Skip to main content

Daily materialized evidence profile

CWE CWE-611

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
1,283
CVEs with mentions
222
Total mentions
578
CVEs with KEV
8
CVEs with PoC
9

Attack vector counts

Network
1,116
Adjacent network
28
Local
138
Physical
1

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2025-2775

Published May 7, 2025

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrato…

CVSS 9.3 · Critical
evidence mentions
9
Buzz score
68.0
KEV listed

CVE-2025-2776

Published May 7, 2025

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administra…

CVSS 9.3 · Critical
evidence mentions
9
Buzz score
68.0
KEV listed

CVE-2019-9670

Published May 29, 2019

mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodisco…

CVSS 9.8 · Critical
evidence mentions
10
Buzz score
65.0
KEV listed

CVE-2024-34102

Published Jun 13, 2024

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could r…

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
63.7
KEV listedPublic PoC observed

CVE-2016-9563

Published Nov 23, 2016

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwl…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
50.6
KEV listed