month report
March 2015
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
March 2015 closed with 457 published CVEs. 59 criticals, microsoft led volume, mostly via windows server 2012. Biggest breakout: php group at ×12.0 their 12-month median. Top weakness class — CWE-79 (63 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
457
— MoM— YoY
Severity mix
59 / 115
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
4.6%
21 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
4017.8
n=21
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
—
n=0
Weakness × Vendor
What's spreading where in March 2015
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
Breakout vendors
CVE count ≥3× their own 12-period median.
- 12.0×php group12 CVE
- 8.7×openssl13 CVE
- 7.0×mybb7 CVE
- 7.0×openssl software foundation7 CVE
- 6.0×schneider-electric6 CVE
- 4.0×aveva4 CVE
- 4.0×adobe systems inc.8 CVE
- 3.3×php13 CVE
- 3.0×apple inc.3 CVE
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #11websense20 CVE
- #26openssl software foundation7 CVE
- #32aveva4 CVE
- #36tcpdump4 CVE
- #37webgateinc4 CVE
- #38wpml4 CVE
- #39ajsquare3 CVE
- #43gaia-gis3 CVE
- #44mageia3 CVE
- #46scadaengine3 CVE
Top vendors
Ranked by distinct CVE count this period.
- 43 CVE20 critCVSS 6.6PoC 2windows server 2012 (21) · windows 8 (20) · windows 7 (20)
- 41 CVE2 critCVSS 6.9ios (15) · ios xe (13) · anyconnect secure mobility client (4)
- 33 CVE2 critCVSS 5.7PoC 5debian linux (32) · cifs-utils (1)
- 33 CVE2 critCVSS 4.6rational quality manager (6) · business process manager (4) · rational team concert (4)
- 32 CVE1 critCVSS 6.3PoC 7ubuntu linux (32)
- 30 CVE2 critCVSS 6.6PoC 1iphone os (22) · tvos (18) · safari (17)
- 24 CVECVSS 6.7chrome (24) · v8 (1)
- 24 CVECVSS 5.6PoC 3opensuse (24)
- 22 CVECVSS 6.6PoC 3enterprise linux server supplementary eus (11) · enterprise linux desktop supplementary (11) · enterprise linux workstation supplementary (11)
- 21 CVE1 critCVSS 5.4PoC 3fedora (21) · 389 directory server (2)
- 20 CVE2 critCVSS 5.2NEWPoC 6v-series appliances (11) · triton ap email (9) · triton ap web (6)
- 17 CVE12 critCVSS 8.1ole point of sale driver (10) · integrated lights-out 2 firmware (2) · integrated lights-out 4 firmware (2)
- 14 CVE1 critCVSS 5.2PoC 3linux kernel (14)
- 13 CVE2 critCVSS 8.0cisco ios (11) · cisco intrusion prevention system (1) · telepresence conductor (1)
- 13 CVECVSS 5.0×8.7openssl (13)
- 13 CVECVSS 6.5×3.3PoC 2php (13)
- 12 CVECVSS 6.4×12.0PoC 1php (12)
- 11 CVE9 critCVSS 9.0PoC 1flash player (11)
- 11 CVECVSS 5.2PoC 3solaris (7) · linux (6) · secure backup (1)
- 9 CVE1 critCVSS 6.2red hat enterprise linux (9)
- 8 CVE8 critCVSS 10.0×4.0flash player (8)
- 8 CVECVSS 6.3PoC 1spcanywhere (5) · spc4000 firmware (1) · simatic cfc (1)
- 7 CVECVSS 5.0PoC 1ubuntu (7)
- 7 CVECVSS 5.5PoC 7rsa certificate manager (3) · rsa registration manager (3) · secure remote services (2)
