month report
May 2007
Data as of Jun 4, 2026, 13:24 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
May 2007 closed with 575 published CVEs. 111 criticals, microsoft led volume, mostly via internet explorer. Biggest breakout: apache at ×4.7 their 12-month median. Top weakness class — CWE-119 (20 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
575
— MoM— YoY
Severity mix
111 / 236
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
1.6%
9 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
6882.2
n=9
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
—
n=0
Weakness × Vendor
What's spreading where in May 2007
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
Breakout vendors
CVE count ≥3× their own 12-period median.
- 4.7×apache7 CVE
- 4.0×debian8 CVE
- 4.0×alstrasoft4 CVE
- 3.0×vmware6 CVE
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #13lead technologies6 CVE
- #14vmware6 CVE
- #19ruben boelinger5 CVE
- #23office ocx4 CVE
- #25wikkawiki4 CVE
- #27acp33 CVE
- #29avast3 CVE
- #32dokeos3 CVE
- #33globalmegacorp3 CVE
- #34madwifi3 CVE
Top vendors
Ranked by distinct CVE count this period.
- 26 CVE14 critCVSS 7.9PoC 3internet explorer (8) · exchange server (4) · office (4)
- 15 CVE8 critCVSS 7.5PoC 1mac os x (7) · mac os x server (5) · quicktime (3)
- 11 CVE2 critCVSS 6.4sunos (3) · jre (3) · sdk (3)
- 10 CVECVSS 5.7PoC 1weblogic server (9) · weblogic integration (1) · weblogic workshop (1)
- 10 CVE2 critCVSS 5.6PoC 1php (10)
- 9 CVE2 critCVSS 7.8PoC 1pix (4) · adaptive security appliance software (4) · ios (3)
- 8 CVECVSS 4.9×4.0PoC 1debian linux (8)
- 8 CVECVSS 5.1PoC 1linux kernel (8)
- 7 CVECVSS 4.4×4.7PoC 1tomcat (6) · tomcat jk web server connector (1)
- 7 CVECVSS 5.6PoC 2jetbox cms (7)
- 7 CVECVSS 5.2PoC 2debian gnu/linux (7)
- 6 CVE2 critCVSS 8.0PoC 1tru64 (2) · openvms (1) · procurve switch 9300m (1)
- 6 CVE3 critCVSS 8.5NEWPoC 3leadtools raster dialog file object (2) · leadtools jpeg 2000 (1) · leadtools isis activex control (1)
- 6 CVECVSS 7.3NEW×3.0workstation (6) · server (1)
- 5 CVECVSS 5.7PoC 1ubuntu linux (5)
- 5 CVECVSS 5.1vbulletin (5)
- 5 CVECVSS 4.6PoC 1org.apache.tomcat:tomcat (4) · org.apache.tomcat:jsp-api (1) · org.apache.tomcat:servlet-api (1)
- 5 CVECVSS 4.1PoC 1mysql (3) · weblogic portal (2)
- 5 CVECVSS 6.9NEWNuclei 5PoC 5wp-table (2) · wordtube (2) · myflash (1)
- 5 CVE2 critCVSS 8.1norton internet security (2) · enterprise security manager (1) · discovery (1)
- 4 CVE3 critCVSS 9.4×4.0PoC 4template seller (2) · e-friends (1) · live support (1)
- 4 CVE1 critCVSS 8.1f-secure anti-virus (3) · f-secure anti-virus client security (3) · f-secure anti-virus linux client security (3)
- 4 CVE2 critCVSS 8.7NEWPoC 2excel viewer ocx (1) · office viewer ocx (1) · powerpoint viewer ocx (1)
- 4 CVECVSS 6.4sunshop shopping cart (4)
- 4 CVECVSS 6.3NEWwikkawiki (4)
