month report
January 2009
Data as of Jun 4, 2026, 13:27 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
January 2009 closed with 469 published CVEs — -6.6% YoY . 72 criticals, oracle led volume, mostly via secure backup. Biggest breakout: oracle at ×11.7 their 12-month median. Top weakness class — CWE-89 (87 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
469
-11.5% MoM-6.6% YoY
Severity mix
72 / 151
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
0.2%
1 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
6245.1
n=1
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
—
n=0
Weakness × Vendor
What's spreading where in January 2009
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
89SQL Injection264CWE-26479XSS119Memory Buffer Bounds22Path Traversal20Improper Input Validation287Improper Authentication94Code Injection200Information Exposure399CWE-399oracle32sun51121microsoft4113сообщество свободного программного обеспечения14422apple5112cisco13linux1112codeavalanche6gentoo foundation inc.211katywhitton222activewebsoftwares5debian11
Breakout vendors
CVE count ≥3× their own 12-period median.
- 11.7×oracle41 CVE
- 5.0×gnome5 CVE
- 3.0×katywhitton6 CVE
- 3.0×fujitsu3 CVE
- 3.0×git3 CVE
- 3.0×nokia3 CVE
- 3.0×phpauctions3 CVE
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #8codeavalanche6 CVE
- #15modxcms5 CVE
- #17asp-dev4 CVE
- #18icash4 CVE
- #20joomlahbs4 CVE
- #22tigris4 CVE
- #24constructr3 CVE
- #25edreamers3 CVE
- #27git3 CVE
- #30ktp computer customer database3 CVE
Top vendors
Ranked by distinct CVE count this period.
- 41 CVE5 critCVSS 5.2×11.7PoC 1secure backup (9) · database 10g (9) · peoplesoft enterprise (6)
- 22 CVE4 critCVSS 6.4PoC 1opensolaris (14) · solaris (9) · java system access manager (3)
- 16 CVE5 critCVSS 7.4PoC 7windows xp (5) · windows server 2003 (4) · windows 2000 (4)
- 16 CVE4 critCVSS 7.0PoC 1debian gnu/linux (15) · libaudiofile (1)
- 14 CVE8 critCVSS 7.7PoC 3quicktime (7) · safari (5) · cups (1)
- 10 CVECVSS 5.8PoC 1ironport postx (4) · ironport encryption appliance (4) · security manager (1)
- 7 CVE1 critCVSS 6.2linux kernel (7)
- 6 CVECVSS 7.1NEWPoC 6articles (1) · directory (1) · freeforall (1)
- 6 CVECVSS 6.2gentoo linux (6)
- 6 CVECVSS 5.6×3.0PoC 6blogit\! (4) · rankem (2)
- 5 CVECVSS 7.5PoC 5active price comparison (2) · active web mail (1) · active business directory (1)
- 5 CVECVSS 5.9debian linux (5)
- 5 CVECVSS 6.9×5.0PoC 1eog (1) · epiphany (1) · gnumeric (1)
- 5 CVE1 critCVSS 7.0db2 universal database (2) · aix (1) · hardware management console (1)
- 5 CVECVSS 5.6NEWPoC 2modxcms (5)
- 5 CVE1 critCVSS 6.7typo3 (4) · freecap captcha extension (1)
- 4 CVECVSS 6.9NEWPoC 3xm events diary (3) · internal e-mail system (1)
- 4 CVECVSS 5.5NEWPoC 4click\&email (2) · click\&rank (2)
- 4 CVECVSS 6.9PoC 4com paxgallery (1) · com pccookbook (1) · com waticketsystem (1)
- 4 CVECVSS 7.5NEWPoC 4hotel booking reservation system (4) · com 5starhotels (1) · com allhotels (1)
