month report
November 2009
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
November 2009 closed with 311 published CVEs. 66 criticals, sun led volume, mostly via jre. Top weakness class — CWE-79 (46 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
311
— MoM— YoY
Severity mix
66 / 69
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
0.6%
2 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
5953.1
n=2
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
4495
n=1
Detection gap
KEV pressure, no Nuclei coverage
November 2009 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 1microsoft20 CVE
Weakness × Vendor
What's spreading where in November 2009
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #19pear4 CVE
- #21telepark4 CVE
- #25cutephp3 CVE
- #27frontaccounting3 CVE
- #28gforge3 CVE
- #30simplog3 CVE
- #32tftgallery3 CVE
- #34cubecart2 CVE
- #35dag.wieers2 CVE
- #36dnnsoftware2 CVE
Top vendors
Ranked by distinct CVE count this period.
- 32 CVE10 critCVSS 7.1jre (23) · jdk (15) · sdk (10)
- 29 CVE2 critCVSS 6.2mac os x (22) · mac os x server (22) · safari (4)
- 20 CVE11 critCVSS 8.6KEV 1PoC 1office (9) · open xml file format converter (9) · excel (8)
- 12 CVECVSS 6.5PoC 3linux kernel (12) · kernel (1)
- 9 CVE5 critCVSS 7.9PoC 1tivoli storage manager (3) · lotus notes intellisync (1) · powerha (1)
- 9 CVECVSS 5.3typo3 (9)
- 7 CVE4 critCVSS 7.9PoC 1openview network node manager (2) · discovery\&dependency mapping inventory (1) · nonstop server (1)
- 7 CVECVSS 5.3typo3/cms-backend (4) · typo3/cms (1) · typo3/cms-core (1)
- 6 CVE1 critCVSS 7.6PoC 3ubuntu linux (6)
- 5 CVE1 critCVSS 7.3PoC 2debian linux (5)
- 5 CVECVSS 6.4PoC 1php (5)
- 4 CVE4 critCVSS 9.3shockwave player (4)
- 4 CVE1 critCVSS 7.8PoC 1fedora (4)
- 4 CVE2 critCVSS 7.4chrome (4)
- 4 CVE2 critCVSS 7.1PoC 1firefox (2) · bugzilla (1) · nss (1)
- 4 CVECVSS 5.3PoC 1mysql (4)
- 4 CVECVSS 7.0PoC 1opensuse (4)
- 4 CVECVSS 5.3PoC 1mysql (4)
- 4 CVE2 critCVSS 8.6NEWPoC 1pear (3) · mail (1)
- 4 CVECVSS 7.1PoC 1enterprise linux server (3) · enterprise linux desktop (3) · enterprise linux eus (3)
- 4 CVECVSS 5.9NEWPoC 3telepark.wiki (4)
- 4 CVECVSS 6.5esx (4) · server (2) · esxi (2)
- 3 CVE1 critCVSS 7.4PoC 2http server (2) · tomcat (1)
- 3 CVE3 critCVSS 9.3PoC 13ds max (1) · alias wavefront maya (1) · autodesk maya (1)
- 3 CVECVSS 5.5NEWPoC 1cutenews (3)
- 3 CVE1 critCVSS 6.6PoC 2nginx (3)
- 3 CVECVSS 7.5NEWfrontaccounting (3)
- 3 CVECVSS 5.4NEWgforge (3)
- 3 CVECVSS 5.7PoC 1edirectory (1) · groupwise (1) · linux desktop (1)
- 3 CVECVSS 5.4NEWPoC 3simplog (3)
- 3 CVECVSS 7.1PoC 1linux enterprise desktop (2) · linux enterprise server (2) · suse linux enterprise desktop (1)
- 3 CVECVSS 4.5NEWPoC 1tftgallery (3)
- 2 CVE1 critCVSS 6.7PoC 1cacti (2)
- 2 CVECVSS 7.5NEWcubecart (2)
- 2 CVECVSS 4.4NEWdstat (2)
- 2 CVECVSS 4.7NEWdotnetnuke (2)
- 2 CVECVSS 5.9e107 (2)
- 2 CVECVSS 4.3NEWPoC 1e-courirer cms (2)
- 2 CVECVSS 4.2NEWog subgroups (1) · smartqueue og (1)
- 2 CVE2 critCVSS 9.3NEWgimp (2)
- 2 CVE1 critCVSS 8.3PoC 1gnutls (1) · libtool (1)
- 2 CVECVSS 5.3joomla\! (2)
- 2 CVECVSS 5.4NEWmahara (2)
- 2 CVECVSS 5.7NEWmpop (1) · msmtp (1)
- 2 CVECVSS 4.3NEWPoC 1intrushield network security manager (2)
- 2 CVECVSS 5.0NEWPoC 1nginx (2)
- 2 CVECVSS 7.2PoC 1opensuse (2)
- 2 CVE1 critCVSS 7.9opera browser (2)
- 2 CVECVSS 4.7NEWPoC 1tftpd32 (2)
- 2 CVECVSS 6.8NEWPoC 1poppler (2)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | sun | 32 | 10 | · | · | jre (23) · jdk (15) · sdk (10) | — | ||
| 2 | apple | 29 | 2 | · | · | mac os x (22) · mac os x server (22) · safari (4) | — | ||
