month report
April 2009
Data as of Jun 11, 2026, 06:04 UTCSnapshot v1 Sources CVEList V5+NVD+GHSA+CSAF+FSTEC BDU+CISA KEV+EPSS+Nuclei templates Methodology →
April 2009 closed with 570 published CVEs. 89 criticals, oracle led volume, mostly via application server. Top weakness class — CWE-79 (77 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
570
— MoM— YoY
Severity mix
89 / 147
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
0.5%
3 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
6156.2
n=3
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
6123
n=1
Detection gap
KEV pressure, no Nuclei coverage
April 2009 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 1microsoft23 CVE
Weakness × Vendor
What's spreading where in April 2009
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS89SQL Injection119Memory Buffer Bounds20Improper Input Validation264CWE-26422Path Traversal94Code Injection189CWE-189399CWE-399287Improper Authenticationoraclemicrosoft1222324novell inc.42164apple53135ibm211mozilla224foolabs41134glyphandcog41134sun1311сообщество свободного программного обеспечения142apache51gentoo foundation inc.132
Most discussed CVEs — April 2009
No CVE mentions in the news this month yet.
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #7foolabs13 CVE
- #8glyphandcog13 CVE
- #12poppler10 CVE
- #22mini-stream7 CVE
- #25peterselie6 CVE
- #26quickersite6 CVE
- #27razorcms6 CVE
- #28viart6 CVE
- #29webbdomain6 CVE
- #30china-on-site5 CVE
Top vendors
Ranked by distinct CVE count this period.
- 43 CVE3 critCVSS 5.5PoC 1application server (12) · database 10g (11) · database 11g (11)
- 23 CVE12 critCVSS 8.3KEV 1PoC 1windows xp (8) · windows 2000 (6) · windows vista (6)
- 20 CVE2 critCVSS 6.5PoC 5cups (13) · mac os x (6) · mac os x server (5)
- 18 CVE2 critCVSS 5.9PoC 2suse linux enterprise (12) · opensuse (6)
- 14 CVE2 critCVSS 6.2PoC 3websphere portal (3) · advanced management module (3) · bladecenter (2)
- 14 CVE1 critCVSS 5.0PoC 3firefox (13) · seamonkey (10) · thunderbird (8)
- 13 CVE1 critCVSS 6.0NEWxpdf (13)
- 13 CVE1 critCVSS 6.0NEWxpdfreader (13)
- 12 CVE2 critCVSS 6.5PoC 3debian gnu/linux (12)
- 11 CVECVSS 4.5PoC 3opensolaris (4) · solaris (3) · openjdk (2)
- 10 CVE1 critCVSS 4.8PoC 3struts (3) · geronimo (3) · mod jk (1)
- 10 CVECVSS 5.5NEWpoppler (10)
- 9 CVE4 critCVSS 8.0communication manager (9) · sip enablement services (4)
- 9 CVE1 critCVSS 6.1PoC 3gentoo linux (9)
- 9 CVE3 critCVSS 7.1storageworks storage mirroring (3) · hp-ux (1) · openview network node manager (1)
- 9 CVECVSS 5.5PoC 2linux kernel (9)
- 8 CVECVSS 6.4pix (6) · adaptive security appliance 5500 (6) · ios (1)
- 8 CVE2 critCVSS 7.2PoC 1debian linux (5) · advanced package tool (2) · apt (1)
- 8 CVE1 critCVSS 5.7PoC 3org.apache.geronimo.plugins:console (3) · org.apache.struts:struts2-core (1) · org.apache.struts:struts2-dojo-plugin (1)
- 8 CVE1 critCVSS 6.1PoC 1ace (6) · workstation (5) · player (5)
- 7 CVE1 critCVSS 6.4PoC 1ubuntu linux (7)
