month report
January 2014
Data as of Jun 11, 2026, 06:04 UTCSnapshot v1 Sources CVEList V5+NVD+GHSA+CSAF+FSTEC BDU+CISA KEV+EPSS+Nuclei templates Methodology →
January 2014 closed with 579 published CVEs. 63 criticals, oracle led volume, mostly via jre. Top weakness class — CWE-79 (80 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
579
— MoM— YoY
Severity mix
63 / 82
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
4.1%
24 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
4432.0
n=24
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
2969
n=1
Detection gap
KEV pressure, no Nuclei coverage
January 2014 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 1adobe7 CVE
Weakness × Vendor
What's spreading where in January 2014
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
Most discussed CVEs — January 2014
No CVE mentions in the news this month yet.
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #12mariadb10 CVE
- #21xen7 CVE
- #23juniper6 CVE
- #27conceptronic5 CVE
- #28fatfreecrm5 CVE
- #31open-xchange5 CVE
- #32checkpoint4 CVE
- #35libreswan4 CVE
- #37memcached4 CVE
- #39belkin3 CVE
Top vendors
Ranked by distinct CVE count this period.
- 121 CVE10 critCVSS 5.3PoC 2jre (36) · jdk (31) · mysql (18)
- 38 CVE4 critCVSS 6.5secure access control system (8) · context directory agent (4) · mediasense (3)
- 34 CVECVSS 4.8PoC 2enterprise linux desktop (11) · enterprise linux workstation (11) · enterprise linux server (11)
- 22 CVECVSS 4.8PoC 2debian linux (19) · axiom (1) · localepurge (1)
- 21 CVE1 critCVSS 5.2qradar security information and event manager (4) · websphere application server (3) · lotus quickr for domino (2)
- 16 CVE9 critCVSS 7.2PoC 2storage data protector (9) · jdk (6) · jre (6)
- 15 CVECVSS 3.9PoC 2ubuntu linux (15) · ubuntu (1)
- 15 CVE1 critCVSS 7.1PoC 1chrome (11) · picasa (4)
- 14 CVE2 critCVSS 4.5PoC 1gentoo linux (14)
- 14 CVECVSS 4.2linux kernel (14)
- 13 CVECVSS 5.8PoC 2opensuse (13)
- 10 CVECVSS 4.0NEWmariadb (10)
- 10 CVECVSS 4.5Nuclei 10PoC 2wordpress (10)
- 9 CVECVSS 3.8PoC 1nova (2) · httplib2 (1) · apache-libcloud (1)
- 9 CVECVSS 6.0PoC 2debian gnu/linux (8) · libxml2 (1) · linux (1)
- 8 CVE1 critCVSS 6.1PoC 3org.springframework:spring-oxm (2) · com.smartbear.soapui:soapui (1) · com.jamonapi:jamon (1)
- 8 CVECVSS 4.6PoC 5fat_free_crm (5) · paratrooper-newrelic (1) · paratrooper-pingdom (1)
- 7 CVE6 critCVSS 9.7KEV 1acrobat (4) · adobe air sdk (2) · acrobat reader (2)
- 7 CVECVSS 3.9PoC 2cloudstack (2) · ofbiz (1) · santuario xml security for java (1)
- 7 CVECVSS 4.3sunos (7)
- 7 CVECVSS 5.6NEWxen (7)
- 6 CVE4 critCVSS 8.5atmail (6)
- 6 CVECVSS 7.2NEWjunos (6) · srx240 (2) · srx100 (2)
- 6 CVE3 critCVSS 8.3PoC 1word (3) · office compatibility pack (3) · word viewer (2)
- 6 CVECVSS 4.8spring framework (3) · esx (2) · esxi (2)
- 5 CVECVSS 6.4PoC 1iphone os (2) · mac os x (2) · watchos (1)