- 4 CVECVSS 7.5PoC 3flashgames module (1) · myconference module (1) · wfquotes module (1)
- 3 CVECVSS 6.9NEWacp3 (3)
- 3 CVECVSS 5.5advanced guestbook (3)
- 3 CVE1 critCVSS 8.1NEWPoC 1avast antivirus (3) · avast antivirus home (1) · avast antivirus professional (1)
- 3 CVE1 critCVSS 6.5resin (3)
- 3 CVE2 critCVSS 8.4trillian pro (2) · trillian (1)
- 3 CVECVSS 6.4NEWPoC 3dokeos (2) · open source learning and knowledge management tool (1)
- 3 CVECVSS 5.1NEWphpchain (2) · dvddb (1)
- 3 CVE1 critCVSS 6.7NEWmadwifi (3)
- 3 CVECVSS 4.8mysql (3)
- 3 CVECVSS 6.1PoC 2groupwise mobile server (3) · intellisync mobile suite (3) · intellisync wireless email express (3)
- 3 CVE2 critCVSS 8.8securelogin (2) · netmail (1)
- 3 CVE1 critCVSS 7.1PoC 2opensuse (2) · suse linux enterprise (1)
- 3 CVE1 critCVSS 8.4NEWPoC 2precisionid barcode (3)
- 3 CVECVSS 3.8NEWqemu (3)
- 3 CVE1 critCVSS 6.9PoC 1red hat enterprise linux (3)
- 3 CVE1 critCVSS 7.7NEWPoC 1samba (3)
- 3 CVECVSS 4.6NEWsonicbb (3)
- 3 CVECVSS 5.6squirrelmail (3)
- 3 CVE3 critCVSS 10.0serverprotect (3)
- 3 CVE1 critCVSS 7.9NEWPoC 3tutorialcms (3)
- 2 CVECVSS 7.5NEWPoC 22z project (2)
- 2 CVE1 critCVSS 8.3NEWadempiere (2)
- 2 CVECVSS 5.4robohelp server (1) · creative suite (1) · robohelp (1)
- 2 CVECVSS 7.2NEWPoC 1aforum (2)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | microsoft | 26 | 14 | · | · | PoC 3 | internet explorer (8) · exchange server (4) · office (4) | — | |
| 2 | apple | 15 | 8 | · | · | PoC 1 | mac os x (7) · mac os x server (5) · quicktime (3) | — | |
| 3 | sun | 11 | 2 | · | · | sunos (3) · jre (3) · sdk (3) | — | ||
| 4 | bea | 10 | · | · | · | PoC 1 | weblogic server (9) · weblogic integration (1) · weblogic workshop (1) | — | |
| 5 | php | 10 | 2 | · | · | PoC 1 | php (10) | — | |
| 6 | cisco | 9 | 2 | · | · | PoC 1 | pix (4) · adaptive security appliance software (4) · ios (3) | — | |
| 7 | debian | 8 | · | · | · | ×4.0PoC 1 | debian linux (8) | — | |
| 8 | linux | 8 | · | · | · | PoC 1 | linux kernel (8) | — | |
| 9 | apache | 7 | · | · | · | ×4.7PoC 1 | tomcat (6) · tomcat jk web server connector (1) | — | |
| 10 | jetbox | 7 | · | · | · | PoC 2 | jetbox cms (7) | — | |
| 11 | сообщество свободного программного обеспечения | 7 | · | · | · | PoC 2 | debian gnu/linux (7) | — | |
| 12 | hp | 6 | 2 | · | · | PoC 1 | tru64 (2) · openvms (1) · procurve switch 9300m (1) | — | |
| 13 | lead technologies | 6 | 3 | · | · | NEWPoC 3 | leadtools raster dialog file object (2) · leadtools jpeg 2000 (1) · leadtools isis activex control (1) | — | |
| 14 | vmware | 6 | · | · | · | NEW×3.0 | workstation (6) · server (1) | — | |
| 15 | canonical | 5 | · | · | · | PoC 1 | ubuntu linux (5) | — | |
| 16 | jelsoft | 5 | · | · | · | vbulletin (5) | — | ||
| 17 | maven | 5 | · | · | · | PoC 1 | org.apache.tomcat:tomcat (4) · org.apache.tomcat:jsp-api (1) · org.apache.tomcat:servlet-api (1) | — | |
