month report
September 2007
Data as of Jun 4, 2026, 13:24 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
September 2007 closed with 453 published CVEs. 59 criticals, php led volume, mostly via php. Biggest breakout: canonical at ×5.0 their 12-month median. Top weakness class — CWE-119 (76 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
453
— MoM— YoY
Severity mix
59 / 135
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
1.3%
6 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
6741.4
n=6
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
5323
n=1
Weakness × Vendor
What's spreading where in September 2007
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
119Memory Buffer Bounds20Improper Input Validation94Code Injection79XSS264CWE-26489SQL Injection22Path Traversal189CWE-189200Information Exposure399CWE-399php3611222apple24131ibm831сообщество свободного программного обеспечения42422microsoft4111111canonical31211joomla2422sun211cisco21linux131vmware2211debian2221
Breakout vendors
CVE count ≥3× their own 12-period median.
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #11vmware7 CVE
- #13firebirdsql6 CVE
- #19auracms4 CVE
- #20boesch-it4 CVE
- #22dibbler4 CVE
- #26wordpress4 CVE
- #27xwiki4 CVE
- #31izicontents3 CVE
- #32jspwiki3 CVE
- #33kwsphp3 CVE
Top vendors
Ranked by distinct CVE count this period.
- 20 CVECVSS 6.3PoC 3php (20) · mysql extension (1)
- 14 CVE3 critCVSS 5.9Nuclei 1PoC 1safari (8) · iphone (3) · iphone os (3)
- 14 CVE1 critCVSS 6.9aix (9) · tivoli storage manager client (2) · websphere application server (2)
- 14 CVECVSS 5.8PoC 1debian gnu/linux (14)
- 11 CVE2 critCVSS 6.9PoC 6visual studio (2) · internet explorer (2) · windows 2003 server (2)
- 10 CVE3 critCVSS 7.6×5.0ubuntu linux (10)
- 10 CVECVSS 6.5PoC 6joomla (6) · flash fun component (1) · akobook (1)
- 8 CVE3 critCVSS 7.8PoC 2solaris (5) · sunos (3) · jre (1)
- 7 CVE2 critCVSS 6.8content switching modules (2) · content switching module with ssl (2) · video surveillance ip gateway encoder decoder (2)
- 7 CVECVSS 4.9PoC 1linux kernel (7)
- 7 CVE4 critCVSS 8.4NEWace (7) · server (6) · player (6)
- 6 CVE1 critCVSS 6.9×3.0debian linux (4) · debian-goodies (1) · reprepro (1)
- 6 CVECVSS 5.3NEWfirebird (6)
- 6 CVECVSS 6.0gentoo linux (6)
- 6 CVECVSS 2.9enterprise linux (5) · linux (2)
- 5 CVE1 critCVSS 5.3PoC 1207w network camera (4) · 207w camera (1)
- 5 CVE1 critCVSS 6.8red hat enterprise linux (5)
- 4 CVE1 critCVSS 6.2tomcat (1) · http server (1) · openoffice (1)
- 4 CVECVSS 7.3NEWPoC 4auracms (4)
- 4 CVECVSS 4.7NEWsimpgb (2) · simpnews (2)
- 4 CVECVSS 4.1×4.0PoC 1claroline (4)
- 4 CVECVSS 5.6NEWdibbler (4)
- 4 CVE1 critCVSS 6.3ucosminexus service platform (3) · ucosminexus application server enterprise (3) · ucosminexus application server standard (3)
- 4 CVE1 critCVSS 7.0imagemagick (4)
- 4 CVE2 critCVSS 7.8PoC 1firefox (3) · seamonkey (2) · bugzilla (1)
- 4 CVECVSS 5.1NEWNuclei 4PoC 1wordpress (4)
- 4 CVECVSS 4.3NEWxwiki (4)
- 3 CVECVSS 6.4×3.0picasa (3)
- 3 CVE2 critCVSS 7.8all-in-on printer (1) · hp-ux (1) · photo and imaging gallery (1)
- 3 CVECVSS 5.9invision power board (3)
- 3 CVECVSS 7.5NEWPoC 3izicontents (3)
- 3 CVECVSS 4.3NEWPoC 1jspwiki (3)
- 3 CVECVSS 7.2NEWPoC 3kwsphp (3)
- 3 CVE2 critCVSS 9.5kerberos 5 (3)
- 3 CVECVSS 4.5NEWurchin (3)
- 3 CVE2 critCVSS 7.9NEWPoC 1winimage (3)
- 2 CVECVSS 6.3NEWPoC 2flip (2)
- 2 CVE1 critCVSS 7.9acrobat (1) · acrobat reader (1) · connect enterprise server (1)
- 2 CVECVSS 5.9simple php blog (2)
- 2 CVECVSS 6.0instant messenger (2) · aim lite (1) · aim pro (1)
- 2 CVECVSS 5.9NEWabyss web server (2)
- 2 CVE2 critCVSS 9.7NEWPoC 1ask toolbar (2)
- 2 CVE1 critCVSS 8.4NEWPoC 1storm (2)
- 2 CVECVSS 7.2NEWPoC 2chupix cms (2)
- 2 CVECVSS 5.0PoC 1coppermine photo gallery (2)
- 2 CVECVSS 6.3NEWalien arena 2007 (2)
- 2 CVE1 critCVSS 7.5NEWPoC 2jetaudio (1) · jetcast server (1)
- 2 CVE1 critCVSS 5.6NEWremotedocs r-viewer (2)
- 2 CVECVSS 5.5NEWPoC 1dfd cart (2)
