Skip to main content

Daily materialized evidence profile

CWE CWE-601

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
1,648
CVEs with mentions
531
Total mentions
1,099
CVEs with KEV
2
CVEs with PoC
5

Attack vector counts

Network
1,611
Adjacent network
18
Local
15
Physical
4

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2021-38000

Published Nov 23, 2021

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a c…

CVSS 6.1 · Medium
evidence mentions
7
Buzz score
53.8
KEV listed

CVE-2025-3155

Published Apr 3, 2025

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents,…

CVSS 7.4 · High
evidence mentions
16
Buzz score
44.3

CVE-2025-57665

Published Sep 9, 2025

Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction gap that obscures URL-based a…

CVSS 6.4 · Medium
evidence mentions
5
Buzz score
37.4
Public PoC observed

CVE-2024-8883

Published Sep 19, 2024

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http:…

CVSS 6.1 · Medium
evidence mentions
17
Buzz score
36.9

CVE-2025-0244

Published Jan 7, 2025

When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are un…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
36.1