month report
December 2012
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
December 2012 closed with 270 published CVEs — -22.2% YoY . 42 criticals, ibm led volume, mostly via security appscan. Biggest breakout: samsung at ×5.0 their 12-month median. Top weakness class — CWE-79 (34 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
270
— MoM-22.2% YoY
Severity mix
42 / 29
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
2.6%
7 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
4825.4
n=7
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
3808
n=2
Detection gap
KEV pressure, no Nuclei coverage
December 2012 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 2microsoft11 CVE
Weakness × Vendor
What's spreading where in December 2012
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
Breakout vendors
CVE count ≥3× their own 12-period median.
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #4xen11 CVE
- #11microfocus7 CVE
- #14layton technology5 CVE
- #15mariadb5 CVE
- #16owncloud5 CVE
- #20openconstructor project4 CVE
- #21openstack4 CVE
- #25carlos carvalhar3 CVE
- #28forescout3 CVE
- #29huawei3 CVE
Top vendors
Ranked by distinct CVE count this period.
- 18 CVE2 critCVSS 5.7×4.5security appscan (2) · rational clearquest (2) · rational policy tester (2)
- 11 CVE7 critCVSS 8.8KEV 2PoC 1internet explorer (4) · windows server 2008 (4) · windows 7 (3)
- 11 CVECVSS 5.0PoC 3wireshark (11)
- 11 CVECVSS 4.1NEWPoC 1xen (11)
- 10 CVE8 critCVSS 9.1chrome (9) · android (1) · chrome os (1)
- 9 CVE8 critCVSS 9.4×3.0opensuse (9)
- 9 CVE2 critCVSS 6.9PoC 3mysql (6) · glassfish web space server10.0 (1) · hyperion financial management (1)
- 8 CVE6 critCVSS 9.3air (3) · air sdk (3) · flash player (3)
- 7 CVECVSS 3.9PoC 1linux kernel (7)
- 7 CVECVSS 5.0org.springframework.security:spring-security-core (3) · org.apache.tomcat:tomcat (2) · org.jboss.ironjacamar:ironjacamar-jdbc (1)
- 7 CVE2 critCVSS 6.7NEWPoC 1edirectory (4) · privileged user manager (3)
- 7 CVECVSS 4.2springsource spring security (3) · vcenter server appliance (2) · hyperic hq (1)
- 6 CVE2 critCVSS 5.2openvms (2) · color laserjet cm60xx (1) · color laserjet cp3525 (1)
- 5 CVECVSS 5.2NEWhelpbox (5)
- 5 CVECVSS 5.6NEWPoC 3mariadb (5)
- 5 CVECVSS 5.4NEWowncloud server (5) · owncloud (4)
- 5 CVE1 critCVSS 5.7×5.0kies air (2) · samsungdive (2) · galaxy s2 (1)
- 4 CVE1 critCVSS 7.2PoC 1ubuntu linux (4)
- 4 CVECVSS 5.9PoC 27500 wireless lan controller (3) · 8500 wireless lan controller (3) · wireless lan controller software (3)
- 4 CVECVSS 4.5NEWPoC 1openconstructor (4)
- 4 CVECVSS 4.3NEW×4.0folsom (3) · essex (1) · grizzly (1)
- 4 CVECVSS 6.7endpoint protection (1) · enterprise security manager (1) · messaging gateway (1)
- 3 CVECVSS 3.7tomcat (3)
- 3 CVE3 critCVSS 10.0×3.0identityminder (2) · xcom data transport (1)
