Skip to main content

Daily materialized evidence profile

Year 2021

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
20,149
CVEs with mentions
1,851
Total mentions
5,137
CVEs with KEV
213
CVEs with PoC
20

Attack vector counts

Network
13,849
Adjacent network
729
Local
5,359
Physical
212

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2021-41773

Published Oct 5, 2021

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories co…

CVSS 9.8 · Critical
evidence mentions
22
Buzz score
93.0
KEV listedPublic PoC observed

CVE-2021-3156

Published Jan 26, 2021

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line ar…

CVSS 7.8 · High
evidence mentions
17
Buzz score
89.3
KEV listedPublic PoC observed

CVE-2021-44228

Published Dec 10, 2021

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect aga…

CVSS 10.0 · Critical
evidence mentions
231
Buzz score
85.0
KEV listedPublic PoC observed

CVE-2021-34473

Published Jul 14, 2021

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 9.1 · Critical
evidence mentions
74
Buzz score
82.5
KEV listedPublic PoC observed

CVE-2021-40444

Published Sep 15, 2021

Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploi…

CVSS 8.8 · High
evidence mentions
59
Buzz score
82.5
KEV listedPublic PoC observed