Skip to main content Loading the latest cvebuzz view.
Search the full CVE archive | cvebuzz
Historical archive search
Search the full CVE archive Search decades of CVEs by regex, severity, date, CWE, vendor/product tags, KEV, PoC, and other evidence.
Years with data 28
Top vendors indexed 100 Filters Refine the archive + 16 results · Sorted by Highest Buzz score first
Modoboa is a mail hosting and management platform. Prior to version 2.7.1, `exec_cmd()` in `modoboa/lib/sysutils.py` always runs subprocess calls with `shell=True`. Since domain n…
CVSS 7.2 · High
evidence mentions 3
Buzz score 18.9 Vendor/product tags Beta · best-effort
Network
Adjacent network
Local
Physical
Year Any year 2026 (44,720) 2025 (48,162) 2024 (39,957) 2023 (28,817) 2022 (25,074) 2021 (20,149) 2020 (18,322) 2019 (17,305) 2018 (16,510) 2017 (14,642) 2016 (6,449) 2015 (6,494) 2014 (7,928) 2013 (5,187) 2012 (5,288) 2011 (4,150) 2010 (4,639) 2009 (5,732) 2008 (5,632) 2007 (6,516) 2006 (6,608) 2005 (4,932) 2004 (2,451) 2003 (1,527) 2002 (2,156) 2001 (1,676) 2000 (1,019) 1999 (894)
CWE Enter a numeric ID such as 79 or the prefixed form CWE-79.
Only show CVEs with KEV evidence
Only show CVEs with public PoC evidence
Only show CVEs with mention evidence
Only show CVEs with AlienVault OTX activity
Sort Highest Buzz score first Newest published first Oldest published first Highest CVSS first Lowest CVSS first Most mentioned first
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.2.2.
CVSS 8.8 · High Vendor/product tags Beta · best-effort
Cross-site Scripting (XSS) - DOM in GitHub repository modoboa/modoboa prior to 2.2.2.
CVSS 5.4 · Medium Vendor/product tags Beta · best-effort
Cross-site Scripting (XSS) - DOM in GitHub repository modoboa/modoboa prior to 2.2.2.
CVSS 5.4 · Medium Vendor/product tags Beta · best-effort
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.1.0.
CVSS 6.8 · Medium Vendor/product tags Beta · best-effort
Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.
CVSS 9.1 · Critical Vendor/product tags Beta · best-effort
Weak Password Requirements in GitHub repository modoboa/modoboa prior to 2.1.0.
CVSS 6.3 · Medium Vendor/product tags Beta · best-effort
Cross-site Scripting (XSS) - Reflected in GitHub repository modoboa/modoboa prior to 2.0.5.
CVSS 4.8 · Medium Vendor/product tags Beta · best-effort
Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4.
CVSS 7.5 · High Vendor/product tags Beta · best-effort
Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4.
CVSS 9.8 · Critical Vendor/product tags Beta · best-effort
Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4.
CVSS 5.4 · Medium Vendor/product tags Beta · best-effort
Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4.
CVSS 5.4 · Medium Vendor/product tags Beta · best-effort
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
CVSS 6.5 · Medium Vendor/product tags Beta · best-effort
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
CVSS 4.3 · Medium Vendor/product tags Beta · best-effort
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
CVSS 6.5 · Medium Vendor/product tags Beta · best-effort
The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to perform…
CVSS 7.5 · High Vendor/product tags Beta · best-effort
Showing 1-16 of 16 CVEs Page 1 of 1
About these shareable results + Every filter state lives in the URL so you can bookmark, share, and crawl exact historical slices instead of a client-only search session.
Buzz order uses the latest all-time evidence snapshot, refreshed every two hours. Evidence-bearing CVEs rank first; records without a snapshot continue newest-first.