- 3 CVECVSS 6.2NEWtime spent (3)
- 3 CVE1 critCVSS 5.8xendesktop (1) · xenapp (1) · xenserver (1)
- 3 CVECVSS 5.4rsa netwitness informer (2) · data protection advisor (1)
- 3 CVECVSS 4.8NEWNuclei 1counteract (3)
- 3 CVECVSS 5.2NEWe585 (3) · e585u-82 (3)
- 3 CVECVSS 6.1PoC 2symfony/symfony (2) · symfony/security (1) · concrete5/concrete5 (1)
- 3 CVECVSS 4.6keystone (2) · nova (1)
- 3 CVECVSS 6.1NEWPoC 3symfony (3)
- 3 CVECVSS 3.7rox ii os (1) · automation license manager (1) · processsuite (1)
- 2 CVE1 critCVSS 8.9NEWeos-box (2)
- 2 CVE1 critCVSS 8.9NEWeos-box photovoltaic monitoring system (2) · eos-box photovoltaic monitoring system firmware (2)
- 2 CVECVSS 5.2cms made simple (2)
- 2 CVECVSS 3.4NEWom maximenu (2)
- 2 CVECVSS 3.5dcs-932l firmware (1) · dcs-932l (1) · dsl-2730u (1)
- 2 CVECVSS 3.5NEWemail (2)
- 2 CVECVSS 6.3joomla\! (2)
- 2 CVECVSS 4.3access report (2)
- 2 CVECVSS 3.5NEWloctouch (2)
- 2 CVECVSS 3.0PoC 1opensuse (1) · suse linux enterprise (1)
- 2 CVECVSS 5.9perl (2)
- 2 CVE2 critCVSS 9.3realplayer (2) · realplayer sp (2)
- 2 CVECVSS 4.5enterprise linux desktop (1) · enterprise linux eus (1) · enterprise linux server (1)
- 2 CVECVSS 6.3PoC 1centos (2)
- 2 CVECVSS 4.2NEWmailchimp (1) · mandrill (1)
- 2 CVECVSS 5.5NEWNuclei 2welcart plugin (2)
- 1 CVECVSS 4.3NEW1password (1)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | ibm | 18 | 2 | · | · | ×4.5 | security appscan (2) · rational clearquest (2) · rational policy tester (2) | — | |
| 2 | microsoft | 11 | 7 | 2 | · | KEV 2PoC 1 | internet explorer (4) · windows server 2008 (4) · windows 7 (3) | — | |
| 3 | wireshark | 11 | · | · | · | PoC 3 | wireshark (11) | — | |
| 4 | xen | 11 | · | · | · | NEWPoC 1 | xen (11) | — | |
| 5 | 10 | 8 | · | · | chrome (9) · android (1) · chrome os (1) | — | |||
| 6 | opensuse | 9 | 8 | · | · | ×3.0 | opensuse (9) | — | |
| 7 | oracle | 9 | 2 | · | · | PoC 3 | mysql (6) · glassfish web space server10.0 (1) · hyperion financial management (1) | — | |
| 8 | adobe | 8 | 6 | · | · | air (3) · air sdk (3) · flash player (3) | — | ||
| 9 | linux | 7 | · | · | · | PoC 1 | linux kernel (7) | — | |
| 10 | maven | 7 | · | · | · | org.springframework.security:spring-security-core (3) · org.apache.tomcat:tomcat (2) · org.jboss.ironjacamar:ironjacamar-jdbc (1) | — | ||
| 11 | microfocus | 7 | 2 | · | · | NEWPoC 1 | edirectory (4) · privileged user manager (3) | — | |
| 12 | vmware | 7 | · | · | · | springsource spring security (3) · vcenter server appliance (2) · hyperic hq (1) | — | ||
| 13 | hp | 6 | 2 | · | · | openvms (2) · color laserjet cm60xx (1) · color laserjet cp3525 (1) | — | ||
| 14 | layton technology | 5 | · | · | · | NEW | helpbox (5) | — | |
| 15 | mariadb | 5 | · | · | · | NEWPoC 3 | mariadb (5) | — | |
| 16 | owncloud | 5 | · | · | · | NEW | owncloud server (5) · owncloud (4) | — | |
