month report
May 2015
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
May 2015 closed with 417 published CVEs. 99 criticals, microsoft led volume, mostly via windows. Biggest breakout: adobe systems inc. at ×6.3 their 12-month median. Top weakness class — CWE-119 (63 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
417
— MoM— YoY
Severity mix
99 / 70
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
4.3%
18 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
3939.1
n=18
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
2569
n=3
Detection gap
KEV pressure, no Nuclei coverage
May 2015 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 1microsoft78 CVE
- KEV 1microsoft corp22 CVE
- KEV 1arcserve2 CVE
Weakness × Vendor
What's spreading where in May 2015
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
119Memory Buffer Bounds79XSS200Information Exposure264CWE-264399CWE-399284CWE-28420Improper Input Validation89SQL Injection352CSRF189CWE-189microsoft28118141adobe1634141apple1222141cisco933921015ibm469243112adobe systems inc.15141debian331221111microsoft corp15google211111google inc211111canonical11141ibm corp.4311121
Breakout vendors
CVE count ≥3× their own 12-period median.
- 6.3×adobe systems inc.38 CVE
- 5.7×ibm corp.17 CVE
- 5.0×fortinet5 CVE
- 4.0×docker4 CVE
- 3.3×adobe49 CVE
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #24blue coat5 CVE
- #26hp inc.5 CVE
- #29docker4 CVE
- #32goautodial4 CVE
- #36kozos3 CVE
- #37lenovo3 CVE
- #38module-signature project3 CVE
- #39oscmax3 CVE
- #40qt3 CVE
- #42thecartpress3 CVE
Top vendors
Ranked by distinct CVE count this period.
- 78 CVE53 critCVSS 6.7KEV 1PoC 2windows (32) · internet explorer (23) · windows 8 (15)
- 49 CVE39 critCVSS 8.9×3.3PoC 9acrobat reader (32) · acrobat (32) · air (17)
- 43 CVE29 critCVSS 8.1PoC 2mac os x (37) · iphone os (7) · safari (6)
- 41 CVE2 critCVSS 6.4headend digital broadband delivery system (6) · headend system release (4) · wireless lan controller software (2)
- 39 CVE5 critCVSS 5.2license metric tool (6) · security siteprotector system (6) · endpoint manager family (5)
- 38 CVE38 critCVSS 10.0×6.3PoC 6adobe acrobat (18) · adobe reader (10) · flash player (5)
- 32 CVE1 critCVSS 6.0PoC 2debian linux (32)
- 22 CVE21 critCVSS 9.1KEV 1internet explorer (14) · windows rt (6) · windows 7 (6)
- 19 CVECVSS 6.7PoC 1chrome (19) · v8 (1)
- 18 CVECVSS 6.8PoC 1google chrome (17) · google v8 (1)
- 17 CVE2 critCVSS 6.0PoC 1ubuntu linux (17)
- 17 CVE5 critCVSS 6.6×5.7security siteprotector system (6) · tivoli storage manager fastback (2) · ibm webshpere portal (2)
- 14 CVECVSS 5.9firefox (14) · thunderbird (6) · firefox esr (5)
- 14 CVECVSS 6.3PoC 2opensuse (14)
- 12 CVE1 critCVSS 6.0PoC 2fedora (12)
- 11 CVECVSS 4.6PoC 1solaris (9) · linux (4) · jrockit (1)
- 10 CVECVSS 6.7PoC 2enterprise linux server supplementary (2) · enterprise linux desktop supplementary (2) · enterprise linux server supplementary eus (2)
- 9 CVE2 critCVSS 6.7adaptive security appliance (1) · anyconnect secure mobility client (1) · cisco identity services engine (1)
- 9 CVECVSS 6.2wireshark (9)
- 8 CVE1 critCVSS 5.5linux kernel (8)
- 8 CVECVSS 6.0PoC 3customer relationship management (2) · hana (2) · sybase unwired platform online data proxy (1)
- 7 CVE2 critCVSS 7.3hp-ux (1) · loadrunner (1) · network virtualization (1)
- 6 CVE2 critCVSS 6.0PoC 1clearpass policy manager (6)