- 7 CVE7 critCVSS 9.3NEWPoC 7wm downloader (1) · asx to mp3 converter (1) · easy rm to mp3 converter (1)
- 7 CVE2 critCVSS 8.2PoC 1red hat enterprise linux (5) · enterprise linux desktop (1) · enterprise linux eus (1)
- 7 CVE4 critCVSS 7.9PoC 1endpoint protection (5) · antivirus (5) · client security (4)
- 6 CVECVSS 5.8NEWPoC 5yourplace (6)
- 6 CVECVSS 6.1NEWPoC 2quickersite (6)
- 6 CVECVSS 5.7NEWPoC 3razorcms (6)
- 6 CVECVSS 5.0NEWPoC 2viart shop (6)
- 6 CVECVSS 7.0NEWPoC 6petition (1) · polls (1) · post card (1)
- 5 CVE2 critCVSS 7.9NEWPoC 5flexphpdirectory (2) · flexphplink (2) · flexcustomer0.0.6 (1)
- 5 CVE1 critCVSS 7.1NEWclamav (5)
- 5 CVECVSS 4.7PoC 2gnutls (3) · gnu screen (1) · screen (1)
- 5 CVECVSS 5.9NEWPoC 3lightneasy (5)
- 5 CVE2 critCVSS 6.9PoC 1wireshark (5)
- 4 CVECVSS 4.3NEWPoC 1dotnetnuke (4)
- 4 CVECVSS 4.3cck comment reference (1) · feedapi mapper (1) · localization client (1)
- 4 CVE1 critCVSS 6.0PoC 1fedora (4)
- 4 CVE2 critCVSS 7.8NEWPoC 2ghostscript (4)
- 4 CVE2 critCVSS 8.2cs1000 (4)
- 4 CVE1 critCVSS 5.3teaming (2) · access manager (1) · netidentity client1.2.3 (1)
- 4 CVECVSS 5.4PoC 1opensuse (4)
- 4 CVECVSS 6.0NEWPoC 4simple machines forum (4)
- 4 CVECVSS 6.1NEWPoC 2sqlite (4)
- 4 CVE1 critCVSS 6.3NEWPoC 2s.t.a.l.k.e.r.\ (4)
- 4 CVECVSS 6.3NEWnd antispam (1) · pmk rssnewsexport extension (1) · tjs reslib (1)
- 3 CVECVSS 7.3NEWPoC 3minimal-ablog (2) · minimal ablog (1)
- 3 CVECVSS 6.4NEWPoC 3sma-db (3)
- 3 CVE3 critCVSS 9.3NEWPoC 1ultraiso (3)
- 3 CVECVSS 6.2NEWPoC 2glfusion (3)
- 3 CVECVSS 5.5PoC 1chrome (3)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | oracle | 43 | 3 | · | · | PoC 1 | application server (12) · database 10g (11) · database 11g (11) | — | |
| 2 | microsoft | 23 | 12 | 1 | · | KEV 1PoC 1 | windows xp (8) · windows 2000 (6) · windows vista (6) | — | |
| 3 | apple | 20 | 2 | · | · | PoC 5 | cups (13) · mac os x (6) · mac os x server (5) | — | |
| 4 | novell inc. | 18 | 2 | · | · | PoC 2 | suse linux enterprise (12) · opensuse (6) | — | |
| 5 | ibm | 14 | 2 | · | · | PoC 3 | websphere portal (3) · advanced management module (3) · bladecenter (2) | — | |
| 6 | mozilla | 14 | 1 | · | · | PoC 3 | firefox (13) · seamonkey (10) · thunderbird (8) | — | |
| 7 | foolabs | 13 | 1 | · | · | NEW | xpdf (13) | — | |
| 8 | glyphandcog | 13 | 1 | · | · | NEW | xpdfreader (13) | — | |
| 9 | сообщество свободного программного обеспечения | 12 | 2 | · | · | PoC 3 | debian gnu/linux (12) | — | |
| 10 | sun | 11 | · | · | · | PoC 3 | opensolaris (4) · solaris (3) · openjdk (2) | — | |
| 11 | apache | 10 | 1 | · | · | PoC 3 | struts (3) · geronimo (3) · mod jk (1) | — | |
| 12 | poppler | 10 | · | · | · | NEW | poppler (10) | — | |
| 13 | avaya | 9 | 4 | · | · | communication manager (9) · sip enablement services (4) | — | ||
| 14 | gentoo foundation inc. | 9 | 1 | · | · | PoC 3 | gentoo linux (9) | — | |
| 15 | hp | 9 | 3 | · | · | storageworks storage mirroring (3) · hp-ux (1) · openview network node manager (1) | — | ||
