month report
July 2016
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
July 2016 closed with 789 published CVEs — +22.5% YoY . 91 criticals, oracle led volume, mostly via mysql. Biggest breakout: phpmyadmin at ×15.0 their 12-month median. Top weakness class — CWE-119 (121 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
789
— MoM+22.5% YoY
Severity mix
91 / 400
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
0.1%
1 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
3515.4
n=1
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
—
n=0
Weakness × Vendor
What's spreading where in July 2016
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
119Memory Buffer Bounds264CWE-26420Improper Input Validation200Information Exposure787Out-of-bounds Write79XSS284CWE-284416Use After Free254CWE-254399CWE-399oracle112google164514133443adobe28361101adobe systems inc.28361101google inc52715131213microsoft corp187828453apple3333712131ibm161161052microsoft187843cisco3492426зао «нпп «релэкс»813opensuse44111
Breakout vendors
CVE count ≥3× their own 12-period median.
- 15.0×phpmyadmin15 CVE
- 6.2×oracle204 CVE
- 5.0×siemens10 CVE
- 5.0×nuget5 CVE
- 5.0×solarwinds inc.5 CVE
- 5.0×vmware5 CVE
- 4.5×php group9 CVE
- 4.0×google119 CVE
- 3.7×packagist11 CVE
- 3.3×apache software foundation10 CVE
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #11зао «нпп «релэкс»25 CVE
- #35ооо «1с-софт»6 CVE
- #40solarwinds inc.5 CVE
- #43nixu corp.4 CVE
- #44opera software asa4 CVE
- #45meinberg3 CVE
- #46misys3 CVE
- #47solare datensysteme gmbh3 CVE
- #49accela2 CVE
- #50bosch2 CVE
Top vendors
Ranked by distinct CVE count this period.
- 204 CVE20 critCVSS 6.7×6.2Nuclei 1PoC 6mysql (21) · linux (20) · agile product lifecycle management (19)
- 119 CVE6 critCVSS 7.6×4.0android (100) · chrome (19) · v8 (2)
- 83 CVE22 critCVSS 9.1PoC 18flash player (52) · flash player desktop runtime (52) · reader (30)
- 82 CVE22 critCVSS 9.1PoC 18flash player (52) · flash player for linux (52) · adobe acrobat document cloud (30)
- 75 CVE6 critCVSS 7.4×3.2android (62) · google chrome (13)
- 73 CVECVSS 7.3PoC 7internet explorer (48) · microsoft edge (46) · windows 10 rtm (12)
- 64 CVE10 critCVSS 8.1PoC 17mac os x (41) · iphone os (26) · tvos (21)
- 57 CVE1 critCVSS 6.1PoC 1powerkvm (6) · tririga application platform (6) · jazz reporting service (6)
- 40 CVECVSS 6.7internet explorer (15) · windows 10 (12) · edge (12)
- 31 CVE2 critCVSS 7.3PoC 3webex meetings server (5) · prime infrastructure (3) · epc3928 firmware (3)
- 25 CVE2 critCVSS 7.6NEWлинтер бастион (24) · программа linstmgr.exe мониторинга и управления серверами системы управления базами данных линтер бастион 6.0 (1)
- 22 CVE1 critCVSS 7.0PoC 4opensuse (21) · leap (19)
- 20 CVE1 critCVSS 7.7PoC 7ios (12) · macos (8) · safari (4)
- 19 CVE1 critCVSS 6.7PoC 1ubuntu linux (18) · openstack ironic (1)
- 18 CVE4 critCVSS 7.5PoC 2debian linux (18)
- 17 CVE1 critCVSS 7.5PoC 5struts (8) · http server (3) · tomcat (2)
- 17 CVE2 critCVSS 6.9enterprise linux server (10) · enterprise linux desktop (9) · enterprise linux workstation (9)
- 16 CVE6 critCVSS 7.9PoC 9debian gnu/linux (10) · linux (6)
- 15 CVE2 critCVSS 6.5×15.0PoC 1phpmyadmin (15)
- 14 CVE1 critCVSS 7.6PoC 2struts:struts (3) · org.apache.struts:struts-core (3) · org.apache.struts:struts2-core (2)
- 11 CVE1 critCVSS 6.4×3.7PoC 1phpmyadmin/phpmyadmin (11)
- 11 CVE6 critCVSS 8.9PoC 4php (11)
- 10 CVE1 critCVSS 7.5×3.3PoC 1struts (7) · xerces c++ (1) · commons fileupload (1)
- 10 CVE4 critCVSS 8.0fedora (10)
- 10 CVE1 critCVSS 7.2×5.0PoC 4simatic net cp 443-1 opc ua firmware (4) · simatic wincc (2) · sicam pas\/pqs (2)
- 9 CVE5 critCVSS 8.9PoC 3ubuntu (9)
- 9 CVE5 critCVSS 8.2java platform (8) · weblogic server (1)
- 9 CVE5 critCVSS 8.9×4.5PoC 4php (9)
- 8 CVECVSS 5.6mariadb (8)
