Skip to main content Loading the latest cvebuzz view.
Search the full CVE archive | cvebuzz
Historical archive search
Search the full CVE archive Search decades of CVEs by regex, severity, date, CWE, vendor/product tags, KEV, PoC, and other evidence.
Years with data 28
Top vendors indexed 100 Filters Refine the archive + 40 results · Sorted by Highest Buzz score first
FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-filling newly allocated clusters. This maps to CWE-908 (Use…
CVSS 4.6 · Medium
evidence mentions 6
Buzz score 42.0
Network
Adjacent network
Local
Physical
Year Any year 2026 (43,229) 2025 (48,162) 2024 (39,957) 2023 (28,817) 2022 (25,074) 2021 (20,149) 2020 (18,322) 2019 (17,305) 2018 (16,510) 2017 (14,642) 2016 (6,449) 2015 (6,494) 2014 (7,928) 2013 (5,187) 2012 (5,288) 2011 (4,150) 2010 (4,639) 2009 (5,732) 2008 (5,632) 2007 (6,516) 2006 (6,608) 2005 (4,932) 2004 (2,451) 2003 (1,527) 2002 (2,156) 2001 (1,676) 2000 (1,019) 1999 (894)
CWE Enter a numeric ID such as 79 or the prefixed form CWE-79.
Only show CVEs with KEV evidence
Only show CVEs with public PoC evidence
Only show CVEs with mention evidence
Only show CVEs with AlienVault OTX activity
Sort Highest Buzz score first Newest published first Oldest published first Highest CVSS first Lowest CVSS first Most mentioned first
Beta · best-effort
In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers
Currently, when nvmet_tcp_build_pdu_io…
CVSS 9.8 · Critical
evidence mentions 9
Buzz score 39.5 Vendor/product tags Beta · best-effort
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
CVSS 9.8 · Critical
evidence mentions 7
Buzz score 38.3 Vendor/product tags Beta · best-effort
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
CVSS 3.7 · Low
evidence mentions 4
Buzz score 36.1 Vendor/product tags Beta · best-effort
libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup p…
CVSS 8.3 · High
evidence mentions 5
Buzz score 34.4 Vendor/product tags Beta · best-effort
In the Linux kernel, the following vulnerability has been resolved:
fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
FUSE_NOTIFY_RETRIEVE must be limited to uptodate folios;…
CVSS 5.5 · Medium
evidence mentions 9
Buzz score 33.0 Vendor/product tags Beta · best-effort
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_exthdr: fix register tracking for F_PRESENT flag
nft_exthdr_init() passes user-controlled priv…
CVSS 5.5 · Medium
evidence mentions 9
Buzz score 33.0 Vendor/product tags Beta · best-effort
In the Linux kernel, the following vulnerability has been resolved:
sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
__sctp_rcv_asconf_lookup() in net/sctp/input.c only chec…
CVSS 9.1 · Critical
evidence mentions 9
Buzz score 33.0 Vendor/product tags Beta · best-effort
Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
CVSS 5.5 · Medium
evidence mentions 5
Buzz score 32.4 Vendor/product tags Beta · best-effort
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVSS 6.5 · Medium
evidence mentions 5
Buzz score 32.4 Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVSS 5.5 · Medium
evidence mentions 5
Buzz score 32.4 Vendor/product tags Beta · best-effort
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS 7.8 · High
evidence mentions 5
Buzz score 32.4 Vendor/product tags Beta · best-effort
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.
CVSS 6.5 · Medium
evidence mentions 5
Buzz score 32.4 Vendor/product tags Beta · best-effort
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVSS 6.5 · Medium
evidence mentions 5
Buzz score 32.4 Vendor/product tags Beta · best-effort
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVSS 6.5 · Medium
evidence mentions 5
Buzz score 32.4 Vendor/product tags Beta · best-effort
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVSS 6.5 · Medium
evidence mentions 5
Buzz score 32.4 Vendor/product tags Beta · best-effort
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.
CVSS 5.5 · Medium
evidence mentions 4
Buzz score 29.1 Vendor/product tags Beta · best-effort
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.
CVSS 7.1 · High
evidence mentions 4
Buzz score 29.1 Vendor/product tags Beta · best-effort
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
CVSS 5.5 · Medium
evidence mentions 4
Buzz score 29.1 Vendor/product tags Beta · best-effort
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVSS 6.5 · Medium
evidence mentions 4
Buzz score 29.1 Vendor/product tags Beta · best-effort
Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
CVSS 6.5 · Medium
evidence mentions 4
Buzz score 29.1 Vendor/product tags Beta · best-effort
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
CVSS 5.5 · Medium
evidence mentions 4
Buzz score 29.1 Vendor/product tags Beta · best-effort
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
CVSS 5.5 · Medium
evidence mentions 4
Buzz score 29.1 Vendor/product tags Beta · best-effort
Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.
CVSS 5.5 · Medium
evidence mentions 4
Buzz score 29.1 Vendor/product tags Beta · best-effort
Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.
CVSS 5.5 · Medium
evidence mentions 4
Buzz score 29.1 Vendor/product tags Beta · best-effort
Showing 1-25 of 40 CVEs Page 1 of 2
Previous 1 2 Next About these shareable results + Every filter state lives in the URL so you can bookmark, share, and crawl exact historical slices instead of a client-only search session.
Buzz order uses the latest all-time evidence snapshot, refreshed every two hours. Evidence-bearing CVEs rank first; records without a snapshot continue newest-first.