month report
September 2013
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
September 2013 closed with 475 published CVEs — -27.5% YoY . 91 criticals, cisco led volume, mostly via unified computing system. Biggest breakout: apple at ×27.0 their 12-month median. Top weakness class — CWE-119 (120 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
475
— MoM-27.5% YoY
Severity mix
91 / 56
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
3.2%
15 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
4558.4
n=15
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
3731
n=2
Weakness × Vendor
What's spreading where in September 2013
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
119Memory Buffer Bounds20Improper Input Validation264CWE-26479XSS200Information Exposure399CWE-399310CWE-310255CWE-255287Improper Authentication94Code Injectioncisco9225732324apple2061543microsoft35412221ibm234412221redhat4242131mozilla1022113linux84121open-xchange11421312adobe121pypi1151112hp2112trivantis214
Breakout vendors
CVE count ≥3× their own 12-period median.
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #8open-xchange17 CVE
- #12trivantis10 CVE
- #20dahuasecurity5 CVE
- #31graphite project3 CVE
- #32libtiff3 CVE
- #33sophos3 CVE
- #34supermicro3 CVE
- #37click2sell2 CVE
- #42gomlab2 CVE
- #45indianic2 CVE
Top vendors
Ranked by distinct CVE count this period.
- 62 CVE6 critCVSS 6.2×5.2PoC 1unified computing system (17) · ios (10) · ios xe (4)
- 54 CVE2 critCVSS 5.8×27.0iphone os (44) · mac os x (11) · itunes (8)
- 48 CVE30 critCVSS 8.0×5.3KEV 1PoC 2word (13) · word viewer (11) · internet explorer (11)
- 24 CVE2 critCVSS 4.9rational requirements composer (4) · spss analytical decision management (4) · data studio web console (3)
- 22 CVE1 critCVSS 4.5PoC 5libvirt (10) · openstack (3) · enterprise linux (3)
- 19 CVE9 critCVSS 7.7firefox (19) · seamonkey (16) · thunderbird (15)
- 17 CVECVSS 4.9PoC 1linux kernel (17)
- 17 CVECVSS 4.4NEWPoC 3open-xchange server (11) · open-xchange appsuite (10)
- 15 CVE15 critCVSS 10.0acrobat reader (8) · acrobat (8) · air sdk (4)
- 14 CVECVSS 4.0×4.7PoC 1nova (3) · ansible (2) · cinder (2)
- 12 CVE4 critCVSS 5.9KEV 1PoC 1procurve manager (5) · identity driven manager (4) · icewall sso agent option (4)
- 10 CVE1 critCVSS 6.2NEWcoursemill learning management system (10)
- 9 CVE8 critCVSS 9.7×4.5cloudportal services manager (8) · xenclient xt (1)
- 7 CVECVSS 5.4ubuntu linux (7)
- 7 CVE1 critCVSS 6.0org.apache.struts:struts2-core (2) · org.owasp.esapi:esapi (2) · org.apache.struts:struts2-rest-plugin (1)
- 7 CVECVSS 4.5cinder (2) · compute (2) · keystone (2)
- 6 CVECVSS 5.4PoC 1debian linux (4) · phpbb3 (1) · txt2man (1)
- 6 CVECVSS 4.4PoC 1wireshark (6)
- 6 CVECVSS 5.7×3.0PoC 1debian gnu/linux (4) · linux (2)
- 5 CVE3 critCVSS 9.0NEWdvr0404hd-a (5) · dvr0404hd-l (5) · dvr0404hd-s (5)
- 5 CVECVSS 4.9PoC 1gentoo linux (5)
- 5 CVECVSS 5.3Nuclei 5PoC 3wordpress (5)
