Skip to main content

Daily materialized evidence profile

CWE CWE-639

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
2,258
CVEs with mentions
1,375
Total mentions
3,637
CVEs with KEV
1
CVEs with PoC
22

Attack vector counts

Network
2,199
Adjacent network
22
Local
32
Physical
1

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2026-55255

Published Jun 23, 2026

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoi…

CVSS 8.4 · High
evidence mentions
15
Buzz score
72.7
KEV listed

CVE-2026-10623

Published Jun 18, 2026

The PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includ…

CVSS 4.3 · Medium
evidence mentions
17
Buzz score
45.4

CVE-2026-41947

Published May 18, 2026

Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardl…

CVSS 9.3 · Critical
evidence mentions
10
Buzz score
44.0

CVE-2026-47101

Published May 21, 2026

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes…

CVSS 8.7 · High
evidence mentions
11
Buzz score
43.9

CVE-2026-12102

Published Jun 18, 2026

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all…

CVSS 2.7 · Low
evidence mentions
13
Buzz score
42.9