Skip to main content

Daily materialized evidence profile

Year 2026

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
47,674
CVEs with mentions
43,841
Total mentions
146,993
CVEs with KEV
115
CVEs with PoC
1,250

Attack vector counts

Network
36,385
Adjacent network
1,188
Local
9,311
Physical
284

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2026-31431

Published Apr 22, 2026

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the…

CVSS 7.8 · High
evidence mentions
164
Buzz score
93.0
KEV listedPublic PoC observed

CVE-2026-63030

Published Jul 17, 2026

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (…

CVSS 9.8 · Critical
evidence mentions
28
Buzz score
93.0
KEV listedPublic PoC observed

CVE-2026-60137

Published Jul 17, 2026

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when…

CVSS 5.9 · Medium
evidence mentions
27
Buzz score
93.0
KEV listedPublic PoC observed

CVE-2026-41940

Published Apr 29, 2026

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to th…

CVSS 9.3 · Critical
evidence mentions
33
Buzz score
92.5
KEV listedPublic PoC observed

CVE-2026-24061

Published Jan 21, 2026

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

CVSS 9.8 · Critical
evidence mentions
23
Buzz score
88.9
KEV listedPublic PoC observed