- 4 CVECVSS 5.3eucalyptus (3) · eustore (1)
- 4 CVECVSS 5.1×4.0freebsd (4)
- 4 CVECVSS 6.3PoC 1moodle (4)
- 4 CVECVSS 4.0opensuse (4)
- 4 CVECVSS 6.8red hat enterprise linux (4)
- 3 CVE1 critCVSS 6.4struts (2) · subversion (1)
- 3 CVECVSS 7.8cisco ios (3)
- 3 CVECVSS 5.5fedora (2) · 389 directory server (1)
- 3 CVECVSS 6.0NEWPoC 1graphite (3)
- 3 CVECVSS 6.8NEW×3.0libtiff (3)
- 3 CVE2 critCVSS 9.1NEWPoC 1unified threat management software (1) · web appliance (1) · web appliance firmware (1)
- 3 CVE3 critCVSS 10.0NEWh8dcl-6f (3) · h8dcl-if (3) · h8dct-hibqf (3)
- 3 CVE1 critCVSS 7.1esx (3) · esxi (3)
- 2 CVE1 critCVSS 7.9struts (2)
- 2 CVECVSS 5.5NEWclick2sell suite module (2)
- 2 CVECVSS 5.0asterisk (2) · certified asterisk (2) · asterisk digiumphones (1)
- 2 CVECVSS 5.0django (2)
- 2 CVECVSS 6.3dwl-2100ap firmware (1) · des-3810 (1) · des-3810 firmware (1)
- 2 CVECVSS 5.9rsa archer egrc (2)
- 2 CVE1 critCVSS 7.2NEWPoC 1gom player (2)
- 2 CVECVSS 6.9android (2)
- 2 CVE1 critCVSS 7.9ibm call center for commerce (2)
- 2 CVECVSS 7.2NEWNuclei 2PoC 2testimonial plugin (2)
- 2 CVECVSS 5.0NEWive os (1) · junos pulse access control service (1) · junos pulse secure access service (1)
- 2 CVECVSS 6.8PoC 1libmodplug (2)
- 2 CVECVSS 6.9NEWdefy xt (2)
- 2 CVE1 critCVSS 7.9mysql enterprise monitor (2) · oracle flexcube private banking (2) · webcenter sites (2)
- 2 CVECVSS 4.2NEWenterprise security api (2)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | cisco | 62 | 6 | · | · | ×5.2PoC 1 | unified computing system (17) · ios (10) · ios xe (4) | — | |
| 2 | apple | 54 | 2 | · | · | ×27.0 | iphone os (44) · mac os x (11) · itunes (8) | — | |
| 3 | microsoft | 48 | 30 | 1 | · | ×5.3KEV 1PoC 2 | word (13) · word viewer (11) · internet explorer (11) | — | |
| 4 | ibm | 24 | 2 | · | · | rational requirements composer (4) · spss analytical decision management (4) · data studio web console (3) | — | ||
| 5 | redhat | 22 | 1 | · | · | PoC 5 | libvirt (10) · openstack (3) · enterprise linux (3) | — | |
| 6 | mozilla | 19 | 9 | · | · | firefox (19) · seamonkey (16) · thunderbird (15) | — | ||
| 7 | linux | 17 | · | · | · | PoC 1 | linux kernel (17) | — | |
| 8 | open-xchange | 17 | · | · | · | NEWPoC 3 | open-xchange server (11) · open-xchange appsuite (10) | — | |
| 9 | adobe | 15 | 15 | · | · | acrobat reader (8) · acrobat (8) · air sdk (4) | — | ||
| 10 | pypi | 14 | · | · | · | ×4.7PoC 1 | nova (3) · ansible (2) · cinder (2) | — | |
| 11 | hp | 12 | 4 | 1 | · | KEV 1PoC 1 | procurve manager (5) · identity driven manager (4) · icewall sso agent option (4) | — | |
| 12 | trivantis | 10 | 1 | · | · | NEW | coursemill learning management system (10) | — | |
| 13 | citrix | 9 | 8 | · | · | ×4.5 | cloudportal services manager (8) · xenclient xt (1) | — | |
| 14 | canonical | 7 | · | · | · | ubuntu linux (7) | — | ||
