NotCVE registry index — public records of vulnerabilities that shipped without a CVE
Full Disclosuremailing list archivesFrom: NotCVE Advisories <advisories () notcv 2026-7-21 05:35:32 Author: seclists.org(查看原文) 阅读量:9 收藏

fulldisclosure logo

Full Disclosure mailing list archives


From: NotCVE Advisories <advisories () notcve org>
Date: Thu, 16 Jul 2026 07:55:12 -0000

----------------------------------------------------------------------------
NotCVE Registry Index — 2026-07-16
----------------------------------------------------------------------------

[-] About the NotCVE registry:

NotCVE (https://notcve.org) assigns public identifiers to real, verifiable
vulnerabilities that did not receive a CVE — typically because the affected
vendor did not acknowledge the issue. Each record preserves the technical
details, affected products and disclosure timeline, and is never deleted: if
a CVE is assigned later, the entry keeps the original dates and cross-
references it.

A recent example: NotCVE-2026-0001 (Cloudflare Universal SSL CAA
augmentation, published 2026-01-19 without a CVE) was assigned
CVE-2026-14440 by the vendor 163 days later — which is exactly what this
registry is for. The original disclosure timeline is preserved. Details:
https://seclists.org/fulldisclosure/2026/Jul/22

[-] Current records:

[2026]

- Windows NTFS self-healing duplicate-name handling may allow delayed
  reparse point exposure from crafted file system images (CVSS 6.3)
  https://notcve.org/notcve/NotCVE-2026-0008
- Schlage/Allegion HandPunch Missing Authentication in TCP/3001 Management
  Protocol Allows Unauthenticated Remote Supervisor Enrollment and Data
  Disclosure (CVSS 9.8)
  https://notcve.org/notcve/NotCVE-2026-0007
- Hardcoded JWT Secret in ClawVet API Allows Session Token Forgery for
  Existing Users (CVSS 9.8)
  https://notcve.org/notcve/NotCVE-2026-0006
- Authenticated OS Command Injection via SSID in TP-Link TL-WR741ND V5 Web
  Management Interface (CVSS 8)
  https://notcve.org/notcve/NotCVE-2026-0005
- BestCrypt Volume Encryption improper signature-based sector bypass allows
  limited cleartext disclosure and plaintext injection (CVSS 5.7)
  https://notcve.org/notcve/NotCVE-2026-0004
- Deno @std/path isGlob quadratic runtime DoS prior to 1.1.2 (CVSS 5.9)
  https://notcve.org/notcve/NotCVE-2026-0003
- NetScaler ADC (VPX) before 14.1-60.52 missing SSH host key validation in
  HA/HA-INC synchronization can enable adversary-in-the-middle and root code
  execution (CVSS 7.5)
  https://notcve.org/notcve/NotCVE-2026-0002
- Cloudflare Universal SSL CAA augmentation may enable unauthorized DV
  certificate issuance by weakening RFC 8657 account binding (CVSS 8.7)
  https://notcve.org/notcve/NotCVE-2026-0001

[2025]

- Use of Vulnerable Go os.RemoveAll Enables Arbitrary Volume Deletion in
  Kubernetes (CVSS 7.5)
  https://notcve.org/notcve/NotCVE-2025-0003
- Symlink Race in Go os.RemoveAll Allows Privileged File Deletion (CVSS 7.5)
  https://notcve.org/notcve/NotCVE-2025-0004
- IBM Instana /auth/SignIn returnUrl Parameter Open Redirect (CVSS 4.1)
  https://notcve.org/notcve/NotCVE-2025-0002
- Docker Bridge Insufficient Isolation Allows LAN Access to Unpublished
  Ports (CVSS 6.5)
  https://notcve.org/notcve/NotCVE-2025-0001

[2024]

- Linux ASLR Weakness: Improper Bit-Mask Manipulation Reducing mmap Entropy
  by Half (CVSS 5.3)
  https://notcve.org/notcve/NotCVE-2024-0001
- AMD Bulldozer Linux ASLR weakness: Reducing entropy by 87.5% (CVSS 5.3)
  https://notcve.org/notcve/NotCVE-2024-0002

[2023]

- RSA signature verification bypass via Arbitrary Code Execution in Sansa
  Connect bootloader (CVSS 6.2)
  https://notcve.org/notcve/NotCVE-2023-0003
- Buffer overflow in NVD Tools (CVSS 7.5)
  https://notcve.org/notcve/NotCVE-2023-0002
- Secure Boot Bypass in MSM8916/APQ8016 Mobile SoC (CVSS 7.6)
  https://notcve.org/notcve/NotCVE-2023-0001

[-] What is next:

Each record will also be published individually on this list as a full
advisory (technical description, affected versions, timeline and
references), and new NotCVE IDs will be announced here as they are assigned.

[-] Requesting a NotCVE ID:

If you found a real, verifiable vulnerability and could not obtain a CVE for
it, you can request a NotCVE identifier at https://notcve.org/form/.
Anonymous and pseudonymous submissions are accepted. Submissions are
reviewed before publication, and researchers are credited in the NotCVE Hall
of Fame: https://notcve.org/hall/

--
NotCVE Advisories
advisories () notcve org · https://notcve.org
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/

Current thread:

  • NotCVE registry index — public records of vulnerabilities that shipped without a CVE NotCVE Advisories (Jul 20)

文章来源: https://seclists.org/fulldisclosure/2026/Jul/23
如有侵权请联系:admin#unsafe.sh