Skip to main content

Daily materialized evidence profile

Year 2019

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
17,305
CVEs with mentions
1,334
Total mentions
3,091
CVEs with KEV
128
CVEs with PoC
13

Attack vector counts

Network
13,260
Adjacent network
336
Local
3,509
Physical
200

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2018-13379

Published Jun 4, 2019

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.…

CVSS 9.1 · Critical
evidence mentions
84
Buzz score
82.5
KEV listedPublic PoC observed

CVE-2019-0708

Published May 16, 2019

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RD…

CVSS 9.8 · Critical
evidence mentions
67
Buzz score
75.0
KEV listed

CVE-2019-16759

Published Sep 24, 2019

vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.

CVSS 9.8 · Critical
evidence mentions
21
Buzz score
75.0
KEV listedPublic PoC observed

CVE-2019-15107

Published Aug 16, 2019

An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.

CVSS 9.8 · Critical
evidence mentions
18
Buzz score
74.4
KEV listed

CVE-2019-11510

Published May 8, 2019

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to…

CVSS 10.0 · Critical
evidence mentions
88
Buzz score
74.0
KEV listed