| 3 | microsoft | 20 | 11 | 1 | · | KEV 1PoC 1 | office (9) · open xml file format converter (9) · excel (8) | — | |
| 4 | linux | 12 | · | · | · | PoC 3 | linux kernel (12) · kernel (1) | — | |
| 5 | ibm | 9 | 5 | · | · | PoC 1 | tivoli storage manager (3) · lotus notes intellisync (1) · powerha (1) | — | |
| 6 | typo3 | 9 | · | · | · | typo3 (9) | — | ||
| 7 | hp | 7 | 4 | · | · | PoC 1 | openview network node manager (2) · discovery\&dependency mapping inventory (1) · nonstop server (1) | — | |
| 8 | packagist | 7 | · | · | · | typo3/cms-backend (4) · typo3/cms (1) · typo3/cms-core (1) | — | ||
| 9 | canonical | 6 | 1 | · | · | PoC 3 | ubuntu linux (6) | — | |
| 10 | debian | 5 | 1 | · | · | PoC 2 | debian linux (5) | — | |
| 11 | php | 5 | · | · | · | PoC 1 | php (5) | — | |
| 12 | adobe | 4 | 4 | · | · | shockwave player (4) | — | ||
| 13 | fedoraproject | 4 | 1 | · | · | PoC 1 | fedora (4) | — | |
| 14 | 4 | 2 | · | · | chrome (4) | — | |||
| 15 | mozilla | 4 | 2 | · | · | PoC 1 | firefox (2) · bugzilla (1) · nss (1) | — | |
| 16 | mysql | 4 | · | · | · | PoC 1 | mysql (4) | — | |
| 17 | opensuse | 4 | · | · | · | PoC 1 | opensuse (4) | — | |
| 18 | oracle | 4 | · | · | · | PoC 1 | mysql (4) | — | |
| 19 | pear | 4 | 2 | · | · | NEWPoC 1 | pear (3) · mail (1) | — | |
| 20 | redhat | 4 | · | · | · | PoC 1 | enterprise linux server (3) · enterprise linux desktop (3) · enterprise linux eus (3) | — | |
| 21 | telepark | 4 | · | · | · | NEWPoC 3 | telepark.wiki (4) | — | |
| 22 | vmware | 4 | · | · | · | esx (4) · server (2) · esxi (2) | — | ||
| 23 | apache | 3 | 1 | · | · | PoC 2 | http server (2) · tomcat (1) | — | |
| 24 | autodesk | 3 | 3 | · | · | PoC 1 | 3ds max (1) · alias wavefront maya (1) · autodesk maya (1) | — | |
| 25 | cutephp | 3 | · | · | · | NEWPoC 1 | cutenews (3) | — | |
| 26 | f5 | 3 | 1 | · | · | PoC 2 | nginx (3) | — | |
| 27 | frontaccounting | 3 | · | · | · | NEW | frontaccounting (3) | — | |
| 28 | gforge | 3 | · | · | · | NEW | gforge (3) | — | |
| 29 | novell | 3 | · | · | · | PoC 1 | edirectory (1) · groupwise (1) · linux desktop (1) | — | |
| 30 | simplog | 3 | · | · | · | NEWPoC 3 | simplog (3) | — | |
| 31 | suse | 3 | · | · | · | PoC 1 | linux enterprise desktop (2) · linux enterprise server (2) · suse linux enterprise desktop (1) | — | |
| 32 | tftgallery | 3 | · | · | · | NEWPoC 1 | tftgallery (3) | — | |
| 33 | cacti | 2 | 1 | · | · | PoC 1 | cacti (2) | — | |
| 34 | cubecart | 2 | · | · | · | NEW | cubecart (2) | — | |
| 35 | dag.wieers | 2 | · | · | · | NEW | dstat (2) | — | |
| 36 | dnnsoftware | 2 | · | · | · | NEW | dotnetnuke (2) | — | |
| 37 | e107 | 2 | · | · | · | e107 (2) | — | ||
| 38 | ecouriersoftware | 2 | · | · | · | NEWPoC 1 | e-courirer cms (2) | — | |
| 39 | ezra barnett gildesgame | 2 | · | · | · | NEW | og subgroups (1) · smartqueue og (1) | — | |
| 40 | gimp | 2 | 2 | · | · | NEW | gimp (2) | — | |
| 41 | gnu | 2 | 1 | · | · | PoC 1 | gnutls (1) · libtool (1) | — | |
| 42 | joomla | 2 | · | · | · | joomla\! (2) | — | ||
| 43 | mahara | 2 | · | · | · | NEW | mahara (2) | — | |
| 44 | martin lambers | 2 | · | · | · | NEW | mpop (1) · msmtp (1) | — | |
| 45 | mcafee | 2 | · | · | · | NEWPoC 1 | intrushield network security manager (2) | — | |
| 46 | nginx | 2 | · | · | · | NEWPoC 1 | nginx (2) | — | |
| 47 | novell inc. | 2 | · | · | · | PoC 1 | opensuse (2) | — | |
| 48 | opera | 2 | 1 | · | · | opera browser (2) | — | ||
| 49 | philippe jounin | 2 | · | · | · | NEWPoC 1 | tftpd32 (2) | — | |
| 50 | poppler | 2 | · | · | · | NEWPoC 1 | poppler (2) | — |