- 4 CVECVSS 4.8PoC 2firefox (3) · libxul (1) · seamonkey (1)
- 4 CVECVSS 5.5NEWPoC 3websvn (4)
- 3 CVECVSS 5.6ubuntu linux (3)
- 3 CVECVSS 4.3NEWPoC 3constructr-cms (3)
- 3 CVECVSS 7.0NEWPoC 3ednews (2) · edcontainer (1)
- 3 CVE2 critCVSS 8.3×3.0systemcastwizard lite (3)
- 3 CVECVSS 6.5NEW×3.0git (3)
- 3 CVE1 critCVSS 7.1PoC 1hplip (1) · openview network node manager (1) · select access (1)
- 3 CVECVSS 4.8enterpriseone (3)
- 3 CVECVSS 6.8NEWPoC 2ktp computer customer database (3)
- 3 CVECVSS 6.0×3.06131 nfc (3)
- 3 CVECVSS 5.6PoC 3mailing list manager (3)
- 3 CVECVSS 6.4NEW×3.0PoC 3phpauctions (3)
- 3 CVECVSS 5.4NEWPoC 3phpclanwebsite (3)
- 3 CVECVSS 7.5NEWPoC 3phpicalendar (3) · phpicalendar2.0 (1)
- 3 CVECVSS 4.0certificate system (3) · dogtag certificate system (1)
- 3 CVECVSS 6.0NEWPoC 2phosheezy (3)
- 3 CVECVSS 6.7NEWPoC 3sg real estate portal (3)
- 3 CVECVSS 4.2NEWmovable type (3)
- 3 CVE1 critCVSS 6.5internet security 2007 (3) · internet security 2008 (3) · officescan (3)
- 3 CVE2 critCVSS 9.1NEWPoC 2vuplayer (3)
- 3 CVECVSS 7.5NEWPoC 1xrdp (3)
- 2 CVECVSS 5.9PoC 2aj auction (2)
- 2 CVE2 critCVSS 9.3amarok (2)
- 2 CVECVSS 6.3PoC 2template creature (2)
- 2 CVE2 critCVSS 10.0arcserve backup (1) · etrust intrusion detection (1) · internet security suite 2007 (1)
- 2 CVECVSS 4.7connectra ngx (1) · vpn-1 (1)
- 2 CVECVSS 5.9NEWPoC 2cms isweb (2)
- 2 CVECVSS 5.9NEWPoC 1blog manager (2)
- 2 CVECVSS 4.8ajax checklist (2)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | oracle | 41 | 5 | · | · | ×11.7PoC 1 | secure backup (9) · database 10g (9) · peoplesoft enterprise (6) | — | |
| 2 | sun | 22 | 4 | · | · | PoC 1 | opensolaris (14) · solaris (9) · java system access manager (3) | · | |
| 3 | microsoft | 16 | 5 | · | · | PoC 7 | windows xp (5) · windows server 2003 (4) · windows 2000 (4) | ↓2 | |
| 4 | сообщество свободного программного обеспечения | 16 | 4 | · | · | PoC 1 | debian gnu/linux (15) · libaudiofile (1) | ↑20 | |
| 5 | apple | 14 | 8 | · | · | PoC 3 | quicktime (7) · safari (5) · cups (1) | ↓1 | |
| 6 | cisco | 10 | · | · | · | PoC 1 | ironport postx (4) · ironport encryption appliance (4) · security manager (1) | ↑49 | |
| 7 | linux | 7 | 1 | · | · | linux kernel (7) | ↑3 | ||
| 8 | codeavalanche | 6 | · | · | · | NEWPoC 6 | articles (1) · directory (1) · freeforall (1) | — | |
| 9 | gentoo foundation inc. | 6 | · | · | · | gentoo linux (6) | ↑5 | ||
| 10 | katywhitton | 6 | · | · | · | ×3.0PoC 6 | blogit\! (4) · rankem (2) | ↑56 | |
| 11 | activewebsoftwares | 5 | · | · | · | PoC 5 | active price comparison (2) · active web mail (1) · active business directory (1) | ↓3 | |
| 12 | debian | 5 | · | · | · | debian linux (5) | ↓5 | ||
| 13 | gnome | 5 | · | · | · | ×5.0PoC 1 | eog (1) · epiphany (1) · gnumeric (1) | ↑147 | |
| 14 | ibm | 5 | 1 | · | · | db2 universal database (2) · aix (1) · hardware management console (1) | ↓11 | ||
