Skip to main content

Daily materialized evidence profile

CWE CWE-285

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
1,501
CVEs with mentions
838
Total mentions
3,104
CVEs with KEV
1
CVEs with PoC
67

Attack vector counts

Network
1,280
Adjacent network
29
Local
173
Physical
19

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2021-28799

Published May 13, 2021

An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in…

CVSS 10.0 · Critical
evidence mentions
15
Buzz score
67.2
KEV listed

CVE-2026-33186

Published Mar 20, 2026

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-head…

CVSS 9.1 · Critical
evidence mentions
223
Buzz score
48.0

CVE-2025-29927

Published Mar 21, 2025

Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypa…

CVSS 9.1 · Critical
evidence mentions
15
Buzz score
47.7

CVE-2026-54121

Published Jul 14, 2026

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

CVSS 8.8 · High
evidence mentions
14
Buzz score
47.1

CVE-2026-45490

Published Jun 9, 2026

Improper authorization in .NET allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
6
Buzz score
39.0