| 16 | linux | 9 | · | · | · | PoC 2 | linux kernel (9) | — | |
| 17 | cisco | 8 | · | · | · | pix (6) · adaptive security appliance 5500 (6) · ios (1) | — | ||
| 18 | debian | 8 | 2 | · | · | PoC 1 | debian linux (5) · advanced package tool (2) · apt (1) | — | |
| 19 | maven | 8 | 1 | · | · | PoC 3 | org.apache.geronimo.plugins:console (3) · org.apache.struts:struts2-core (1) · org.apache.struts:struts2-dojo-plugin (1) | — | |
| 20 | vmware | 8 | 1 | · | · | PoC 1 | ace (6) · workstation (5) · player (5) | — | |
| 21 | canonical | 7 | 1 | · | · | PoC 1 | ubuntu linux (7) | — | |
| 22 | mini-stream | 7 | 7 | · | · | NEWPoC 7 | wm downloader (1) · asx to mp3 converter (1) · easy rm to mp3 converter (1) | — | |
| 23 | redhat | 7 | 2 | · | · | PoC 1 | red hat enterprise linux (5) · enterprise linux desktop (1) · enterprise linux eus (1) | — | |
| 24 | symantec | 7 | 4 | · | · | PoC 1 | endpoint protection (5) · antivirus (5) · client security (4) | — | |
| 25 | peterselie | 6 | · | · | · | NEWPoC 5 | yourplace (6) | — | |
| 26 | quickersite | 6 | · | · | · | NEWPoC 2 | quickersite (6) | — | |
| 27 | razorcms | 6 | · | · | · | NEWPoC 3 | razorcms (6) | — | |
| 28 | viart | 6 | · | · | · | NEWPoC 2 | viart shop (6) | — | |
| 29 | webbdomain | 6 | · | · | · | NEWPoC 6 | petition (1) · polls (1) · post card (1) | — | |
| 30 | china-on-site | 5 | 2 | · | · | NEWPoC 5 | flexphpdirectory (2) · flexphplink (2) · flexcustomer0.0.6 (1) | — | |
| 31 | clamav | 5 | 1 | · | · | NEW | clamav (5) | — | |
| 32 | gnu | 5 | · | · | · | PoC 2 | gnutls (3) · gnu screen (1) · screen (1) | — | |
| 33 | lightneasy | 5 | · | · | · | NEWPoC 3 | lightneasy (5) | — | |
| 34 | wireshark | 5 | 2 | · | · | PoC 1 | wireshark (5) | — | |
| 35 | dnnsoftware | 4 | · | · | · | NEWPoC 1 | dotnetnuke (4) | — | |
| 36 | drupal | 4 | · | · | · | cck comment reference (1) · feedapi mapper (1) · localization client (1) | — | ||
| 37 | fedoraproject | 4 | 1 | · | · | PoC 1 | fedora (4) | — | |
| 38 | ghostscript | 4 | 2 | · | · | NEWPoC 2 | ghostscript (4) | — | |
| 39 | nortel | 4 | 2 | · | · | cs1000 (4) | — | ||
| 40 | novell | 4 | 1 | · | · | teaming (2) · access manager (1) · netidentity client1.2.3 (1) | — | ||
| 41 | opensuse | 4 | · | · | · | PoC 1 | opensuse (4) | — | |
| 42 | simple machines | 4 | · | · | · | NEWPoC 4 | simple machines forum (4) | — | |
| 43 | sqlite | 4 | · | · | · | NEWPoC 2 | sqlite (4) | — | |
| 44 | stalker-game | 4 | 1 | · | · | NEWPoC 2 | s.t.a.l.k.e.r.\ (4) | — | |
| 45 | typo3 | 4 | · | · | · | NEW | nd antispam (1) · pmk rssnewsexport extension (1) · tjs reslib (1) | — | |
| 46 | abweb | 3 | · | · | · | NEWPoC 3 | minimal-ablog (2) · minimal ablog (1) | — | |
| 47 | bluevirus-design | 3 | · | · | · | NEWPoC 3 | sma-db (3) | — | |
| 48 | ezbsystems | 3 | 3 | · | · | NEWPoC 1 | ultraiso (3) | — | |
| 49 | glfusion | 3 | · | · | · | NEWPoC 2 | glfusion (3) | — | |
| 50 | 3 | · | · | · | PoC 1 | chrome (3) | — |
Sectors
Solution categories ranked by distinct CVE count this period.