| 15 | modxcms | 5 | · | · | · | NEWPoC 2 | modxcms (5) | — | |
| 16 | typo3 | 5 | 1 | · | · | typo3 (4) · freecap captcha extension (1) | ↓7 | ||
| 17 | asp-dev | 4 | · | · | · | NEWPoC 3 | xm events diary (3) · internal e-mail system (1) | — | |
| 18 | icash | 4 | · | · | · | NEWPoC 4 | click\&email (2) · click\&rank (2) | — | |
| 19 | joomla | 4 | · | · | · | PoC 4 | com paxgallery (1) · com pccookbook (1) · com waticketsystem (1) | ↑15 | |
| 20 | joomlahbs | 4 | · | · | · | NEWPoC 4 | hotel booking reservation system (4) · com 5starhotels (1) · com allhotels (1) | — | |
| 21 | mozilla | 4 | · | · | · | PoC 2 | firefox (3) · libxul (1) · seamonkey (1) | ↓16 | |
| 22 | tigris | 4 | · | · | · | NEWPoC 3 | websvn (4) | — | |
| 23 | canonical | 3 | · | · | · | ubuntu linux (3) | ↓17 | ||
| 24 | constructr | 3 | · | · | · | NEWPoC 3 | constructr-cms (3) | — | |
| 25 | edreamers | 3 | · | · | · | NEWPoC 3 | ednews (2) · edcontainer (1) | — | |
| 26 | fujitsu | 3 | 2 | · | · | ×3.0 | systemcastwizard lite (3) | — | |
| 27 | git | 3 | · | · | · | NEW×3.0 | git (3) | — | |
| 28 | hp | 3 | 1 | · | · | PoC 1 | hplip (1) · openview network node manager (1) · select access (1) | ↑5 | |
| 29 | jdedwards | 3 | · | · | · | enterpriseone (3) | — | ||
| 30 | ktp computer customer database | 3 | · | · | · | NEWPoC 2 | ktp computer customer database (3) | — | |
| 31 | nokia | 3 | · | · | · | ×3.0 | 6131 nfc (3) | — | |
| 32 | ocean12 technologies | 3 | · | · | · | PoC 3 | mailing list manager (3) | — | |
| 33 | phpauctions | 3 | · | · | · | NEW×3.0PoC 3 | phpauctions (3) | — | |
| 34 | phpclanwebsite | 3 | · | · | · | NEWPoC 3 | phpclanwebsite (3) | — | |
| 35 | phpicalendar | 3 | · | · | · | NEWPoC 3 | phpicalendar (3) · phpicalendar2.0 (1) | — | |
| 36 | redhat | 3 | · | · | · | certificate system (3) · dogtag certificate system (1) | — | ||
| 37 | ryneezy | 3 | · | · | · | NEWPoC 2 | phosheezy (3) | — | |
| 38 | sg real estate portal | 3 | · | · | · | NEWPoC 3 | sg real estate portal (3) | — | |
| 39 | sixapart | 3 | · | · | · | NEW | movable type (3) | — | |
| 40 | trend micro | 3 | 1 | · | · | internet security 2007 (3) · internet security 2008 (3) · officescan (3) | ↑4 | ||
| 41 | vuplayer | 3 | 2 | · | · | NEWPoC 2 | vuplayer (3) | — | |
| 42 | xrdp | 3 | · | · | · | NEWPoC 1 | xrdp (3) | — | |
| 43 | aj square | 2 | · | · | · | PoC 2 | aj auction (2) | — | |
| 44 | amarok | 2 | 2 | · | · | amarok (2) | — | ||
| 45 | aspapps | 2 | · | · | · | PoC 2 | template creature (2) | ↓32 | |
| 46 | ca | 2 | 2 | · | · | arcserve backup (1) · etrust intrusion detection (1) · internet security suite 2007 (1) | ↑75 | ||
| 47 | checkpoint | 2 | · | · | · | connectra ngx (1) · vpn-1 (1) | — | ||
| 48 | cmsisweb | 2 | · | · | · | NEWPoC 2 | cms isweb (2) | — | |
| 49 | dmxready | 2 | · | · | · | NEWPoC 1 | blog manager (2) | — | |
| 50 | drupal | 2 | · | · | · | ajax checklist (2) | — |