month report
November 2015
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
November 2015 closed with 368 published CVEs — -27.1% YoY . 75 criticals, microsoft led volume, mostly via internet explorer. Biggest breakout: microsoft corp at ×25.0 their 12-month median. Top weakness class — CWE-119 (68 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
368
— MoM-27.1% YoY
Severity mix
75 / 73
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
1.9%
7 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
3770.4
n=7
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
2451
n=2
Detection gap
KEV pressure, no Nuclei coverage
November 2015 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 1redhat17 CVE
- KEV 1maven16 CVE
- KEV 1jenkins12 CVE
- KEV 1oracle11 CVE
- KEV 1oracle corp.3 CVE
Weakness × Vendor
What's spreading where in November 2015
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
119Memory Buffer Bounds200Information Exposure264CWE-26420Improper Input Validation79XSS399CWE-399254CWE-254284CWE-284352CSRF189CWE-189microsoft30653311microsoft corp30653311cisco5253713canonical623143ibm7611111debian73411mozilla941241adobe1112mozilla corp.941241adobe systems inc.1112redhat143111maven44111
Breakout vendors
CVE count ≥3× their own 12-period median.
- 25.0×microsoft corp50 CVE
- 21.0×adobe systems inc.21 CVE
- 6.0×novell inc.6 CVE
- 4.5×hp9 CVE
- 3.5×huawei7 CVE
- 3.0×citrix3 CVE
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #38csl dualcom4 CVE
- #39ffmpeg team4 CVE
- #40lenovo4 CVE
- #43nvidia corp.4 CVE
- #44the document foundation4 CVE
- #45xmlsoft4 CVE
- #50samsung3 CVE
- #52the linux foundation3 CVE
- #54arista2 CVE
- #55arm2 CVE
Top vendors
Ranked by distinct CVE count this period.
- 50 CVE33 critCVSS 7.2PoC 8internet explorer (25) · windows 7 (11) · windows vista (11)
- 50 CVE32 critCVSS 7.1×25.0PoC 8internet explorer (25) · windows 7 service pack 1 (11) · windows server 2012 r2 (11)
- 30 CVE1 critCVSS 6.0PoC 1firepower extensible operating system (8) · web security appliance (4) · ios (3)
- 28 CVE1 critCVSS 5.7PoC 3ubuntu linux (28)
- 26 CVECVSS 5.2security qradar incident forensics (7) · system networking switch center (4) · maximo asset management (2)
- 24 CVE1 critCVSS 6.0PoC 3debian linux (24)
- 23 CVE1 critCVSS 6.6PoC 3firefox (23) · network security services (3)
- 22 CVE17 critCVSS 9.0PoC 3air sdk \& compiler (17) · air (17) · air sdk (17)
- 22 CVE1 critCVSS 6.7PoC 3firefox (22) · firefox esr (13)
- 21 CVE16 critCVSS 8.8×21.0PoC 3adobe integrated runtime (17) · flash player (17) · coldfusion (3)
- 17 CVE1 critCVSS 6.1KEV 1PoC 2openshift (11) · enterprise linux workstation (2) · enterprise linux server aus (2)
- 16 CVE1 critCVSS 5.8KEV 1PoC 1org.jenkins-ci.main:jenkins-core (11) · org.apache.ambari:ambari (2) · org.apache.cxf:cxf-rt-rs-security-sso-saml (1)
- 14 CVE1 critCVSS 5.7PoC 2opensuse (14) · leap (8)
- 13 CVECVSS 5.1PoC 2ambari (6) · openoffice (4) · cordova (2)
- 13 CVE8 critCVSS 8.3PoC 2android (10) · picasa (2) · chrome (1)
- 12 CVE1 critCVSS 6.2KEV 1PoC 1jenkins (12)
- 11 CVE6 critCVSS 8.0android (10) · google chrome (1)
- 11 CVE4 critCVSS 7.6KEV 1PoC 2solaris (5) · linux (2) · virtual desktop infrastructure (2)
- 10 CVECVSS 5.5cisco firepower extensible operating system (8) · adaptive security appliance (1) · cisco ios (1)
- 9 CVECVSS 4.8PoC 1ubuntu (9)
- 9 CVECVSS 6.3×4.5PoC 1arcsight logger (3) · arcsight smartconnectors (2) · arcsight connectors (1)
