month report
April 2009
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
April 2009 closed with 570 published CVEs. 89 criticals, oracle led volume, mostly via application server. Top weakness class — CWE-79 (77 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
570
— MoM— YoY
Severity mix
89 / 147
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
0.5%
3 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
6156.2
n=3
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
6123
n=1
Detection gap
KEV pressure, no Nuclei coverage
April 2009 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 1microsoft23 CVE
Weakness × Vendor
What's spreading where in April 2009
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS89SQL Injection119Memory Buffer Bounds20Improper Input Validation264CWE-26422Path Traversal94Code Injection189CWE-189399CWE-399287Improper Authenticationoraclemicrosoft1222324apple53135novell inc.42143ibm211mozilla224foolabs41134glyphandcog41134сообщество свободного программного обеспечения143sun1311apache51poppler2134
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #7foolabs13 CVE
- #8glyphandcog13 CVE
- #13poppler10 CVE
- #22mini-stream7 CVE
- #24peterselie6 CVE
- #25quickersite6 CVE
- #26razorcms6 CVE
- #27viart6 CVE
- #28webbdomain6 CVE
- #29china-on-site5 CVE
Top vendors
Ranked by distinct CVE count this period.
- 43 CVE3 critCVSS 5.5PoC 1application server (12) · database 10g (11) · database 11g (11)
- 23 CVE12 critCVSS 8.3KEV 1PoC 1windows xp (8) · windows 2000 (6) · windows vista (6)
- 20 CVE2 critCVSS 6.5PoC 5cups (13) · mac os x (6) · mac os x server (5)
- 19 CVE2 critCVSS 5.9PoC 2suse linux enterprise (13) · opensuse (6)
- 14 CVE2 critCVSS 6.2PoC 3websphere portal (3) · advanced management module (3) · bladecenter (2)
- 14 CVE1 critCVSS 5.0PoC 3firefox (13) · seamonkey (10) · thunderbird (8)
- 13 CVE1 critCVSS 6.0NEWxpdf (13)
- 13 CVE1 critCVSS 6.0NEWxpdfreader (13)
- 11 CVECVSS 4.5PoC 3opensolaris (4) · solaris (3) · openjdk (2)
- 11 CVE2 critCVSS 6.4PoC 2debian gnu/linux (11)
- 10 CVE1 critCVSS 4.8PoC 3struts (3) · geronimo (3) · mod jk (1)
- 10 CVE1 critCVSS 6.2PoC 4gentoo linux (10)
- 10 CVECVSS 5.5NEWpoppler (10)
- 9 CVE4 critCVSS 8.0communication manager (9) · sip enablement services (4)
- 9 CVE3 critCVSS 7.1storageworks storage mirroring (3) · hp-ux (1) · openview network node manager (1)
- 9 CVECVSS 5.5PoC 2linux kernel (9)
- 8 CVECVSS 6.4pix (6) · adaptive security appliance 5500 (6) · ios (1)
- 8 CVE2 critCVSS 7.2PoC 1debian linux (5) · advanced package tool (2) · apt (1)
- 8 CVE1 critCVSS 5.7PoC 3org.apache.geronimo.plugins:console (3) · org.apache.struts:struts2-core (1) · org.apache.struts:struts2-dojo-plugin (1)
- 8 CVE1 critCVSS 6.1PoC 1ace (6) · workstation (5) · player (5)
- 7 CVE1 critCVSS 6.4PoC 1ubuntu linux (7)
- 7 CVE7 critCVSS 9.3NEWPoC 7wm downloader (1) · asx to mp3 converter (1) · easy rm to mp3 converter (1)
