 is a high-severity HTTP request smuggling vulnerability in OpenWrt's uhttpd web server. The flaw affects request processing on keep-alive connections and is caused by an invalid reset of parser state related to chunk-length handling during HTTP message framing. This can cause uhttpd to misinterpret request boundaries when processing chunked request bodies, leading to front-end/back-end desynchronization conditions. In deployments where uhttpd is reachable by an attacker, a crafted sequence of HTTP requests can be used to smuggle a second request across a persistent connection and have it processed out of sync with the visible request stream.
CVE-2026-55612First seen Jun 30, 2026
CVE-2026-53920 is a high-severity information disclosure vulnerability in OpenWrt's odhcpd DHCPv6 service. The flaw is triggered when odhcpd processes a truncated DHCPv6 IA_NA or IA_PD option, leading to disclosure of stack memory. The issue affects the DHCPv6 Identity Association handling path in a default-enabled core network service and is reachable by a network-adjacent attacker able to send crafted DHCPv6 traffic to the target device.
CVE-2026-53920First seen Jun 30, 2026
CVE-2026-31022First seen Apr 16, 2026
CVE-2026-39212 is a stack-based buffer overflow vulnerability in FFmpeg affecting ffmpeg_opt.c. The issue is described as a regression introduced in July 2025 and impacts FFmpeg command-line parsing or option-processing logic implemented in that source file. Successful exploitation occurs when attacker-controlled input reaches the vulnerable stack-resident buffer handling path, causing memory corruption through out-of-bounds writes on the stack. As a memory corruption flaw in a widely deployed media-processing framework, the vulnerability can lead to process instability and potentially more serious compromise depending on the surrounding execution context and exploitability of the overwritten stack data.
CVE-2026-39212First seen Jun 6, 2026
CVE-2026-39214 is a stack buffer overflow vulnerability in FFmpeg's Service Description Table (SDT) implementation. The flaw was reportedly introduced in 2003 and remained latent for many years. Based on the available information, the issue arises from unsafe handling of attacker-controlled input in SDT parsing logic, resulting in data being written past the bounds of a stack-allocated buffer. As a memory corruption flaw in media parsing code, successful exploitation could occur when FFmpeg processes a crafted media stream or container carrying malicious SDT data.
CVE-2026-39214First seen Jun 6, 2026
CVE-2026-39213 is a heap buffer overflow vulnerability in FFmpeg’s yuv4mpegenc component. The issue was reported as having been introduced in 2023. Available information identifies the flaw class and affected component, but does not provide the specific vulnerable function, code path, or triggering input structure. Successful exploitation would involve crafted media-processing input reaching the yuv4mpegenc encoding path and causing an out-of-bounds write on heap-allocated memory.
CVE-2026-39213First seen Jun 6, 2026
CVE-2026-39215 is a heap buffer overflow vulnerability in FFmpeg in the function update_mb_info(). The flaw was reportedly introduced in 2012. The available information identifies it as one of a set of FFmpeg memory-corruption issues affecting media-processing code paths. A crafted media input processed by the vulnerable code can cause out-of-bounds writes on the heap, leading to memory corruption and potentially destabilizing the process or enabling further exploitation, depending on allocator behavior and surrounding memory layout. Specific details about the exact source file, triggering format, and the precise bounds-checking failure are not currently available from the provided information.
CVE-2026-39215First seen Jun 6, 2026
CVE-2026-39211 is an integer overflow vulnerability in FFmpeg's swscale component. The issue was reportedly introduced in 2010. The available information identifies the flaw class and affected subsystem, but does not provide the specific vulnerable function, code path, trigger condition, or memory-safety consequences beyond the presence of an integer overflow. swscale is used for image scaling and pixel format conversion, so malformed or attacker-controlled media inputs that reach this processing path could potentially trigger incorrect size or arithmetic calculations during scaling operations.
CVE-2026-39211First seen Jun 6, 2026
CVE-2026-39217 is a heap buffer overflow vulnerability in FFmpeg's VP9 decoder. The issue is described as a regression introduced in March 2025. Successful exploitation occurs when the decoder processes attacker-controlled VP9 media data and performs an out-of-bounds write on heap-allocated memory. As a memory corruption flaw in a media parsing and decoding path, the vulnerability can be triggered during handling of crafted VP9 content by applications or services that rely on FFmpeg for decoding.
CVE-2026-39217First seen Jun 6, 2026
CVE-2026-39216 is a heap buffer overflow vulnerability in FFmpeg affecting code in img2enc.c. The flaw was reportedly introduced in 2012. The available information identifies the bug class and affected source file, but does not provide further technical detail about the specific vulnerable function, trigger condition, or parsing pathway. Successful exploitation would involve causing FFmpeg to perform an out-of-bounds write on heap-allocated memory while processing attacker-controlled input that reaches the vulnerable img2enc.c code path.
CVE-2026-39216First seen Jun 6, 2026
CVE-2026-53582 is a stored XPath injection vulnerability in OPNsense affecting certificate authority management functionality exposed through the trust and CA management API. The flaw arises because a user-controllable reference identifier field is incorporated into an XPath expression executed against the system configuration without sufficient validation or neutralization of XPath metacharacters. Specifically, the vulnerable logic performs an XPath lookup using attacker-influenced input when resolving references in the configuration data, allowing a low-privileged user with certificate-related management permissions to persist a crafted payload and later trigger XPath evaluation against config.xml. This enables extraction of sensitive configuration values through a boolean oracle exposed by API responses. Disclosed examples include private keys, password hashes, synchronization credentials, and API secrets stored in the configuration. The issue can result in privilege escalation and may create a path to remote code execution depending on the secrets exposed and the deployment context.
CVE-2026-53582First seen Jul 7, 2026