- 9 CVECVSS 5.7PoC 2debian gnu/linux (7) · libxml2 (2) · linux (1)
- 8 CVECVSS 5.0PoC 1mac os x (7) · iphone os (6) · tvos (3)
- 8 CVECVSS 6.6fedora (8)
- 7 CVECVSS 7.1ffmpeg (7)
- 7 CVECVSS 5.5×3.5PoC 1espace firmware (3) · ne router software (1) · vp 9660 firmware (1)
- 7 CVE1 critCVSS 5.5PoC 1linux kernel (7)
- 7 CVE1 critCVSS 6.7PoC 7sap hana (5) · hana (5) · plant connectivity (1)
- 6 CVECVSS 4.5×6.0opensuse (5) · suse linux enterprise desktop (1)
- 6 CVECVSS 5.7linux enterprise desktop (6) · linux enterprise server (6) · linux enterprise software development kit (4)
- 6 CVECVSS 5.4Nuclei 6wordpress (6)
- 5 CVECVSS 6.0ibm maximo asset management (1) · ibm smartcloud control desk (1) · ibm sterling b2b integrator (1)
- 5 CVECVSS 5.2mediawiki (5)
- 5 CVE1 critCVSS 7.6PoC 1gpu driver (5)
- 5 CVECVSS 5.9PoC 1astra linux common edition (4) · astra linux special edition (3) · astra linux special edition для «эльбрус» (1)
- 4 CVECVSS 6.2openoffice (4)
- 4 CVE1 critCVSS 6.2PoC 1na model 862 gw mono firmware (4)
- 4 CVECVSS 6.0NEWPoC 2gprs cs2300-r firmware (4)
- 4 CVECVSS 7.3NEWffmpeg (4)
- 4 CVECVSS 6.6NEWswitch center (4)
- 4 CVECVSS 6.2libreoffice (4)
- 4 CVECVSS 6.2kerberos 5 (4)
- 4 CVE1 critCVSS 7.9NEWPoC 1nvidia gpu (4)
- 4 CVECVSS 6.2NEWlibreoffice (4)
- 4 CVECVSS 4.7NEWPoC 1libxml2 (3) · libxslt (1)
- 3 CVECVSS 4.8×3.0netscaler gateway firmware (3) · netscaler application delivery controller firmware (3) · netscaler service delivery appliance service vm (3)
- 3 CVE2 critCVSS 9.6KEV 1PoC 1communications application session controller (1) · communications performance intelligence center (pic) software (1) · communications webrtc session controller (1)
- 3 CVECVSS 5.8ipsilon (2) · ironic-inspector (1) · python-ironic-inspector-client (1)
- 3 CVECVSS 6.6qemu (3)
- 3 CVECVSS 7.0NEWPoC 1smartviewer (2) · galaxy s6 (1)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | microsoft | 50 | 33 | · | · | PoC 8 | internet explorer (25) · windows 7 (11) · windows vista (11) | — | |
| 2 | microsoft corp | 50 | 32 | · | · | ×25.0PoC 8 | internet explorer (25) · windows 7 service pack 1 (11) · windows server 2012 r2 (11) | — | |
| 3 | cisco | 30 | 1 | · | · | PoC 1 | firepower extensible operating system (8) · web security appliance (4) · ios (3) | — | |
| 4 | canonical | 28 | 1 | · | · | PoC 3 | ubuntu linux (28) | — | |
| 5 | ibm | 26 | · | · | · | security qradar incident forensics (7) · system networking switch center (4) · maximo asset management (2) | — | ||
| 6 | debian | 24 | 1 | · | · | PoC 3 | debian linux (24) | — | |
| 7 | mozilla | 23 | 1 | · | · | PoC 3 | firefox (23) · network security services (3) | — | |
| 8 | adobe | 22 | 17 | · | · | PoC 3 | air sdk \& compiler (17) · air (17) · air sdk (17) | — | |
| 9 | mozilla corp. | 22 | 1 | · | · | PoC 3 | firefox (22) · firefox esr (13) | — | |
| 10 | adobe systems inc. | 21 | 16 | · | · | ×21.0PoC 3 | adobe integrated runtime (17) · flash player (17) · coldfusion (3) | — | |
| 11 | redhat | 17 | 1 | 1 | · | KEV 1PoC 2 | openshift (11) · enterprise linux workstation (2) · enterprise linux server aus (2) | — | |
| 12 | maven | 16 | 1 | 1 | · | KEV 1PoC 1 | org.jenkins-ci.main:jenkins-core (11) · org.apache.ambari:ambari (2) · org.apache.cxf:cxf-rt-rs-security-sso-saml (1) | — | |
| 13 | opensuse | 14 | 1 | · | · | PoC 2 | opensuse (14) · leap (8) | — | |
| 14 | apache | 13 | · | · | · | PoC 2 | ambari (6) · openoffice (4) · cordova (2) | — | |