- 5 CVECVSS 4.8NEWssl visibility appliance sv1800 firmware (5) · ssl visibility appliance sv2800 firmware (5) · ssl visibility appliance sv3800 firmware (5)
- 5 CVECVSS 4.3×5.0Nuclei 1PoC 1fortios (2) · fortiadc firmware (1) · fortianalyzer firmware (1)
- 5 CVE1 critCVSS 7.5NEWhp nonstop safegguard security (1) · hewlett-packard virtual application network software-defined networking controller (1) · hp access control (1)
- 5 CVECVSS 7.2suse linux enterprise desktop (5) · suse linux enterprise server (5) · suse linux enterprise software development kit (5)
- 4 CVECVSS 5.0clamav (4)
- 4 CVECVSS 6.6NEW×4.0PoC 4docker (3) · libcontainer (2)
- 4 CVE1 critCVSS 7.1PoC 3autostart (1) · rsa identity management and governance (1) · sourceone email management (1)
- 4 CVECVSS 6.5PoC 4github.com/docker/docker (4)
- 4 CVE3 critCVSS 9.4NEWPoC 4goadmin ce (4)
- 4 CVE1 critCVSS 5.5PoC 2seq analyst (2) · e355s mobile wifi firmware (1) · e587 mobile wifi firmware (1)
- 3 CVECVSS 7.6PoC 1os x (2) · ios (2) · itunes (1)
- 3 CVECVSS 6.8qt (3)
- 3 CVECVSS 5.0NEWeasyctf (3)
- 3 CVECVSS 7.5NEWsystem update (3)
- 3 CVE1 critCVSS 7.4NEWmodule-signature (3)
- 3 CVECVSS 6.2NEWoscmax (3)
- 3 CVECVSS 6.8NEWqt (3)
- 3 CVECVSS 5.3linux enterprise desktop (2) · linux enterprise server (2) · linux enterprise software development kit (2)
- 3 CVECVSS 4.2NEWNuclei 3PoC 3thecartpress ecommerce shopping cart (3)
- 3 CVECVSS 5.1NEWycb001 firmware (3) · ycb002 firmware (3) · ycb003 firmware (3)
- 2 CVE1 critCVSS 8.4NEWKEV 1arcserve unified data protection (1) · udp (1)
- 2 CVECVSS 4.3NEWweb filter (2)
- 2 CVE1 critCVSS 8.8ubuntu (2)
- 2 CVECVSS 4.3NEWPoC 1concrete5 (2)
- 2 CVECVSS 4.7NEWPoC 2coppermine photo gallery (2)
- 2 CVECVSS 6.7PoC 1big-ip link controller (2) · big-ip policy enforcement manager (2) · big-ip access policy manager (2)
- 2 CVECVSS 5.5NEWPoC 1pacemaker configuration system (2)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | microsoft | 78 | 53 | 1 | · | KEV 1PoC 2 | windows (32) · internet explorer (23) · windows 8 (15) | — | |
| 2 | adobe | 49 | 39 | · | · | ×3.3PoC 9 | acrobat reader (32) · acrobat (32) · air (17) | — | |
| 3 | apple | 43 | 29 | · | · | PoC 2 | mac os x (37) · iphone os (7) · safari (6) | — | |
| 4 | cisco | 41 | 2 | · | · | headend digital broadband delivery system (6) · headend system release (4) · wireless lan controller software (2) | — | ||
| 5 | ibm | 39 | 5 | · | · | license metric tool (6) · security siteprotector system (6) · endpoint manager family (5) | — | ||
| 6 | adobe systems inc. | 38 | 38 | · | · | ×6.3PoC 6 | adobe acrobat (18) · adobe reader (10) · flash player (5) | — | |
| 7 | debian | 32 | 1 | · | · | PoC 2 | debian linux (32) | — | |
| 8 | microsoft corp | 22 | 21 | 1 | · | KEV 1 | internet explorer (14) · windows rt (6) · windows 7 (6) | — | |
| 9 | 19 | · | · | · | PoC 1 | chrome (19) · v8 (1) | — | ||
| 10 | google inc | 18 | · | · | · | PoC 1 | google chrome (17) · google v8 (1) | — | |
| 11 | canonical | 17 | 2 | · | · | PoC 1 | ubuntu linux (17) | — | |
| 12 | ibm corp. | 17 | 5 | · | · | ×5.7 | security siteprotector system (6) · tivoli storage manager fastback (2) · ibm webshpere portal (2) | — | |
| 13 | mozilla | 14 | · | · | · | firefox (14) · thunderbird (6) · firefox esr (5) | — | ||
| 14 | opensuse | 14 | · | · | · | PoC 2 | opensuse (14) | — | |
| 15 | fedoraproject | 12 | 1 | · | · | PoC 2 | fedora (12) | — | |
| 16 | oracle | 11 | · | · | · | PoC 1 | solaris (9) · linux (4) · jrockit (1) | — | |