| 18 | oracle | 5 | · | · | · | PoC 1 | mysql (3) · weblogic portal (2) | — | |
| 19 | ruben boelinger | 5 | · | · | 5 | NEWNuclei 5PoC 5 | wp-table (2) · wordtube (2) · myflash (1) | — | |
| 20 | symantec | 5 | 2 | · | · | norton internet security (2) · enterprise security manager (1) · discovery (1) | — | ||
| 21 | alstrasoft | 4 | 3 | · | · | ×4.0PoC 4 | template seller (2) · e-friends (1) · live support (1) | — | |
| 22 | f-secure | 4 | 1 | · | · | f-secure anti-virus (3) · f-secure anti-virus client security (3) · f-secure anti-virus linux client security (3) | — | ||
| 23 | office ocx | 4 | 2 | · | · | NEWPoC 2 | excel viewer ocx (1) · office viewer ocx (1) · powerpoint viewer ocx (1) | — | |
| 24 | turnkey web tools | 4 | · | · | · | sunshop shopping cart (4) | — | ||
| 25 | wikkawiki | 4 | · | · | · | NEW | wikkawiki (4) | — | |
| 26 | xoops | 4 | · | · | · | PoC 3 | flashgames module (1) · myconference module (1) · wfquotes module (1) | — | |
| 27 | acp3 | 3 | · | · | · | NEW | acp3 (3) | — | |
| 28 | advanced guestbook | 3 | · | · | · | advanced guestbook (3) | — | ||
| 29 | avast | 3 | 1 | · | · | NEWPoC 1 | avast antivirus (3) · avast antivirus home (1) · avast antivirus professional (1) | — | |
| 30 | caucho technology | 3 | 1 | · | · | resin (3) | — | ||
| 31 | cerulean studios | 3 | 2 | · | · | trillian pro (2) · trillian (1) | — | ||
| 32 | dokeos | 3 | · | · | · | NEWPoC 3 | dokeos (2) · open source learning and knowledge management tool (1) | — | |
| 33 | globalmegacorp | 3 | · | · | · | NEW | phpchain (2) · dvddb (1) | — | |
| 34 | madwifi | 3 | 1 | · | · | NEW | madwifi (3) | — | |
| 35 | mysql | 3 | · | · | · | mysql (3) | — | ||
| 36 | nokia | 3 | · | · | · | PoC 2 | groupwise mobile server (3) · intellisync mobile suite (3) · intellisync wireless email express (3) | — | |
| 37 | novell | 3 | 2 | · | · | securelogin (2) · netmail (1) | — | ||
| 38 | novell inc. | 3 | 1 | · | · | PoC 2 | opensuse (2) · suse linux enterprise (1) | — | |
| 39 | precisionid barcode | 3 | 1 | · | · | NEWPoC 2 | precisionid barcode (3) | — | |
| 40 | qemu | 3 | · | · | · | NEW | qemu (3) | — | |
| 41 | red hat inc. | 3 | 1 | · | · | PoC 1 | red hat enterprise linux (3) | — | |
| 42 | samba | 3 | 1 | · | · | NEWPoC 1 | samba (3) | — | |
| 43 | sonicbb | 3 | · | · | · | NEW | sonicbb (3) | — | |
| 44 | squirrelmail | 3 | · | · | · | squirrelmail (3) | — | ||
| 45 | trend micro | 3 | 3 | · | · | serverprotect (3) | — | ||
| 46 | wavelink media | 3 | 1 | · | · | NEWPoC 3 | tutorialcms (3) | — | |
| 47 | 2z project | 2 | · | · | · | NEWPoC 2 | 2z project (2) | — | |
| 48 | adempiere | 2 | 1 | · | · | NEW | adempiere (2) | — | |
| 49 | adobe | 2 | · | · | · | robohelp server (1) · creative suite (1) · robohelp (1) | — | ||
| 50 | agner fog | 2 | · | · | · | NEWPoC 1 | aforum (2) | — |