- 5 CVECVSS 5.8NEWPoC 3c54apm (4) · c54apm firmware (4) · cipcamptiwl (1)
- 5 CVECVSS 5.7NEWPoC 2fat free crm (5)
- 5 CVECVSS 4.8PoC 1websphere application server (3) · aix (1) · tivoli business service manager (1)
- 5 CVECVSS 3.5PoC 1suse linux enterprise (4) · opensuse (1)
- 5 CVECVSS 4.2NEWopen-xchange appsuite (5)
- 4 CVECVSS 4.7NEWPoC 1security gateway (1) · session authentication agent (1) · endpoint security mi server r73 (1)
- 4 CVE1 critCVSS 7.6powerconnect 5324 (3) · powerconnect 3524p (3) · powerconnect 3348 (3)
- 4 CVECVSS 4.6PoC 1drupal (4)
- 4 CVE1 critCVSS 6.1NEWPoC 1libreswan (4)
- 4 CVECVSS 4.9PoC 2vulnerability manager (3) · superscan (1)
- 4 CVECVSS 2.5NEWPoC 1memcached (4)
- 4 CVECVSS 4.5nova (1) · havana (1) · python-keystoneclient (1)
- 3 CVECVSS 4.3NEWf5d8236-4 (1) · n300 (1) · n900 (1)
- 3 CVECVSS 5.2PoC 1fedora (3)
- 3 CVECVSS 6.3NEWicinga (3)
- 3 CVECVSS 6.1NEWmariadb (3)
- 3 CVECVSS 5.4moodle (3)
- 3 CVECVSS 5.6NEWopsview (3)
- 3 CVE1 critCVSS 6.1ec-cube/ec-cube (1) · typo3/cms-core (1) · civicrm/civicrm-core (1)
- 3 CVECVSS 4.6NEWPoC 1projectforge (3)
- 3 CVECVSS 4.1NEWPoC 1python (1) · pyxdg (1) · rply (1)
- 3 CVECVSS 6.4endpoint protection (3)
- 3 CVE1 critCVSS 8.5NEWPoC 1n8800 nas server (3) · n8800 nas server firmware (3)
- 3 CVECVSS 5.4NEWNuclei 3forumpress (3)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | oracle | 121 | 10 | · | · | PoC 2 | jre (36) · jdk (31) · mysql (18) | — | |
| 2 | cisco | 38 | 4 | · | · | secure access control system (8) · context directory agent (4) · mediasense (3) | — | ||
| 3 | redhat | 34 | · | · | · | PoC 2 | enterprise linux desktop (11) · enterprise linux workstation (11) · enterprise linux server (11) | — | |
| 4 | debian | 22 | · | · | · | PoC 2 | debian linux (19) · axiom (1) · localepurge (1) | — | |
| 5 | ibm | 21 | 1 | · | · | qradar security information and event manager (4) · websphere application server (3) · lotus quickr for domino (2) | — | ||
| 6 | hp | 16 | 9 | · | · | PoC 2 | storage data protector (9) · jdk (6) · jre (6) | — | |
| 7 | canonical | 15 | · | · | · | PoC 2 | ubuntu linux (15) · ubuntu (1) | — | |
| 8 | 15 | 1 | · | · | PoC 1 | chrome (11) · picasa (4) | — | ||
| 9 | gentoo foundation inc. | 14 | 2 | · | · | PoC 1 | gentoo linux (14) | — | |
| 10 | linux | 14 | · | · | · | linux kernel (14) | — | ||
| 11 | opensuse | 13 | · | · | · | PoC 2 | opensuse (13) | — | |
| 12 | mariadb | 10 | · | · | · | NEW | mariadb (10) | — | |
| 13 | wordpress | 10 | · | · | 10 | Nuclei 10PoC 2 | wordpress (10) | — | |
| 14 | pypi | 9 | · | · | · | PoC 1 | nova (2) · httplib2 (1) · apache-libcloud (1) | — | |
| 15 | сообщество свободного программного обеспечения | 9 | · | · | · | PoC 2 | debian gnu/linux (8) · libxml2 (1) · linux (1) | — | |
| 16 | maven | 8 | 1 | · | · | PoC 3 | org.springframework:spring-oxm (2) · com.smartbear.soapui:soapui (1) · com.jamonapi:jamon (1) | — | |