- 7 CVE1 critCVSS 5.9×7.0mybb (7)
- 7 CVECVSS 4.8NEW×7.0openssl (7)
- 7 CVECVSS 6.1PoC 2django (3) · dulwich (2) · mercurial (1)
- 6 CVECVSS 4.5×6.0wonderware intouch 2014 (4) · pelco ds-nv (1) · device type manager (1)
- 6 CVECVSS 5.0wireshark (6)
- 5 CVECVSS 5.8PoC 3batik (1) · http server (1) · mod-gnutls (1)
- 5 CVECVSS 3.6xen (5)
- 4 CVECVSS 3.1NEW×4.0aveva edge (4)
- 4 CVECVSS 6.1PoC 3org.opencms:opencms-core (1) · org.apache.taglibs:taglibs-standard (1) · org.apache.taglibs:taglibs-standard-impl (1)
- 4 CVECVSS 5.2data loss prevention endpoint (4)
- 4 CVECVSS 5.2PoC 1linux enterprise server (2) · linux enterprise software development kit (1) · linux enterprise workstation extension (1)
- 4 CVECVSS 6.3NEWPoC 4tcpdump (4)
- 4 CVECVSS 7.0NEWPoC 1edvr manager (2) · webeyeaudio (1) · winrds (1)
- 4 CVECVSS 6.4NEWNuclei 4PoC 4wpml (4)
- 3 CVECVSS 4.5NEWPoC 3zeuscart (3)
- 3 CVE1 critCVSS 7.4×3.0os x (2) · ios (1)
- 3 CVECVSS 6.2request tracker (3)
- 3 CVECVSS 4.5PoC 1django (3)
- 3 CVECVSS 6.0NEWfreexl (3)
- 3 CVECVSS 5.0NEWmageia (3)
- 3 CVECVSS 6.7opensuse leap (3)
- 3 CVE2 critCVSS 8.5NEWbacnet opc server (3)
- 3 CVECVSS 6.4NEWPoC 3webshop hun (3)
- 3 CVECVSS 8.5libxfont (3)
- 3 CVECVSS 6.9debian gnu/linux (3) · libzip (1)
- 2 CVECVSS 5.5PoC 2rt-g32 firmware (2)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | microsoft | 43 | 20 | · | · | PoC 2 | windows server 2012 (21) · windows 8 (20) · windows 7 (20) | — | |
| 2 | cisco | 41 | 2 | · | · | ios (15) · ios xe (13) · anyconnect secure mobility client (4) | — | ||
| 3 | debian | 33 | 2 | · | · | PoC 5 | debian linux (32) · cifs-utils (1) | — | |
| 4 | ibm | 33 | 2 | · | · | rational quality manager (6) · business process manager (4) · rational team concert (4) | — | ||
| 5 | canonical | 32 | 1 | · | · | PoC 7 | ubuntu linux (32) | — | |
| 6 | apple | 30 | 2 | · | · | PoC 1 | iphone os (22) · tvos (18) · safari (17) | — | |
| 7 | 24 | · | · | · | chrome (24) · v8 (1) | — | |||
| 8 | opensuse | 24 | · | · | · | PoC 3 | opensuse (24) | — | |
| 9 | redhat | 22 | · | · | · | PoC 3 | enterprise linux server supplementary eus (11) · enterprise linux desktop supplementary (11) · enterprise linux workstation supplementary (11) | — | |
| 10 | fedoraproject | 21 | 1 | · | · | PoC 3 | fedora (21) · 389 directory server (2) | — | |
| 11 | websense | 20 | 2 | · | · | NEWPoC 6 | v-series appliances (11) · triton ap email (9) · triton ap web (6) | — | |
| 12 | hp | 17 | 12 | · | · | ole point of sale driver (10) · integrated lights-out 2 firmware (2) · integrated lights-out 4 firmware (2) | — | ||
| 13 | linux | 14 | 1 | · | · | PoC 3 | linux kernel (14) | — | |
| 14 | cisco systems inc. | 13 | 2 | · | · | cisco ios (11) · cisco intrusion prevention system (1) · telepresence conductor (1) | — | ||