- 7 CVE4 critCVSS 7.9PoC 1endpoint protection (5) · antivirus (5) · client security (4)
- 6 CVECVSS 5.8NEWPoC 5yourplace (6)
- 6 CVECVSS 6.1NEWPoC 2quickersite (6)
- 6 CVECVSS 5.7NEWPoC 3razorcms (6)
- 6 CVECVSS 5.0NEWPoC 2viart shop (6)
- 6 CVECVSS 7.0NEWPoC 6petition (1) · polls (1) · post card (1)
- 5 CVE2 critCVSS 7.9NEWPoC 5flexphpdirectory (2) · flexphplink (2) · flexcustomer0.0.6 (1)
- 5 CVE1 critCVSS 7.1NEWclamav (5)
- 5 CVECVSS 4.7PoC 2gnutls (3) · gnu screen (1) · screen (1)
- 5 CVECVSS 5.9NEWPoC 3lightneasy (5)
- 5 CVE2 critCVSS 6.9PoC 1wireshark (5)
- 4 CVECVSS 4.3NEWPoC 1dotnetnuke (4)
- 4 CVECVSS 4.3cck comment reference (1) · feedapi mapper (1) · localization client (1)
- 4 CVE1 critCVSS 6.0PoC 1fedora (4)
- 4 CVE2 critCVSS 7.8NEWPoC 2ghostscript (4)
- 4 CVE2 critCVSS 8.2cs1000 (4)
- 4 CVE1 critCVSS 5.3teaming (2) · access manager (1) · netidentity client1.2.3 (1)
- 4 CVECVSS 5.4PoC 1opensuse (4)
- 4 CVE1 critCVSS 7.8PoC 1red hat enterprise linux (4)
- 4 CVECVSS 6.0NEWPoC 4simple machines forum (4)
- 4 CVECVSS 6.1NEWPoC 2sqlite (4)
- 4 CVE1 critCVSS 6.3NEWPoC 2s.t.a.l.k.e.r.\ (4)
- 4 CVECVSS 6.3NEWnd antispam (1) · pmk rssnewsexport extension (1) · tjs reslib (1)
- 3 CVECVSS 7.3NEWPoC 3minimal-ablog (2) · minimal ablog (1)
- 3 CVECVSS 6.4NEWPoC 3sma-db (3)
- 3 CVE3 critCVSS 9.3NEWPoC 1ultraiso (3)
- 3 CVECVSS 6.2NEWPoC 2glfusion (3)
- 3 CVECVSS 5.5PoC 1chrome (3)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | oracle | 43 | 3 | · | · | PoC 1 | application server (12) · database 10g (11) · database 11g (11) | — | |
| 2 | microsoft | 23 | 12 | 1 | · | KEV 1PoC 1 | windows xp (8) · windows 2000 (6) · windows vista (6) | — | |
| 3 | apple | 20 | 2 | · | · | PoC 5 | cups (13) · mac os x (6) · mac os x server (5) | — | |
| 4 | novell inc. | 19 | 2 | · | · | PoC 2 | suse linux enterprise (13) · opensuse (6) | — | |
| 5 | ibm | 14 | 2 | · | · | PoC 3 | websphere portal (3) · advanced management module (3) · bladecenter (2) | — | |
| 6 | mozilla | 14 | 1 | · | · | PoC 3 | firefox (13) · seamonkey (10) · thunderbird (8) | — | |
| 7 | foolabs | 13 | 1 | · | · | NEW | xpdf (13) | — | |
| 8 | glyphandcog | 13 | 1 | · | · | NEW | xpdfreader (13) | — | |
| 9 | sun | 11 | · | · | · | PoC 3 | opensolaris (4) · solaris (3) · openjdk (2) | — | |
| 10 | сообщество свободного программного обеспечения | 11 | 2 | · | · | PoC 2 | debian gnu/linux (11) | — | |
| 11 | apache | 10 | 1 | · | · | PoC 3 | struts (3) · geronimo (3) · mod jk (1) | — | |
| 12 | gentoo foundation inc. | 10 | 1 | · | · | PoC 4 | gentoo linux (10) | — | |
| 13 | poppler | 10 | · | · | · | NEW | poppler (10) | — | |
| 14 | avaya | 9 | 4 | · | · | communication manager (9) · sip enablement services (4) | — | ||
| 15 | hp | 9 | 3 | · | · | storageworks storage mirroring (3) · hp-ux (1) · openview network node manager (1) | — | ||