| 17 | rubygems | 8 | · | · | · | PoC 5 | fat_free_crm (5) · paratrooper-newrelic (1) · paratrooper-pingdom (1) | — | |
| 18 | adobe | 7 | 6 | 1 | · | KEV 1 | acrobat (4) · adobe air sdk (2) · acrobat reader (2) | — | |
| 19 | apache | 7 | · | · | · | PoC 2 | cloudstack (2) · ofbiz (1) · santuario xml security for java (1) | — | |
| 20 | sun | 7 | · | · | · | sunos (7) | — | ||
| 21 | xen | 7 | · | · | · | NEW | xen (7) | — | |
| 22 | atmail | 6 | 4 | · | · | atmail (6) | — | ||
| 23 | juniper | 6 | · | · | · | NEW | junos (6) · srx240 (2) · srx100 (2) | — | |
| 24 | microsoft | 6 | 3 | · | · | PoC 1 | word (3) · office compatibility pack (3) · word viewer (2) | — | |
| 25 | vmware | 6 | · | · | · | spring framework (3) · esx (2) · esxi (2) | — | ||
| 26 | apple | 5 | · | · | · | PoC 1 | iphone os (2) · mac os x (2) · watchos (1) | — | |
| 27 | conceptronic | 5 | · | · | · | NEWPoC 3 | c54apm (4) · c54apm firmware (4) · cipcamptiwl (1) | — | |
| 28 | fatfreecrm | 5 | · | · | · | NEWPoC 2 | fat free crm (5) | — | |
| 29 | ibm corp. | 5 | · | · | · | PoC 1 | websphere application server (3) · aix (1) · tivoli business service manager (1) | — | |
| 30 | novell inc. | 5 | · | · | · | PoC 1 | suse linux enterprise (4) · opensuse (1) | — | |
| 31 | open-xchange | 5 | · | · | · | NEW | open-xchange appsuite (5) | — | |
| 32 | checkpoint | 4 | · | · | · | NEWPoC 1 | security gateway (1) · session authentication agent (1) · endpoint security mi server r73 (1) | — | |
| 33 | dell | 4 | 1 | · | · | powerconnect 5324 (3) · powerconnect 3524p (3) · powerconnect 3348 (3) | — | ||
| 34 | drupal | 4 | · | · | · | PoC 1 | drupal (4) | — | |
| 35 | libreswan | 4 | 1 | · | · | NEWPoC 1 | libreswan (4) | — | |
| 36 | mcafee | 4 | · | · | · | PoC 2 | vulnerability manager (3) · superscan (1) | — | |
| 37 | memcached | 4 | · | · | · | NEWPoC 1 | memcached (4) | — | |
| 38 | openstack | 4 | · | · | · | nova (1) · havana (1) · python-keystoneclient (1) | — | ||
| 39 | belkin | 3 | · | · | · | NEW | f5d8236-4 (1) · n300 (1) · n900 (1) | — | |
| 40 | fedoraproject | 3 | · | · | · | PoC 1 | fedora (3) | — | |
| 41 | icinga | 3 | · | · | · | NEW | icinga (3) | — | |
| 42 | mariadb foundation | 3 | · | · | · | NEW | mariadb (3) | — | |
| 43 | moodle | 3 | · | · | · | moodle (3) | — | ||
| 44 | opsview | 3 | · | · | · | NEW | opsview (3) | — | |
| 45 | packagist | 3 | 1 | · | · | ec-cube/ec-cube (1) · typo3/cms-core (1) · civicrm/civicrm-core (1) | — | ||
| 46 | projectforge | 3 | · | · | · | NEWPoC 1 | projectforge (3) | — | |
| 47 | python | 3 | · | · | · | NEWPoC 1 | python (1) · pyxdg (1) · rply (1) | — | |
| 48 | symantec | 3 | · | · | · | endpoint protection (3) | — | ||
| 49 | thecus | 3 | 1 | · | · | NEWPoC 1 | n8800 nas server (3) · n8800 nas server firmware (3) | — | |
| 50 | vasthtml | 3 | · | · | 3 | NEWNuclei 3 | forumpress (3) | — |
Sectors
Solution categories ranked by distinct CVE count this period.