| 17 | samsung | 5 | 1 | · | · | ×5.0 | kies air (2) · samsungdive (2) · galaxy s2 (1) | — | |
| 18 | canonical | 4 | 1 | · | · | PoC 1 | ubuntu linux (4) | — | |
| 19 | cisco | 4 | · | · | · | PoC 2 | 7500 wireless lan controller (3) · 8500 wireless lan controller (3) · wireless lan controller software (3) | — | |
| 20 | openconstructor project | 4 | · | · | · | NEWPoC 1 | openconstructor (4) | — | |
| 21 | openstack | 4 | · | · | · | NEW×4.0 | folsom (3) · essex (1) · grizzly (1) | — | |
| 22 | symantec | 4 | · | · | · | endpoint protection (1) · enterprise security manager (1) · messaging gateway (1) | — | ||
| 23 | apache | 3 | · | · | · | tomcat (3) | — | ||
| 24 | ca | 3 | 3 | · | · | ×3.0 | identityminder (2) · xcom data transport (1) | — | |
| 25 | carlos carvalhar | 3 | · | · | · | NEW | time spent (3) | — | |
| 26 | citrix | 3 | 1 | · | · | xendesktop (1) · xenapp (1) · xenserver (1) | — | ||
| 27 | emc | 3 | · | · | · | rsa netwitness informer (2) · data protection advisor (1) | — | ||
| 28 | forescout | 3 | · | · | 1 | NEWNuclei 1 | counteract (3) | — | |
| 29 | huawei | 3 | · | · | · | NEW | e585 (3) · e585u-82 (3) | — | |
| 30 | packagist | 3 | · | · | · | PoC 2 | symfony/symfony (2) · symfony/security (1) · concrete5/concrete5 (1) | — | |
| 31 | pypi | 3 | · | · | · | keystone (2) · nova (1) | — | ||
| 32 | sensiolabs | 3 | · | · | · | NEWPoC 3 | symfony (3) | — | |
| 33 | siemens | 3 | · | · | · | rox ii os (1) · automation license manager (1) · processsuite (1) | — | ||
| 34 | carlo gavazzi automation | 2 | 1 | · | · | NEW | eos-box (2) | — | |
| 35 | carlosgavazzi | 2 | 1 | · | · | NEW | eos-box photovoltaic monitoring system (2) · eos-box photovoltaic monitoring system firmware (2) | — | |
| 36 | cmsmadesimple | 2 | · | · | · | cms made simple (2) | — | ||
| 37 | daniel honrade | 2 | · | · | · | NEW | om maximenu (2) | — | |
| 38 | dlink | 2 | · | · | · | dcs-932l firmware (1) · dcs-932l (1) · dsl-2730u (1) | — | ||
| 39 | epiqo | 2 | · | · | · | NEW | email (2) | — | |
| 40 | joomla | 2 | · | · | · | joomla\! (2) | — | ||
| 41 | kent-web | 2 | · | · | · | access report (2) | — | ||
| 42 | naver | 2 | · | · | · | NEW | loctouch (2) | — | |
| 43 | novell inc. | 2 | · | · | · | PoC 1 | opensuse (1) · suse linux enterprise (1) | — | |
| 44 | perl | 2 | · | · | · | perl (2) | — | ||
| 45 | realnetworks | 2 | 2 | · | · | realplayer (2) · realplayer sp (2) | — | ||
| 46 | redhat | 2 | · | · | · | enterprise linux desktop (1) · enterprise linux eus (1) · enterprise linux server (1) | — | ||
| 47 | the centos project | 2 | · | · | · | PoC 1 | centos (2) | — | |
| 48 | thinkshout | 2 | · | · | · | NEW | mailchimp (1) · mandrill (1) | — | |
| 49 | welcart | 2 | · | · | 2 | NEWNuclei 2 | welcart plugin (2) | — | |
| 50 | 1password | 1 | · | · | · | NEW | 1password (1) | — |