Skip to main content

Daily materialized evidence profile

CWE CWE-79

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
45,972
CVEs with mentions
11,437
Total mentions
24,419
CVEs with KEV
32
CVEs with PoC
477

Attack vector counts

Network
45,477
Adjacent network
257
Local
231
Physical
5

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2026-42897

Published May 14, 2026

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a networ…

CVSS 8.1 · High
evidence mentions
20
Buzz score
75.0
KEV listed

CVE-2025-66376

Published Jan 5, 2026

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

CVSS 7.2 · High
evidence mentions
20
Buzz score
75.0
KEV listed

CVE-2025-27915

Published Mar 12, 2025

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient…

CVSS 5.4 · Medium
evidence mentions
12
Buzz score
70.7
KEV listed

CVE-2020-35730

Published Dec 28, 2020

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in…

CVSS 6.1 · Medium
evidence mentions
16
Buzz score
67.8
KEV listed

CVE-2025-48700

Published Jun 23, 2025

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to exe…

CVSS 6.1 · Medium
evidence mentions
8
Buzz score
66.5
KEV listed