month report
May 2009
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
May 2009 closed with 367 published CVEs. 80 criticals, apple led volume, mostly via mac os x. Top weakness class — CWE-89 (66 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
367
— MoM— YoY
Severity mix
80 / 109
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
0.8%
3 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
6148.2
n=3
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
6200
n=1
Detection gap
KEV pressure, no Nuclei coverage
May 2009 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 1microsoft16 CVE
Weakness × Vendor
What's spreading where in May 2009
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #6scripts-for-sites8 CVE
- #8collector6 CVE
- #112daybiz5 CVE
- #12cgi rescue5 CVE
- #14easy-scripts5 CVE
- #16mini-stream5 CVE
- #18aten4 CVE
- #20icewarp4 CVE
- #23pidgin4 CVE
- #24armorlogic3 CVE
Top vendors
Ranked by distinct CVE count this period.
- 21 CVE3 critCVSS 6.3mac os x (18) · mac os x server (17) · safari (3)
- 16 CVE13 critCVSS 9.0KEV 1PoC 2office powerpoint (13) · windows xp (3) · office compatibility pack for word excel ppt 2007 (1)
- 9 CVE4 critCVSS 7.1PoC 3solaris (3) · jre (2) · java system portal server (1)
- 8 CVE1 critCVSS 8.4Nuclei 1PoC 3wvc54gca (5) · wvc54gc (1) · telepresence readiness assessment manager (1)
- 8 CVE2 critCVSS 6.7PoC 3gentoo linux (8)
- 8 CVECVSS 7.5NEWPoC 8ez adult directory (1) · ez affiliate (1) · ez auction (1)
- 7 CVE3 critCVSS 8.2PoC 1tivoli storage manager client (4) · tivoli storage manager express (3) · aix (1)
- 6 CVECVSS 5.2NEWPoC 6mycolex (3) · mygesuad (3)
- 6 CVE2 critCVSS 6.7red hat enterprise linux (6)
- 6 CVE1 critCVSS 6.5PoC 1debian gnu/linux (6)
- 5 CVECVSS 6.4NEWPoC 5business community script (2) · custom t-shirt design script (2) · template monster clone (1)
- 5 CVECVSS 4.6NEWform2mail (1) · rescue (1) · cgi rescue minibbs (1)
- 5 CVECVSS 5.0drupal (2) · news page (1) · nodeaccess userreference (1)
- 5 CVECVSS 6.3NEWPoC 5answer and question script (5)
- 5 CVE2 critCVSS 6.9PoC 2chrome (4) · android (1)
- 5 CVE5 critCVSS 9.3NEWPoC 5easy rm-mp3 converter (1) · castripper (1) · mini-stream rm downloader (1)
- 5 CVECVSS 5.8PoC 1squirrelmail (5) · imap general.php (1)
- 4 CVE3 critCVSS 9.5NEWkh1516i ip kvm switch (4) · kn9116 ip kvm switch (4) · pn9108 power over the net (1)
- 4 CVE2 critCVSS 7.9PoC 1openview network node manager (1) · data protector express (1) · remote graphics software (1)
- 4 CVECVSS 5.4NEWPoC 2webmail server (3) · email server (3) · merak mail server (1)
- 4 CVECVSS 5.7PoC 1linux kernel (4)
- 4 CVE1 critCVSS 6.5groupwise (4)
- 4 CVE1 critCVSS 6.6NEWpidgin (4)