| 15 | 13 | 8 | · | · | PoC 2 | android (10) · picasa (2) · chrome (1) | — | ||
| 16 | jenkins | 12 | 1 | 1 | · | KEV 1PoC 1 | jenkins (12) | — | |
| 17 | google inc | 11 | 6 | · | · | android (10) · google chrome (1) | — | ||
| 18 | oracle | 11 | 4 | 1 | · | KEV 1PoC 2 | solaris (5) · linux (2) · virtual desktop infrastructure (2) | — | |
| 19 | cisco systems inc. | 10 | · | · | · | cisco firepower extensible operating system (8) · adaptive security appliance (1) · cisco ios (1) | — | ||
| 20 | canonical ltd. | 9 | · | · | · | PoC 1 | ubuntu (9) | — | |
| 21 | hp | 9 | · | · | · | ×4.5PoC 1 | arcsight logger (3) · arcsight smartconnectors (2) · arcsight connectors (1) | — | |
| 22 | сообщество свободного программного обеспечения | 9 | · | · | · | PoC 2 | debian gnu/linux (7) · libxml2 (2) · linux (1) | — | |
| 23 | apple | 8 | · | · | · | PoC 1 | mac os x (7) · iphone os (6) · tvos (3) | — | |
| 24 | fedoraproject | 8 | · | · | · | fedora (8) | — | ||
| 25 | ffmpeg | 7 | · | · | · | ffmpeg (7) | — | ||
| 26 | huawei | 7 | · | · | · | ×3.5PoC 1 | espace firmware (3) · ne router software (1) · vp 9660 firmware (1) | — | |
| 27 | linux | 7 | 1 | · | · | PoC 1 | linux kernel (7) | — | |
| 28 | sap | 7 | 1 | · | · | PoC 7 | sap hana (5) · hana (5) · plant connectivity (1) | — | |
| 29 | novell inc. | 6 | · | · | · | ×6.0 | opensuse (5) · suse linux enterprise desktop (1) | — | |
| 30 | suse | 6 | · | · | · | linux enterprise desktop (6) · linux enterprise server (6) · linux enterprise software development kit (4) | — | ||
| 31 | wordpress | 6 | · | · | 6 | Nuclei 6 | wordpress (6) | — | |
| 32 | ibm corp. | 5 | · | · | · | ibm maximo asset management (1) · ibm smartcloud control desk (1) · ibm sterling b2b integrator (1) | — | ||
| 33 | mediawiki | 5 | · | · | · | mediawiki (5) | — | ||
| 34 | nvidia | 5 | 1 | · | · | PoC 1 | gpu driver (5) | — | |
| 35 | ооо «русбитех-астра» | 5 | · | · | · | PoC 1 | astra linux common edition (4) · astra linux special edition (3) · astra linux special edition для «эльбрус» (1) | — | |
| 36 | apache software foundation | 4 | · | · | · | openoffice (4) | — | ||
| 37 | arris | 4 | 1 | · | · | PoC 1 | na model 862 gw mono firmware (4) | — | |
| 38 | csl dualcom | 4 | · | · | · | NEWPoC 2 | gprs cs2300-r firmware (4) | — | |
| 39 | ffmpeg team | 4 | · | · | · | NEW | ffmpeg (4) | — | |
| 40 | lenovo | 4 | · | · | · | NEW | switch center (4) | — | |
| 41 | libreoffice | 4 | · | · | · | libreoffice (4) | — | ||
| 42 | mit | 4 | · | · | · | kerberos 5 (4) | — | ||
| 43 | nvidia corp. | 4 | 1 | · | · | NEWPoC 1 | nvidia gpu (4) | — | |
| 44 | the document foundation | 4 | · | · | · | NEW | libreoffice (4) | — | |
| 45 | xmlsoft | 4 | · | · | · | NEWPoC 1 | libxml2 (3) · libxslt (1) | — | |
| 46 | citrix | 3 | · | · | · | ×3.0 | netscaler gateway firmware (3) · netscaler application delivery controller firmware (3) · netscaler service delivery appliance service vm (3) | — | |
| 47 | oracle corp. | 3 | 2 | 1 | · | KEV 1PoC 1 | communications application session controller (1) · communications performance intelligence center (pic) software (1) · communications webrtc session controller (1) | — | |
| 48 | pypi | 3 | · | · | · | ipsilon (2) · ironic-inspector (1) · python-ironic-inspector-client (1) | — | ||
| 49 | qemu | 3 | · | · | · | qemu (3) | — | ||
| 50 | samsung | 3 | · | · | · | NEWPoC 1 | smartviewer (2) · galaxy s6 (1) | — |