- 2 CVECVSS 5.9NEWPoC 2ebcrypt (2)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | php | 20 | · | · | · | PoC 3 | php (20) · mysql extension (1) | — | |
| 2 | apple | 14 | 3 | · | 1 | Nuclei 1PoC 1 | safari (8) · iphone (3) · iphone os (3) | — | |
| 3 | ibm | 14 | 1 | · | · | aix (9) · tivoli storage manager client (2) · websphere application server (2) | — | ||
| 4 | сообщество свободного программного обеспечения | 14 | · | · | · | PoC 1 | debian gnu/linux (14) | — | |
| 5 | microsoft | 11 | 2 | · | · | PoC 6 | visual studio (2) · internet explorer (2) · windows 2003 server (2) | — | |
| 6 | canonical | 10 | 3 | · | · | ×5.0 | ubuntu linux (10) | — | |
| 7 | joomla | 10 | · | · | · | PoC 6 | joomla (6) · flash fun component (1) · akobook (1) | — | |
| 8 | sun | 8 | 3 | · | · | PoC 2 | solaris (5) · sunos (3) · jre (1) | — | |
| 9 | cisco | 7 | 2 | · | · | content switching modules (2) · content switching module with ssl (2) · video surveillance ip gateway encoder decoder (2) | — | ||
| 10 | linux | 7 | · | · | · | PoC 1 | linux kernel (7) | — | |
| 11 | vmware | 7 | 4 | · | · | NEW | ace (7) · server (6) · player (6) | — | |
| 12 | debian | 6 | 1 | · | · | ×3.0 | debian linux (4) · debian-goodies (1) · reprepro (1) | — | |
| 13 | firebirdsql | 6 | · | · | · | NEW | firebird (6) | — | |
| 14 | gentoo foundation inc. | 6 | · | · | · | gentoo linux (6) | — | ||
| 15 | redhat | 6 | · | · | · | enterprise linux (5) · linux (2) | — | ||
| 16 | axis | 5 | 1 | · | · | PoC 1 | 207w network camera (4) · 207w camera (1) | — | |
| 17 | red hat inc. | 5 | 1 | · | · | red hat enterprise linux (5) | — | ||
| 18 | apache | 4 | 1 | · | · | tomcat (1) · http server (1) · openoffice (1) | — | ||
| 19 | auracms | 4 | · | · | · | NEWPoC 4 | auracms (4) | — | |
| 20 | boesch-it | 4 | · | · | · | NEW | simpgb (2) · simpnews (2) | — | |
| 21 | claroline | 4 | · | · | · | ×4.0PoC 1 | claroline (4) | — | |
| 22 | dibbler | 4 | · | · | · | NEW | dibbler (4) | — | |
| 23 | hitachi | 4 | 1 | · | · | ucosminexus service platform (3) · ucosminexus application server enterprise (3) · ucosminexus application server standard (3) | — | ||
| 24 | imagemagick | 4 | 1 | · | · | imagemagick (4) | — | ||
| 25 | mozilla | 4 | 2 | · | · | PoC 1 | firefox (3) · seamonkey (2) · bugzilla (1) | — | |
| 26 | wordpress | 4 | · | · | 4 | NEWNuclei 4PoC 1 | wordpress (4) | — | |
| 27 | xwiki | 4 | · | · | · | NEW | xwiki (4) | — | |
| 28 | 3 | · | · | · | ×3.0 | picasa (3) | — | ||
| 29 | hp | 3 | 2 | · | · | all-in-on printer (1) · hp-ux (1) · photo and imaging gallery (1) | — | ||
| 30 | invision power services | 3 | · | · | · | invision power board (3) | — | ||
| 31 | izicontents | 3 | · | · | · | NEWPoC 3 | izicontents (3) | — | |
| 32 | jspwiki | 3 | · | · | · | NEWPoC 1 | jspwiki (3) | — | |
| 33 | kwsphp | 3 | · | · | · | NEWPoC 3 | kwsphp (3) | — | |
| 34 | mit | 3 | 2 | · | · | kerberos 5 (3) | — | ||
| 35 | roi revolution | 3 | · | · | · | NEW | urchin (3) | — | |
| 36 | winimage | 3 | 2 | · | · | NEWPoC 1 | winimage (3) | — | |
| 37 | adam scheinberg | 2 | · | · | · | NEWPoC 2 | flip (2) | — | |
| 38 | adobe | 2 | 1 | · | · | acrobat (1) · acrobat reader (1) · connect enterprise server (1) | — | ||
| 39 | alexander palmo | 2 | · | · | · | simple php blog (2) | — | ||
| 40 | aol | 2 | · | · | · | instant messenger (2) · aim lite (1) · aim pro (1) | — | ||
| 41 | aprelium technologies | 2 | · | · | · | NEW | abyss web server (2) | — | |
| 42 | ask.com | 2 | 2 | · | · | NEWPoC 1 | ask toolbar (2) | — | |
| 43 | baofeng | 2 | 1 | · | · | NEWPoC 1 | storm (2) | — | |
| 44 | chupix | 2 | · | · | · | NEWPoC 2 | chupix cms (2) | — | |
| 45 | coppermine | 2 | · | · | · | PoC 1 | coppermine photo gallery (2) | — | |
| 46 | cor entertainment | 2 | · | · | · | NEW | alien arena 2007 (2) | — | |
| 47 | cowon america | 2 | 1 | · | · | NEWPoC 2 | jetaudio (1) · jetcast server (1) | — | |
| 48 | data-vision | 2 | 1 | · | · | NEW | remotedocs r-viewer (2) | — | |
| 49 | dragonfrugal | 2 | · | · | · | NEWPoC 1 | dfd cart (2) | — | |
| 50 | eb design pty ltd | 2 | · | · | · | NEWPoC 2 | ebcrypt (2) | — |