Skip to main content

Daily materialized evidence profile

CWE CWE-502

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
3,023
CVEs with mentions
1,312
Total mentions
4,211
CVEs with KEV
75
CVEs with PoC
42

Attack vector counts

Network
2,592
Adjacent network
71
Local
358
Physical
2

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2025-55182

Published Dec 3, 2025

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-serv…

CVSS 10.0 · Critical
evidence mentions
55
Buzz score
93.0
KEV listedPublic PoC observed

CVE-2021-44228

Published Dec 10, 2021

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect aga…

CVSS 10.0 · Critical
evidence mentions
179
Buzz score
80.5
KEV listedPublic PoC observed

CVE-2026-45659

Published May 22, 2026

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVSS 8.8 · High
evidence mentions
23
Buzz score
79.6
KEV listedPublic PoC observed

CVE-2025-53770

Published Jul 20, 2025

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for…

CVSS 9.8 · Critical
evidence mentions
52
Buzz score
79.5
KEV listedPublic PoC observed

CVE-2025-24813

Published Mar 10, 2025

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Defa…

CVSS 9.8 · Critical
evidence mentions
21
Buzz score
79.5
KEV listedPublic PoC observed