Skip to main content

Daily materialized evidence profile

CWE CWE-77

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
3,699
CVEs with mentions
1,477
Total mentions
5,828
CVEs with KEV
37
CVEs with PoC
331

Attack vector counts

Network
2,913
Adjacent network
324
Local
443
Physical
18

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2026-42271

Published May 8, 2026

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server bef…

CVSS 8.7 · High
evidence mentions
15
Buzz score
77.9
KEV listedPublic PoC observed

CVE-2012-1823

Published May 11, 2012

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign)…

CVSS 9.8 · Critical
evidence mentions
18
Buzz score
75.4
KEV listedPublic PoC observed

CVE-2024-21887

Published Jan 12, 2024

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specia…

CVSS 9.1 · Critical
evidence mentions
79
Buzz score
75.0
KEV listed

CVE-2024-3400

Published Apr 12, 2024

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distin…

CVSS 10.0 · Critical
evidence mentions
40
Buzz score
75.0
KEV listed

CVE-2024-12356

Published Dec 17, 2024

A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that…

CVSS 9.8 · Critical
evidence mentions
25
Buzz score
75.0
KEV listed