Skip to main content

Daily materialized evidence profile

CWE CWE-89

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
20,110
CVEs with mentions
5,204
Total mentions
17,368
CVEs with KEV
28
CVEs with PoC
1,521

Attack vector counts

Network
19,604
Adjacent network
334
Local
157
Physical
14

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2026-60137

Published Jul 17, 2026

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when…

CVSS 5.9 · Medium
evidence mentions
27
Buzz score
93.0
KEV listedPublic PoC observed

CVE-2026-9082

Published May 20, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: fro…

CVSS 9.8 · Critical
evidence mentions
10
Buzz score
78.8
KEV listedPublic PoC observed

CVE-2023-34362

Published Jun 2, 2023

In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found…

CVSS 9.8 · Critical
evidence mentions
75
Buzz score
75.0
KEV listed

CVE-2026-21643

Published Feb 6, 2026

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to exe…

CVSS 9.8 · Critical
evidence mentions
20
Buzz score
75.0
KEV listed

CVE-2026-42208

Published May 8, 2026

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key che…

CVSS 9.3 · Critical
evidence mentions
12
Buzz score
74.7
KEV listedPublic PoC observed