| 17 | redhat | 10 | · | · | · | PoC 2 | enterprise linux server supplementary (2) · enterprise linux desktop supplementary (2) · enterprise linux server supplementary eus (2) | — | |
| 18 | cisco systems inc. | 9 | 2 | · | · | adaptive security appliance (1) · anyconnect secure mobility client (1) · cisco identity services engine (1) | — | ||
| 19 | wireshark | 9 | · | · | · | wireshark (9) | — | ||
| 20 | linux | 8 | 1 | · | · | linux kernel (8) | — | ||
| 21 | sap | 8 | · | · | · | PoC 3 | customer relationship management (2) · hana (2) · sybase unwired platform online data proxy (1) | — | |
| 22 | hp | 7 | 2 | · | · | hp-ux (1) · loadrunner (1) · network virtualization (1) | — | ||
| 23 | arubanetworks | 6 | 2 | · | · | PoC 1 | clearpass policy manager (6) | — | |
| 24 | blue coat | 5 | · | · | · | NEW | ssl visibility appliance sv1800 firmware (5) · ssl visibility appliance sv2800 firmware (5) · ssl visibility appliance sv3800 firmware (5) | — | |
| 25 | fortinet | 5 | · | · | 1 | ×5.0Nuclei 1PoC 1 | fortios (2) · fortiadc firmware (1) · fortianalyzer firmware (1) | — | |
| 26 | hp inc. | 5 | 1 | · | · | NEW | hp nonstop safegguard security (1) · hewlett-packard virtual application network software-defined networking controller (1) · hp access control (1) | — | |
| 27 | novell | 5 | · | · | · | suse linux enterprise desktop (5) · suse linux enterprise server (5) · suse linux enterprise software development kit (5) | — | ||
| 28 | clamav | 4 | · | · | · | clamav (4) | — | ||
| 29 | docker | 4 | · | · | · | NEW×4.0PoC 4 | docker (3) · libcontainer (2) | — | |
| 30 | emc | 4 | 1 | · | · | PoC 3 | autostart (1) · rsa identity management and governance (1) · sourceone email management (1) | — | |
| 31 | go | 4 | · | · | · | PoC 4 | github.com/docker/docker (4) | — | |
| 32 | goautodial | 4 | 3 | · | · | NEWPoC 4 | goadmin ce (4) | — | |
| 33 | huawei | 4 | 1 | · | · | PoC 2 | seq analyst (2) · e355s mobile wifi firmware (1) · e587 mobile wifi firmware (1) | — | |
| 34 | apple inc. | 3 | · | · | · | PoC 1 | os x (2) · ios (2) · itunes (1) | — | |
| 35 | digia | 3 | · | · | · | qt (3) | — | ||
| 36 | kozos | 3 | · | · | · | NEW | easyctf (3) | — | |
| 37 | lenovo | 3 | · | · | · | NEW | system update (3) | — | |
| 38 | module-signature project | 3 | 1 | · | · | NEW | module-signature (3) | — | |
| 39 | oscmax | 3 | · | · | · | NEW | oscmax (3) | — | |
| 40 | qt | 3 | · | · | · | NEW | qt (3) | — | |
| 41 | suse | 3 | · | · | · | linux enterprise desktop (2) · linux enterprise server (2) · linux enterprise software development kit (2) | — | ||
| 42 | thecartpress | 3 | · | · | 3 | NEWNuclei 3PoC 3 | thecartpress ecommerce shopping cart (3) | — | |
| 43 | y-cam | 3 | · | · | · | NEW | ycb001 firmware (3) · ycb002 firmware (3) · ycb003 firmware (3) | — | |
| 44 | arcserve | 2 | 1 | 1 | · | NEWKEV 1 | arcserve unified data protection (1) · udp (1) | — | |
| 45 | barracuda | 2 | · | · | · | NEW | web filter (2) | — | |
| 46 | canonical ltd. | 2 | 1 | · | · | ubuntu (2) | — | ||
| 47 | concrete5 | 2 | · | · | · | NEWPoC 1 | concrete5 (2) | — | |
| 48 | coppermine-gallery | 2 | · | · | · | NEWPoC 2 | coppermine photo gallery (2) | — | |
| 49 | f5 | 2 | · | · | · | PoC 1 | big-ip link controller (2) · big-ip policy enforcement manager (2) · big-ip access policy manager (2) | — | |
| 50 | fedora | 2 | · | · | · | NEWPoC 1 | pacemaker configuration system (2) | — |