| 16 | linux | 9 | · | · | · | PoC 2 | linux kernel (9) | — | |
| 17 | cisco | 8 | · | · | · | pix (6) · adaptive security appliance 5500 (6) · ios (1) | — | ||
| 18 | debian | 8 | 2 | · | · | PoC 1 | debian linux (5) · advanced package tool (2) · apt (1) | — | |
| 19 | maven | 8 | 1 | · | · | PoC 3 | org.apache.geronimo.plugins:console (3) · org.apache.struts:struts2-core (1) · org.apache.struts:struts2-dojo-plugin (1) | — | |
| 20 | vmware | 8 | 1 | · | · | PoC 1 | ace (6) · workstation (5) · player (5) | — | |
| 21 | canonical | 7 | 1 | · | · | PoC 1 | ubuntu linux (7) | — | |
| 22 | mini-stream | 7 | 7 | · | · | NEWPoC 7 | wm downloader (1) · asx to mp3 converter (1) · easy rm to mp3 converter (1) | — | |
| 23 | symantec | 7 | 4 | · | · | PoC 1 | endpoint protection (5) · antivirus (5) · client security (4) | — | |
| 24 | peterselie | 6 | · | · | · | NEWPoC 5 | yourplace (6) | — | |
| 25 | quickersite | 6 | · | · | · | NEWPoC 2 | quickersite (6) | — | |
| 26 | razorcms | 6 | · | · | · | NEWPoC 3 | razorcms (6) | — | |
| 27 | viart | 6 | · | · | · | NEWPoC 2 | viart shop (6) | — | |
| 28 | webbdomain | 6 | · | · | · | NEWPoC 6 | petition (1) · polls (1) · post card (1) | — | |
| 29 | china-on-site | 5 | 2 | · | · | NEWPoC 5 | flexphpdirectory (2) · flexphplink (2) · flexcustomer0.0.6 (1) | — | |
| 30 | clamav | 5 | 1 | · | · | NEW | clamav (5) | — | |
| 31 | gnu | 5 | · | · | · | PoC 2 | gnutls (3) · gnu screen (1) · screen (1) | — | |
| 32 | lightneasy | 5 | · | · | · | NEWPoC 3 | lightneasy (5) | — | |
| 33 | wireshark | 5 | 2 | · | · | PoC 1 | wireshark (5) | — | |
| 34 | dnnsoftware | 4 | · | · | · | NEWPoC 1 | dotnetnuke (4) | — | |
| 35 | drupal | 4 | · | · | · | cck comment reference (1) · feedapi mapper (1) · localization client (1) | — | ||
| 36 | fedoraproject | 4 | 1 | · | · | PoC 1 | fedora (4) | — | |
| 37 | ghostscript | 4 | 2 | · | · | NEWPoC 2 | ghostscript (4) | — | |
| 38 | nortel | 4 | 2 | · | · | cs1000 (4) | — | ||
| 39 | novell | 4 | 1 | · | · | teaming (2) · access manager (1) · netidentity client1.2.3 (1) | — | ||
| 40 | opensuse | 4 | · | · | · | PoC 1 | opensuse (4) | — | |
| 41 | red hat inc. | 4 | 1 | · | · | PoC 1 | red hat enterprise linux (4) | — | |
| 42 | simple machines | 4 | · | · | · | NEWPoC 4 | simple machines forum (4) | — | |
| 43 | sqlite | 4 | · | · | · | NEWPoC 2 | sqlite (4) | — | |
| 44 | stalker-game | 4 | 1 | · | · | NEWPoC 2 | s.t.a.l.k.e.r.\ (4) | — | |
| 45 | typo3 | 4 | · | · | · | NEW | nd antispam (1) · pmk rssnewsexport extension (1) · tjs reslib (1) | — | |
| 46 | abweb | 3 | · | · | · | NEWPoC 3 | minimal-ablog (2) · minimal ablog (1) | — | |
| 47 | bluevirus-design | 3 | · | · | · | NEWPoC 3 | sma-db (3) | — | |
| 48 | ezbsystems | 3 | 3 | · | · | NEWPoC 1 | ultraiso (3) | — | |
| 49 | glfusion | 3 | · | · | · | NEWPoC 2 | glfusion (3) | — | |
| 50 | 3 | · | · | · | PoC 1 | chrome (3) | — |