month report
April 2011
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
April 2011 closed with 312 published CVEs — -40.0% YoY . 47 criticals, microsoft led volume, mostly via windows xp. Biggest breakout: oracle at ×12.3 their 12-month median. Top weakness class — CWE-399 (38 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
312
— MoM-40.0% YoY
Severity mix
47 / 55
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
0.6%
2 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
5446.0
n=2
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
3977
n=1
Weakness × Vendor
What's spreading where in April 2011
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
Breakout vendors
CVE count ≥3× their own 12-period median.
- 12.3×oracle49 CVE
- 4.7×mediawiki7 CVE
- 4.7×red hat inc.7 CVE
- 4.0×mono4 CVE
- 3.0×horde3 CVE
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #167t4 CVE
- #17mark pilgrim4 CVE
- #18mono4 CVE
- #21aphpkb3 CVE
- #23icanlocalize3 CVE
- #29baconmap2 CVE
- #35enanocms2 CVE
- #36joomlaseller2 CVE
- #40ncpfs2 CVE
- #42phpwebscripts2 CVE
Top vendors
Ranked by distinct CVE count this period.
- 54 CVE18 critCVSS 7.9PoC 1windows xp (38) · windows server 2003 (36) · windows server 2008 (35)
- 49 CVE1 critCVSS 5.0×12.3peoplesoft and jdedwards product suite (10) · jd edwards enterpriseone ep (8) · database server (8)
- 23 CVE3 critCVSS 5.0tivoli directory server (17) · webi (2) · soliddb (1)
- 19 CVE3 critCVSS 5.6network node manager i (4) · photosmart b110 (3) · photosmart d110 (3)
- 12 CVE1 critCVSS 4.8sunos (11) · java system application server (1)
- 9 CVE2 critCVSS 6.6moonlight (4) · opensuse build service (2) · zenworks configuration management (1)
- 8 CVECVSS 4.9PoC 3gentoo linux (8)
- 7 CVECVSS 3.6linux kernel (4) · util-linux (3)
- 7 CVECVSS 4.5×4.7PoC 1mediawiki (7)
- 7 CVECVSS 4.0spice-xpi (2) · enterprise linux desktop (2) · enterprise linux workstation (2)
- 7 CVE1 critCVSS 5.5×4.7red hat enterprise linux (7)
- 6 CVECVSS 4.7rt (6)
- 6 CVECVSS 5.0PoC 2glibc (6) · eglibc (1)
- 6 CVE3 critCVSS 8.3KEV 1PoC 3chrome (5) · android (1)
- 5 CVE2 critCVSS 7.7total defense (3) · output management web viewer (1) · siteminder (1)
- 4 CVE4 critCVSS 10.0NEWPoC 4igss (4)
- 4 CVECVSS 4.5NEWPoC 3feedparser (4)
- 4 CVECVSS 6.0NEW×4.0mono (4)
- 4 CVECVSS 4.5PoC 3feedparser (4)
- 4 CVE4 critCVSS 9.5PoC 1helix mobile server (2) · helix server (2) · realplayer (2)
- 3 CVECVSS 7.0NEWPoC 2aphpkb (3)
- 3 CVECVSS 4.3×3.0groupware (2) · dynamic imp (1) · gollem (1)
- 3 CVECVSS 6.2NEWtranslation management (3)
- 3 CVECVSS 7.3KEV 1PoC 1opensuse (3)
- 3 CVECVSS 5.2KEV 1PoC 1linux enterprise desktop (2) · linux enterprise server (2)
- 3 CVE1 critCVSS 6.0PoC 1wireshark (3)
- 2 CVECVSS 5.4tomcat (2)
- 2 CVECVSS 4.7iphone os (1) · webkit (1)
- 2 CVECVSS 6.8NEWPoC 2baconmap (2)
- 2 CVECVSS 4.8PoC 1ubuntu linux (2)
- 2 CVE1 critCVSS 7.5ios (1) · secure access control system (1)
- 2 CVECVSS 5.0PoC 1debian linux (2)
- 2 CVE1 critCVSS 7.0asterisk (2)
- 2 CVECVSS 5.6networker (1) · rsa adaptive authentication on-premise (1)
- 2 CVECVSS 6.3NEWPoC 2enano cms (2)
- 2 CVECVSS 5.9NEWPoC 2com jscalendar (2)
- 2 CVECVSS 5.0kde sc (2)
- 2 CVECVSS 5.4org.apache.tomcat:tomcat (2)
- 2 CVE1 critCVSS 6.2firefox (2) · seamonkey (1)
- 2 CVECVSS 3.9NEWncpfs (2)
- 2 CVECVSS 5.9prosafe wnap210 firmware (2) · prosafe wnap210 (2)
- 2 CVECVSS 4.7NEWPoC 1easy banner free (2)
- 2 CVECVSS 4.7NEWPoC 2qooxdoo (2)
- 2 CVE2 critCVSS 10.0NEWPoC 2realwin (2)
- 2 CVECVSS 4.5webmail (2)
- 2 CVE1 critCVSS 6.3centos (2)
- 2 CVECVSS 5.5NEWPoC 1phplist (2)
- 2 CVECVSS 5.7open-vm-tools (1) · vix api (1) · workstation (1)
- 2 CVECVSS 4.8PoC 1debian gnu/linux (1) · perl (1)
- 1 CVECVSS 8.8KEV 1PoC 1acrobat (1) · acrobat reader (1) · adobe air (1)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | microsoft | 54 | 18 | · | · | PoC 1 | windows xp (38) · windows server 2003 (36) · windows server 2008 (35) | — | |