- 3 CVE1 critCVSS 7.3NEWprofense web application firewall (3)
- 3 CVECVSS 5.5PoC 2ubuntu linux (3)
- 3 CVECVSS 5.4PoC 1debian linux (3)
- 3 CVE3 critCVSS 9.8NEWPoC 332bit ftp (3)
- 3 CVECVSS 7.5NEWPoC 3php recommend (3)
- 3 CVECVSS 5.4NEWfreepbx (3)
- 3 CVECVSS 5.4NEWPoC 3leap (3)
- 3 CVECVSS 6.6NEWPoC 1application access server (3)
- 3 CVECVSS 5.1NEWPoC 3photo gallery (3)
- 3 CVE1 critCVSS 6.4PoC 2firefox (3)
- 3 CVE3 critCVSS 9.3NEWPoC 2winamp (3)
- 3 CVECVSS 5.9NEWPoC 3vidsharepro (3)
- 3 CVECVSS 5.0NEWPoC 2openssl (3)
- 3 CVECVSS 5.0NEWPoC 2openssl (3)
- 3 CVECVSS 4.9NEWPoC 2tematres (3)
- 3 CVECVSS 5.4NEWfreepbx (3)
- 3 CVECVSS 7.5NEWPoC 3filestream (1) · linktracker (1) · livehelp (1)
- 3 CVECVSS 5.5NEWlinux (3)
- 3 CVECVSS 5.0NEWPoC 2rosa virtualization (3) · rosa virtualization 3.0 (3)
- 2 CVECVSS 4.7NEWactivecollab (2)
- 2 CVE2 critCVSS 9.3PoC 1storm (2)
- 2 CVECVSS 7.0PoC 2bitweaver (2)
- 2 CVECVSS 7.5NEWPoC 2booking system for hotels group (2)
- 2 CVE2 critCVSS 9.3NEWPoC 1cscope (2)
- 2 CVECVSS 4.7NEWPoC 2dew-newphplinks (2)
- 2 CVECVSS 7.7NEWPoC 1directadmin (2)
- 2 CVECVSS 7.5NEWPoC 2flyspeck cms (2)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | apple | 21 | 3 | · | · | mac os x (18) · mac os x server (17) · safari (3) | — | ||
| 2 | microsoft | 16 | 13 | 1 | · | KEV 1PoC 2 | office powerpoint (13) · windows xp (3) · office compatibility pack for word excel ppt 2007 (1) | — | |
| 3 | sun | 9 | 4 | · | · | PoC 3 | solaris (3) · jre (2) · java system portal server (1) | — | |
| 4 | cisco | 8 | 1 | · | 1 | Nuclei 1PoC 3 | wvc54gca (5) · wvc54gc (1) · telepresence readiness assessment manager (1) | — | |
| 5 | gentoo foundation inc. | 8 | 2 | · | · | PoC 3 | gentoo linux (8) | — | |
| 6 | scripts-for-sites | 8 | · | · | · | NEWPoC 8 | ez adult directory (1) · ez affiliate (1) · ez auction (1) | — | |
| 7 | ibm | 7 | 3 | · | · | PoC 1 | tivoli storage manager client (4) · tivoli storage manager express (3) · aix (1) | — | |
| 8 | collector | 6 | · | · | · | NEWPoC 6 | mycolex (3) · mygesuad (3) | — | |
| 9 | red hat inc. | 6 | 2 | · | · | red hat enterprise linux (6) | — | ||
| 10 | сообщество свободного программного обеспечения | 6 | 1 | · | · | PoC 1 | debian gnu/linux (6) | — | |
| 11 | 2daybiz | 5 | · | · | · | NEWPoC 5 | business community script (2) · custom t-shirt design script (2) · template monster clone (1) | — | |
| 12 | cgi rescue | 5 | · | · | · | NEW | form2mail (1) · rescue (1) · cgi rescue minibbs (1) | — | |
| 13 | drupal | 5 | · | · | · | drupal (2) · news page (1) · nodeaccess userreference (1) | — | ||
| 14 | easy-scripts | 5 | · | · | · | NEWPoC 5 | answer and question script (5) | — | |
| 15 | 5 | 2 | · | · | PoC 2 | chrome (4) · android (1) | — | ||
