These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,109 reserved CVEs with public mentions, ranked by all-time mention count.
Page 9 of 45
First seen Jul 1, 2026
CVE-2024-13745 is a flaw in EDK II’s GPT measurement and parsing logic that allows the GUID Partition Table layout or metadata actually used by firmware to differ from what is measured into TPM PCR[5]. According to the disclosure, affected versions include EDK II releases up to and including edk2-stable202411, and later versions may also be affected because no fix was known at disclosure time. The issue arises from inconsistencies between DxeTpm2MeasureBootLib, which measures GPT data for TPM event logging, and PartitionDxe, which parses, validates, and may recover GPT structures for actual use. DxeTpm2MeasureBootLib reads the GPT header from LBA 1, applies comparatively relaxed validation, does not validate CRC32 checksums, does not consult the backup GPT header, and omits unused GPT partition entries from the measured structure. PartitionDxe, by contrast, performs stricter validation, reads both primary and backup GPT headers, and includes recovery logic. The disclosure further describes error-handling flaws in PartitionRestoreGptTable() and PartitionValidGptTable() where failures can leave PrimaryHeader populated with untrusted invalid data while execution continues down a path treating both GPT tables as valid. An attacker can exploit these discrepancies by preserving the GPT data that DxeTpm2MeasureBootLib measures while causing PartitionDxe to recover or use a different GPT header and partition entry array, including via malformed backup GPT headers and attacker-controlled AlternateLBA values. The result is a data-only integrity failure in which PCR[5] and TPM event logs can indicate an expected GPT state while firmware and the operating system use attacker-influenced partition layout or metadata.
CVE-2024-13745First seen May 29, 2026
CVE-2026-33224 affects Bisheng and is described in the provided reporting as an authenticated remote command execution vulnerability in Bisheng's MCP tool/server configuration functionality. The issue is tied to unsafe handling of Model Context Protocol (MCP) STDIO-based server configuration, where attacker-controlled command and argument values can be introduced into local process execution without adequate sanitization or restriction. In the reported exploitation pattern, a user able to access Bisheng's MCP configuration workflow can register or modify an MCP tool/server definition so that Bisheng launches an attacker-specified operating system command on the host running the application. The reporting places this issue in a broader family of MCP STDIO command-injection flaws propagated through unsafe SDK and application design. It also notes that Bisheng's open user registration lowers the barrier to obtaining the authenticated access needed for exploitation.
CVE-2026-33224First seen Apr 20, 2026
CVE-2021-35406 is a command injection vulnerability in the Prolink PRC2402M router, tested on firmware version 20190909. Based on the provided supporting content, the flaw is in the /cgi-bin/qos.cgi CGI handler. When the page parameter is set to qos, the qos_settings routine processes attacker-controlled parameters including qos_dat and qos_bandwidth, uses sprintf to embed them into shell command strings, and executes the resulting command via do_system, a wrapper around system, without sufficient input validation or sanitization. This allows arbitrary shell metacharacters or command substitution to be injected through HTTP POST parameters. The provided proof of concept uses a crafted POST request to /cgi-bin/qos.cgi with page=qos and a malicious qos_dat value such as $(echo gg>/tmp/gg) to demonstrate code execution.
CVE-2021-35406First seen Apr 11, 2026
CVE-2026-34485 is a Nokia vulnerability described in the available advisory context as a CLI ACL bypass affecting Nokia GX G42, GX G31, GX G32, and GX G34 devices running versions prior to GX r9.0. Based on the provided information, the flaw allows command-line interface access-control restrictions to be bypassed. The available source material does not identify the specific vulnerable function, code path, or protocol handling logic responsible for the bypass.
CVE-2026-34485First seen Mar 31, 2026
CVE-2024-35347 is a vulnerability in AMD CPUs, specifically affecting the microcode signature verification process. The flaw allows systems to accept microcode updates that lack the critical microcode signing fix, leaving them exposed to potential exploitation. The vulnerability primarily impacts AMD Family 19h CPUs and is documented in AMD security bulletin AMD-SB-7033. The root cause is insufficient enforcement of microcode signature verification, which can only be fully remediated by applying a BIOS update that delivers the updated microcode with the signing fix. Without this update, systems remain vulnerable even if they receive microcode updates from the Linux firmware repository, as these do not address the underlying signature verification issue.
CVE-2024-35347First seen Mar 18, 2026
First seen Mar 18, 2026
First seen Mar 18, 2026
CVE-2025-29617 is a critical vulnerability in the Piciorgros TMO-100 data modem for TETRA radio networks. The device exposes an unauthenticated TFTP service on both LAN and TETRA data networks, allowing any network-adjacent attacker to read and modify the modem's configuration. The configuration file contains sensitive information such as PPP credentials and network settings. Attackers can leverage this to alter port forwarding, disrupt modem operation, or facilitate further attacks. The issue affects software versions below 4.20, where TFTP access is unrestricted and unauthenticated.
CVE-2025-29617First seen Mar 18, 2026
First seen Oct 8, 2026
First seen Oct 8, 2026
First seen Oct 8, 2026
First seen Oct 8, 2026
First seen Oct 7, 2026
First seen Oct 7, 2026
First seen Oct 7, 2026
First seen Oct 7, 2026
First seen Oct 7, 2026
First seen Oct 7, 2026
First seen Oct 7, 2026
First seen Oct 7, 2026
First seen Oct 7, 2026
First seen Oct 7, 2026
First seen Oct 6, 2026
CVE-2013-0808 is a vulnerability in the Hancom Hangul Office Suite (HWP), specifically in the handling of Encapsulated PostScript (EPS) objects. The vulnerability allows for arbitrary code execution when a user opens a maliciously crafted HWP document containing a specially crafted EPS object. This flaw was actively exploited by threat actors, notably Group 123, as an initial infection vector in targeted spear phishing campaigns against South Korean entities.
CVE-2013-0808First seen Aug 14, 2026