| 2 | oracle | 49 | 1 | · | · | ×12.3 | peoplesoft and jdedwards product suite (10) · jd edwards enterpriseone ep (8) · database server (8) | — | |
| 3 | ibm | 23 | 3 | · | · | tivoli directory server (17) · webi (2) · soliddb (1) | — | ||
| 4 | hp | 19 | 3 | · | · | network node manager i (4) · photosmart b110 (3) · photosmart d110 (3) | — | ||
| 5 | sun | 12 | 1 | · | · | sunos (11) · java system application server (1) | — | ||
| 6 | novell | 9 | 2 | · | · | moonlight (4) · opensuse build service (2) · zenworks configuration management (1) | — | ||
| 7 | gentoo foundation inc. | 8 | · | · | · | PoC 3 | gentoo linux (8) | — | |
| 8 | linux | 7 | · | · | · | linux kernel (4) · util-linux (3) | — | ||
| 9 | mediawiki | 7 | · | · | · | ×4.7PoC 1 | mediawiki (7) | — | |
| 10 | redhat | 7 | · | · | · | spice-xpi (2) · enterprise linux desktop (2) · enterprise linux workstation (2) | — | ||
| 11 | red hat inc. | 7 | 1 | · | · | ×4.7 | red hat enterprise linux (7) | — | |
| 12 | bestpractical | 6 | · | · | · | rt (6) | — | ||
| 13 | gnu | 6 | · | · | · | PoC 2 | glibc (6) · eglibc (1) | — | |
| 14 | 6 | 3 | 1 | · | KEV 1PoC 3 | chrome (5) · android (1) | — | ||
| 15 | broadcom | 5 | 2 | · | · | total defense (3) · output management web viewer (1) · siteminder (1) | — | ||
| 16 | 7t | 4 | 4 | · | · | NEWPoC 4 | igss (4) | — | |
| 17 | mark pilgrim | 4 | · | · | · | NEWPoC 3 | feedparser (4) | — | |
| 18 | mono | 4 | · | · | · | NEW×4.0 | mono (4) | — | |
| 19 | pypi | 4 | · | · | · | PoC 3 | feedparser (4) | — | |
| 20 | realnetworks | 4 | 4 | · | · | PoC 1 | helix mobile server (2) · helix server (2) · realplayer (2) | — | |
| 21 | aphpkb | 3 | · | · | · | NEWPoC 2 | aphpkb (3) | — | |
| 22 | horde | 3 | · | · | · | ×3.0 | groupware (2) · dynamic imp (1) · gollem (1) | — | |
| 23 | icanlocalize | 3 | · | · | · | NEW | translation management (3) | — | |
| 24 | opensuse | 3 | · | 1 | · | KEV 1PoC 1 | opensuse (3) | — | |
| 25 | suse | 3 | · | 1 | · | KEV 1PoC 1 | linux enterprise desktop (2) · linux enterprise server (2) | — | |
| 26 | wireshark | 3 | 1 | · | · | PoC 1 | wireshark (3) | — | |
| 27 | apache | 2 | · | · | · | tomcat (2) | — | ||
| 28 | apple | 2 | · | · | · | iphone os (1) · webkit (1) | — | ||
| 29 | baconmap | 2 | · | · | · | NEWPoC 2 | baconmap (2) | — | |
| 30 | canonical | 2 | · | · | · | PoC 1 | ubuntu linux (2) | — | |
| 31 | cisco | 2 | 1 | · | · | ios (1) · secure access control system (1) | — | ||
| 32 | debian | 2 | · | · | · | PoC 1 | debian linux (2) | — | |
| 33 | digium | 2 | 1 | · | · | asterisk (2) | — | ||
| 34 | emc | 2 | · | · | · | networker (1) · rsa adaptive authentication on-premise (1) | — | ||
| 35 | enanocms | 2 | · | · | · | NEWPoC 2 | enano cms (2) | — | |
| 36 | joomlaseller | 2 | · | · | · | NEWPoC 2 | com jscalendar (2) | — | |
| 37 | kde | 2 | · | · | · | kde sc (2) | — | ||
| 38 | maven | 2 | · | · | · | org.apache.tomcat:tomcat (2) | — | ||
| 39 | mozilla | 2 | 1 | · | · | firefox (2) · seamonkey (1) | — | ||
| 40 | ncpfs | 2 | · | · | · | NEW | ncpfs (2) | — | |
| 41 | netgear | 2 | · | · | · | prosafe wnap210 firmware (2) · prosafe wnap210 (2) | — | ||
| 42 | phpwebscripts | 2 | · | · | · | NEWPoC 1 | easy banner free (2) | — | |
| 43 | qooxdoo | 2 | · | · | · | NEWPoC 2 | qooxdoo (2) | — | |
| 44 | realflex | 2 | 2 | · | · | NEWPoC 2 | realwin (2) | — | |
| 45 | roundcube | 2 | · | · | · | webmail (2) | — | ||
| 46 | the centos project | 2 | 1 | · | · | centos (2) | — | ||
| 47 | tincan | 2 | · | · | · | NEWPoC 1 | phplist (2) | — | |
| 48 | vmware | 2 | · | · | · | open-vm-tools (1) · vix api (1) · workstation (1) | — | ||
| 49 | сообщество свободного программного обеспечения | 2 | · | · | · | PoC 1 | debian gnu/linux (1) · perl (1) | — | |
| 50 | adobe | 1 | · | 1 | · | KEV 1PoC 1 | acrobat (1) · acrobat reader (1) · adobe air (1) | — |