- Databases129 CVE26 crit6 vendorsCVSS 5.3jre (36) · mysql (33) · jdk (31)
- Operating Systems106 CVE17 crit26 vendorsCVSS 8.3debian linux (19) · ubuntu linux (15) · gentoo linux (14)
- Enterprise Software72 CVE15 crit20 vendorsCVSS 8.7storage data protector (9) · jdk (6) · jre (6)
- 51 crit20 vendorsCVSS 7.1secure access control system (8) · junos (6) · c54apm (4)
- Web & CMS Plugins67 CVE2 crit37 vendorsCVSS 7.2wordpress (10) · drupal (4) · moodle (3)
- OSS Libraries56 CVE6 crit27 vendorsCVSS 6.1graphviz (2) · openssl (2) · pixman (2)
- Security Products27 CVE5 crit12 vendorsCVSS 7.0endpoint protection (3) · vulnerability manager (3) · check point management server (1)
- Mobile Apps21 CVE1 crit3 vendorsCVSS 6.9chrome (11) · picasa (4) · mt882 (1)
- Cloud & SaaS20 CVE7 vendorsCVSS 5.6xen (7)
- Communications19 CVE5 crit9 vendorsCVSS 10.0atmail (6) · open-xchange appsuite (5) · flite (1)
- Consumer Software16 CVE11 crit3 KEV11 vendorsCVSS 9.7acrobat (4) · acrobat reader (2) · adobe air (2)
- Hardware Firmware15 CVE7 crit9 vendorsCVSS 8.9n8800 nas server (3) · n8800 nas server firmware (3) · blackarmor nas 220 (2)
- ICS / OT / IoT12 CVE10 crit9 vendorsCVSS 10.0integraxor (2) · intelligent platforms proficy hmi\%2fscada cimplicity (2) · intelligent platforms proficy hmi\/scada cimplicity (2)
- DevTools & CI5 CVE2 crit6 vendorsCVSS 7.0soapui (2) · nexus (1) · puppet (1)
- Unclassified25 CVE2 crit24 vendorsCVSS 6.3command school student management system (2) · netbill (2) · access risk management suite (1)
| Sector | CVEs | Crit | KEV | Vendors | Products | Avg CVSS | Top products |
|---|---|---|---|---|---|---|---|
| Databases▸ 2 | 129 | 26 | · | 6 | 30 | 5.3 | jre (36) · mysql (33) · jdk (31) |
| Operating Systems▸ 3 | 106 | 17 | · | 26 | 69 | 8.3 | debian linux (19) · ubuntu linux (15) · gentoo linux (14) |
| Enterprise Software▸ 5 | 72 | 15 | · | 20 | 81 | 8.7 | storage data protector (9) · jdk (6) · jre (6) |
| Networking Infrastructure▸ 5 | 68 | 51 | · | 20 | 147 | 7.1 | secure access control system (8) · junos (6) · c54apm (4) |
| Web & CMS Plugins▸ 6 | 67 | 2 | · | 37 | 40 | 7.2 | wordpress (10) · drupal (4) · moodle (3) |
| OSS Libraries▸ 6 | 56 | 6 | · | 27 | 48 | 6.1 | graphviz (2) · openssl (2) · pixman (2) |
| Security Products▸ 5 | 27 | 5 | · | 12 | 32 | 7.0 | endpoint protection (3) · vulnerability manager (3) · check point management server (1) |
| Mobile Apps▸ 2 | 21 | 1 | · | 3 | 12 | 6.9 | chrome (11) · picasa (4) · mt882 (1) |
| Cloud & SaaS▸ 3 | 20 | · | · | 7 | 16 | 5.6 | xen (7) |
| Communications▸ 4 | 19 | 5 | · | 9 | 10 | 10.0 | atmail (6) · open-xchange appsuite (5) · flite (1) |
| Consumer Software▸ 4 | 16 | 11 | 3 | 11 | 17 | 9.7 | acrobat (4) · acrobat reader (2) · adobe air (2) |
| Hardware Firmware▸ 4 | 15 | 7 | · | 9 | 15 | 8.9 | n8800 nas server (3) · n8800 nas server firmware (3) · blackarmor nas 220 (2) |
| ICS / OT / IoT▸ 3 | 12 | 10 | · | 9 | 22 | 10.0 | integraxor (2) · intelligent platforms proficy hmi\%2fscada cimplicity (2) · intelligent platforms proficy hmi\/scada cimplicity (2) |
| DevTools & CI▸ 3 | 5 | 2 | · | 6 | 5 | 7.0 | soapui (2) · nexus (1) · puppet (1) |
| Unclassified | 25 | 2 | · | 24 | 29 | 6.3 | command school student management system (2) · netbill (2) · access risk management suite (1) |
Weakness × Sector
Which weaknesses hit which solution categories in January 2014
Cells shaded by share of the sector's hottest weakness. Click a row to open the sector history.
79XSS264CWE-26420Improper Input Validation119Memory Buffer Bounds89SQL Injection200Information Exposure352CSRF22Path Traversal310CWE-310399CWE-399OSS Libraries4114638222Operating Systems1111710153114Enterprise Software85571045141Networking Infrastructure1312192111111Web & CMS Plugins3110193351Consumer Software22115111331Databases2134Security Products9332131Cloud & SaaS52212Communications711111