| 15 | maven | 7 | 1 | · | · | org.apache.struts:struts2-core (2) · org.owasp.esapi:esapi (2) · org.apache.struts:struts2-rest-plugin (1) | — | ||
| 16 | openstack | 7 | · | · | · | cinder (2) · compute (2) · keystone (2) | — | ||
| 17 | debian | 6 | · | · | · | PoC 1 | debian linux (4) · phpbb3 (1) · txt2man (1) | — | |
| 18 | wireshark | 6 | · | · | · | PoC 1 | wireshark (6) | — | |
| 19 | сообщество свободного программного обеспечения | 6 | · | · | · | ×3.0PoC 1 | debian gnu/linux (4) · linux (2) | — | |
| 20 | dahuasecurity | 5 | 3 | · | · | NEW | dvr0404hd-a (5) · dvr0404hd-l (5) · dvr0404hd-s (5) | — | |
| 21 | gentoo foundation inc. | 5 | · | · | · | PoC 1 | gentoo linux (5) | — | |
| 22 | wordpress | 5 | · | · | 5 | Nuclei 5PoC 3 | wordpress (5) | — | |
| 23 | eucalyptus | 4 | · | · | · | eucalyptus (3) · eustore (1) | — | ||
| 24 | freebsd | 4 | · | · | · | ×4.0 | freebsd (4) | — | |
| 25 | moodle | 4 | · | · | · | PoC 1 | moodle (4) | — | |
| 26 | opensuse | 4 | · | · | · | opensuse (4) | — | ||
| 27 | red hat inc. | 4 | · | · | · | red hat enterprise linux (4) | — | ||
| 28 | apache | 3 | 1 | · | · | struts (2) · subversion (1) | — | ||
| 29 | cisco systems inc. | 3 | · | · | · | cisco ios (3) | — | ||
| 30 | fedoraproject | 3 | · | · | · | fedora (2) · 389 directory server (1) | — | ||
| 31 | graphite project | 3 | · | · | · | NEWPoC 1 | graphite (3) | — | |
| 32 | libtiff | 3 | · | · | · | NEW×3.0 | libtiff (3) | — | |
| 33 | sophos | 3 | 2 | · | · | NEWPoC 1 | unified threat management software (1) · web appliance (1) · web appliance firmware (1) | — | |
| 34 | supermicro | 3 | 3 | · | · | NEW | h8dcl-6f (3) · h8dcl-if (3) · h8dct-hibqf (3) | — | |
| 35 | vmware | 3 | 1 | · | · | esx (3) · esxi (3) | — | ||
| 36 | apache software foundation | 2 | 1 | · | · | struts (2) | — | ||
| 37 | click2sell | 2 | · | · | · | NEW | click2sell suite module (2) | — | |
| 38 | digium | 2 | · | · | · | asterisk (2) · certified asterisk (2) · asterisk digiumphones (1) | — | ||
| 39 | djangoproject | 2 | · | · | · | django (2) | — | ||
| 40 | dlink | 2 | · | · | · | dwl-2100ap firmware (1) · des-3810 (1) · des-3810 firmware (1) | — | ||
| 41 | emc | 2 | · | · | · | rsa archer egrc (2) | — | ||
| 42 | gomlab | 2 | 1 | · | · | NEWPoC 1 | gom player (2) | — | |
| 43 | 2 | · | · | · | android (2) | — | |||
| 44 | ibm corp. | 2 | 1 | · | · | ibm call center for commerce (2) | — | ||
| 45 | indianic | 2 | · | · | 2 | NEWNuclei 2PoC 2 | testimonial plugin (2) | — | |
| 46 | juniper | 2 | · | · | · | NEW | ive os (1) · junos pulse access control service (1) · junos pulse secure access service (1) | — | |
| 47 | konstanty bialkowski | 2 | · | · | · | PoC 1 | libmodplug (2) | — | |
| 48 | motorola | 2 | · | · | · | NEW | defy xt (2) | — | |
| 49 | oracle corp. | 2 | 1 | · | · | mysql enterprise monitor (2) · oracle flexcube private banking (2) · webcenter sites (2) | — | ||
| 50 | owasp | 2 | · | · | · | NEW | enterprise security api (2) | — |