- Web & CMS Plugins167 CVE8 crit91 vendorsCVSS 10.0razorcms (6) · dotnetnuke (4) · geronimo (3)
- Operating Systems99 CVE58 crit2 KEV23 vendorsCVSS 8.3debian gnu/linux (12) · suse linux enterprise (12) · opensuse (10)
- Consumer Software64 CVE23 crit23 vendorsCVSS 8.8xpdfreader (13) · ultraiso (3) · air filemanager (1)
- Databases50 CVE3 crit4 vendorsCVSS 7.5application server (12) · database 10g (11) · database 11g (11)
- OSS Libraries50 CVE6 crit19 vendorsCVSS 5.9xpdf (13) · poppler (10) · ghostscript (4)
- Enterprise Software37 CVE16 crit14 vendorsCVSS 10.0advanced management module (3) · storageworks storage mirroring (3) · websphere portal (3)
- Security Products29 CVE21 crit12 vendorsCVSS 10.0antivirus (5) · clamav (5) · endpoint protection (5)
- Mobile Apps23 CVE3 crit2 vendorsCVSS 6.5cups (13) · mac os x (6) · mac os x server (5)
- 3 crit9 vendorsCVSS 8.4adaptive security appliance 5500 (6) · pix (6) · 1701hg (1)
- Communications16 CVE7 crit7 vendorsCVSS 8.1communication manager (9) · sip enablement services (4) · wanpipe (1)
- Cloud & SaaS15 CVE4 crit3 vendorsCVSS 7.2ace (6) · player (5) · server (5)
- ICS / OT / IoT4 CVE3 vendorsCVSS 7.5acute control panel (1) · acutecp (1)
- Hardware Firmware1 CVE1 crit1 vendorsCVSS 10.0adsl2\/2\+4-port router (1)
- Unclassified63 CVE6 crit47 vendorsCVSS 6.4quickersite (6) · sunage (3) · ablespace (2)
| Sector | CVEs | Crit | KEV | Vendors | Products | Avg CVSS | Top products |
|---|---|---|---|---|---|---|---|
| Web & CMS Plugins▸ 6 | 167 | 8 | · | 91 | 113 | 10.0 | razorcms (6) · dotnetnuke (4) · geronimo (3) |
| Operating Systems▸ 3 | 99 | 58 | 2 | 23 | 66 | 8.3 | debian gnu/linux (12) · suse linux enterprise (12) · opensuse (10) |
| Consumer Software▸ 5 | 64 | 23 | · | 23 | 34 | 8.8 | xpdfreader (13) · ultraiso (3) · air filemanager (1) |
| Databases▸ 3 | 50 | 3 | · | 4 | 14 | 7.5 | application server (12) · database 10g (11) · database 11g (11) |
| OSS Libraries▸ 6 | 50 | 6 | · | 19 | 28 | 5.9 | xpdf (13) · poppler (10) · ghostscript (4) |
| Enterprise Software▸ 5 | 37 | 16 | · | 14 | 40 | 10.0 | advanced management module (3) · storageworks storage mirroring (3) · websphere portal (3) |
| Security Products▸ 5 | 29 | 21 | · | 12 | 33 | 10.0 | antivirus (5) · clamav (5) · endpoint protection (5) |
| Mobile Apps▸ 2 | 23 | 3 | · | 2 | 6 | 6.5 | cups (13) · mac os x (6) · mac os x server (5) |
| Networking Infrastructure▸ 4 | 18 | 3 | · | 9 | 34 | 8.4 | adaptive security appliance 5500 (6) · pix (6) · 1701hg (1) |
| Communications▸ 3 | 16 | 7 | · | 7 | 8 | 8.1 | communication manager (9) · sip enablement services (4) · wanpipe (1) |
| Cloud & SaaS▸ 2 | 15 | 4 | · | 3 | 17 | 7.2 | ace (6) · player (5) · server (5) |
| ICS / OT / IoT▸ 2 | 4 | · | · | 3 | 3 | 7.5 | acute control panel (1) · acutecp (1) |
| Hardware Firmware▸ 1 | 1 | 1 | · | 1 | 1 | 10.0 | adsl2\/2\+4-port router (1) |
| Unclassified | 63 | 6 | · | 47 | 49 | 6.4 | quickersite (6) · sunage (3) · ablespace (2) |
Weakness × Sector
Which weaknesses hit which solution categories in April 2009
Cells shaded by share of the sector's hottest weakness. Click a row to open the sector history.
79XSS89SQL Injection119Memory Buffer Bounds20Improper Input Validation264CWE-26422Path Traversal94Code Injection189CWE-189399CWE-399287Improper AuthenticationWeb & CMS Plugins415719171314112Operating Systems3131561126Consumer Software322173138151OSS Libraries82125341861Enterprise Software742112Databases11221Networking Infrastructure311311Security Products22461132Communications3111231Cloud & SaaS112221