| 16 | mini-stream | 5 | 5 | · | · | NEWPoC 5 | easy rm-mp3 converter (1) · castripper (1) · mini-stream rm downloader (1) | — | |
| 17 | squirrelmail | 5 | · | · | · | PoC 1 | squirrelmail (5) · imap general.php (1) | — | |
| 18 | aten | 4 | 3 | · | · | NEW | kh1516i ip kvm switch (4) · kn9116 ip kvm switch (4) · pn9108 power over the net (1) | — | |
| 19 | hp | 4 | 2 | · | · | PoC 1 | openview network node manager (1) · data protector express (1) · remote graphics software (1) | — | |
| 20 | icewarp | 4 | · | · | · | NEWPoC 2 | webmail server (3) · email server (3) · merak mail server (1) | — | |
| 21 | linux | 4 | · | · | · | PoC 1 | linux kernel (4) | — | |
| 22 | novell | 4 | 1 | · | · | groupwise (4) | — | ||
| 23 | pidgin | 4 | 1 | · | · | NEW | pidgin (4) | — | |
| 24 | armorlogic | 3 | 1 | · | · | NEW | profense web application firewall (3) | — | |
| 25 | canonical | 3 | · | · | · | PoC 2 | ubuntu linux (3) | — | |
| 26 | debian | 3 | · | · | · | PoC 1 | debian linux (3) | — | |
| 27 | electrasoft | 3 | 3 | · | · | NEWPoC 3 | 32bit ftp (3) | — | |
| 28 | frax | 3 | · | · | · | NEWPoC 3 | php recommend (3) | — | |
| 29 | freepbx | 3 | · | · | · | NEW | freepbx (3) | — | |
| 30 | gowondesigns | 3 | · | · | · | NEWPoC 3 | leap (3) | — | |
| 31 | klinzmann | 3 | · | · | · | NEWPoC 1 | application access server (3) | — | |
| 32 | minddezign | 3 | · | · | · | NEWPoC 3 | photo gallery (3) | — | |
| 33 | mozilla | 3 | 1 | · | · | PoC 2 | firefox (3) | — | |
| 34 | nullsoft | 3 | 3 | · | · | NEWPoC 2 | winamp (3) | — | |
| 35 | omnisoftsol | 3 | · | · | · | NEWPoC 3 | vidsharepro (3) | — | |
| 36 | openssl | 3 | · | · | · | NEWPoC 2 | openssl (3) | — | |
| 37 | openssl software foundation | 3 | · | · | · | NEWPoC 2 | openssl (3) | — | |
| 38 | r020 | 3 | · | · | · | NEWPoC 2 | tematres (3) | — | |
| 39 | sangoma | 3 | · | · | · | NEW | freepbx (3) | — | |
| 40 | teraway | 3 | · | · | · | NEWPoC 3 | filestream (1) · linktracker (1) · livehelp (1) | — | |
| 41 | ubuntu | 3 | · | · | · | NEW | linux (3) | — | |
| 42 | ао «нтц ит роса» | 3 | · | · | · | NEWPoC 2 | rosa virtualization (3) · rosa virtualization 3.0 (3) | — | |
| 43 | activecollab | 2 | · | · | · | NEW | activecollab (2) | — | |
| 44 | baofeng | 2 | 2 | · | · | PoC 1 | storm (2) | — | |
| 45 | bitweaver | 2 | · | · | · | PoC 2 | bitweaver (2) | — | |
| 46 | bookingcentre | 2 | · | · | · | NEWPoC 2 | booking system for hotels group (2) | — | |
| 47 | cscope | 2 | 2 | · | · | NEWPoC 1 | cscope (2) | — | |
| 48 | dew-code | 2 | · | · | · | NEWPoC 2 | dew-newphplinks (2) | — | |
| 49 | directadmin | 2 | · | · | · | NEWPoC 1 | directadmin (2) | — | |
| 50 | flyspeck | 2 | · | · | · | NEWPoC 2 | flyspeck cms (2) | — |