| 15 | openssl | 13 | · | · | · | ×8.7 | openssl (13) | — | |
| 16 | php | 13 | · | · | · | ×3.3PoC 2 | php (13) | — | |
| 17 | php group | 12 | · | · | · | ×12.0PoC 1 | php (12) | — | |
| 18 | adobe | 11 | 9 | · | · | PoC 1 | flash player (11) | — | |
| 19 | oracle | 11 | · | · | · | PoC 3 | solaris (7) · linux (6) · secure backup (1) | — | |
| 20 | red hat inc. | 9 | 1 | · | · | red hat enterprise linux (9) | — | ||
| 21 | adobe systems inc. | 8 | 8 | · | · | ×4.0 | flash player (8) | — | |
| 22 | siemens | 8 | · | · | · | PoC 1 | spcanywhere (5) · spc4000 firmware (1) · simatic cfc (1) | — | |
| 23 | canonical ltd. | 7 | · | · | · | PoC 1 | ubuntu (7) | — | |
| 24 | emc | 7 | · | · | · | PoC 7 | rsa certificate manager (3) · rsa registration manager (3) · secure remote services (2) | — | |
| 25 | mybb | 7 | 1 | · | · | ×7.0 | mybb (7) | — | |
| 26 | openssl software foundation | 7 | · | · | · | NEW×7.0 | openssl (7) | — | |
| 27 | pypi | 7 | · | · | · | PoC 2 | django (3) · dulwich (2) · mercurial (1) | — | |
| 28 | schneider-electric | 6 | · | · | · | ×6.0 | wonderware intouch 2014 (4) · pelco ds-nv (1) · device type manager (1) | — | |
| 29 | wireshark | 6 | · | · | · | wireshark (6) | — | ||
| 30 | apache | 5 | · | · | · | PoC 3 | batik (1) · http server (1) · mod-gnutls (1) | — | |
| 31 | xen | 5 | · | · | · | xen (5) | — | ||
| 32 | aveva | 4 | · | · | · | NEW×4.0 | aveva edge (4) | — | |
| 33 | maven | 4 | · | · | · | PoC 3 | org.opencms:opencms-core (1) · org.apache.taglibs:taglibs-standard (1) · org.apache.taglibs:taglibs-standard-impl (1) | — | |
| 34 | mcafee | 4 | · | · | · | data loss prevention endpoint (4) | — | ||
| 35 | suse | 4 | · | · | · | PoC 1 | linux enterprise server (2) · linux enterprise software development kit (1) · linux enterprise workstation extension (1) | — | |
| 36 | tcpdump | 4 | · | · | · | NEWPoC 4 | tcpdump (4) | — | |
| 37 | webgateinc | 4 | · | · | · | NEWPoC 1 | edvr manager (2) · webeyeaudio (1) · winrds (1) | — | |
| 38 | wpml | 4 | · | · | 4 | NEWNuclei 4PoC 4 | wpml (4) | — | |
| 39 | ajsquare | 3 | · | · | · | NEWPoC 3 | zeuscart (3) | — | |
| 40 | apple inc. | 3 | 1 | · | · | ×3.0 | os x (2) · ios (1) | — | |
| 41 | bestpractical | 3 | · | · | · | request tracker (3) | — | ||
| 42 | djangoproject | 3 | · | · | · | PoC 1 | django (3) | — | |
| 43 | gaia-gis | 3 | · | · | · | NEW | freexl (3) | — | |
| 44 | mageia | 3 | · | · | · | NEW | mageia (3) | — | |
| 45 | novell inc. | 3 | · | · | · | opensuse leap (3) | — | ||
| 46 | scadaengine | 3 | 2 | · | · | NEW | bacnet opc server (3) | — | |
| 47 | webshophun | 3 | · | · | · | NEWPoC 3 | webshop hun (3) | — | |
| 48 | x | 3 | · | · | · | libxfont (3) | — | ||
| 49 | сообщество свободного программного обеспечения | 3 | · | · | · | debian gnu/linux (3) · libzip (1) | — | ||
| 50 | asus | 2 | · | · | · | PoC 2 | rt-g32 firmware (2) | — |