- 7 CVE1 critCVSS 7.6prime infrastructure (3) · cisco evolved programmable network manager (2) · cisco private internet exchange (2)
- 7 CVE1 critCVSS 7.5PoC 1linux kernel (7)
- 7 CVECVSS 6.7PoC 4manager proxy (5) · linux enterprise desktop (5) · linux enterprise server (5)
- 6 CVE1 critCVSS 8.6PoC 1system management homepage (3) · intelligent management center application performance manager (1) · intelligent management center branch intelligent management system (1)
- 6 CVECVSS 5.9×3.0PoC 5роса кобальт (5) · rosa virtualization (1) · rosa virtualization 3.0 (1)
- 6 CVE1 critCVSS 8.1NEW1с:предприятие (6)
- 5 CVECVSS 6.4websphere application server (4) · ibm maximo asset management (1)
- 5 CVECVSS 7.5PoC 3suse manager (3) · suse linux enterprise live patching (1) · suse linux enterprise module for public cloud (1)
- 5 CVECVSS 6.7×3.3PoC 4ntp (5)
- 5 CVECVSS 8.8×5.0microsoft.chakracore (5)
- 5 CVECVSS 5.8NEW×5.0serv-u file server (5)
- 5 CVECVSS 6.4×5.0vrealize log insight (2) · nsx edge (1) · spring framework (1)
- 5 CVE4 critCVSS 9.6×3.3libxslt (4) · libxml2 (1)
- 4 CVE1 critCVSS 5.4NEWnamesurfer (4)
- 4 CVE2 critCVSS 8.8NEWopera (4)
- 3 CVECVSS 7.6NEWPoC 2ims-lantime m1000 (3) · ims-lantime m3000 (3) · ims-lantime m500 (3)
- 3 CVECVSS 6.6NEWfusioncapital opics plus (3)
- 3 CVE1 critCVSS 7.5NEWмикропрограммное обеспечение звена фотоэлектрической системы solar-log (2) · solar-log web (1)
- 3 CVECVSS 5.7workspace virtualization (2) · workspace streaming (2) · client intrusion detection system (1)
- 2 CVECVSS 7.5NEWcivic platform citizen access portal (1) · civic platform (1)
- 2 CVECVSS 6.3NEWbladecontrol-webvis (2)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | oracle | 204 | 20 | · | 1 | ×6.2Nuclei 1PoC 6 | mysql (21) · linux (20) · agile product lifecycle management (19) | — | |
| 2 | 119 | 6 | · | · | ×4.0 | android (100) · chrome (19) · v8 (2) | — | ||
| 3 | adobe | 83 | 22 | · | · | PoC 18 | flash player (52) · flash player desktop runtime (52) · reader (30) | — | |
| 4 | adobe systems inc. | 82 | 22 | · | · | PoC 18 | flash player (52) · flash player for linux (52) · adobe acrobat document cloud (30) | — | |
| 5 | google inc | 75 | 6 | · | · | ×3.2 | android (62) · google chrome (13) | — | |
| 6 | microsoft corp | 73 | · | · | · | PoC 7 | internet explorer (48) · microsoft edge (46) · windows 10 rtm (12) | — | |
| 7 | apple | 64 | 10 | · | · | PoC 17 | mac os x (41) · iphone os (26) · tvos (21) | — | |
| 8 | ibm | 57 | 1 | · | · | PoC 1 | powerkvm (6) · tririga application platform (6) · jazz reporting service (6) | — | |
| 9 | microsoft | 40 | · | · | · | internet explorer (15) · windows 10 (12) · edge (12) | — | ||
| 10 | cisco | 31 | 2 | · | · | PoC 3 | webex meetings server (5) · prime infrastructure (3) · epc3928 firmware (3) | — | |
| 11 | зао «нпп «релэкс» | 25 | 2 | · | · | NEW | линтер бастион (24) · программа linstmgr.exe мониторинга и управления серверами системы управления базами данных линтер бастион 6.0 (1) | — | |
| 12 | opensuse | 22 | 1 | · | · | PoC 4 | opensuse (21) · leap (19) | — | |
| 13 | apple inc. | 20 | 1 | · | · | PoC 7 | ios (12) · macos (8) · safari (4) | — | |
| 14 | canonical | 19 | 1 | · | · | PoC 1 | ubuntu linux (18) · openstack ironic (1) | — | |
| 15 | debian | 18 | 4 | · | · | PoC 2 | debian linux (18) | — | |
| 16 | apache | 17 | 1 | · | · | PoC 5 | struts (8) · http server (3) · tomcat (2) | — | |
| 17 | redhat | 17 | 2 | · | · | enterprise linux server (10) · enterprise linux desktop (9) · enterprise linux workstation (9) | — | ||
| 18 | сообщество свободного программного обеспечения | 16 | 6 | · | · | PoC 9 | debian gnu/linux (10) · linux (6) | — | |
| 19 | phpmyadmin | 15 | 2 | · | · | ×15.0PoC 1 | phpmyadmin (15) | — | |
| 20 | maven | 14 | 1 | · | · | PoC 2 | struts:struts (3) · org.apache.struts:struts-core (3) · org.apache.struts:struts2-core (2) | — | |
| 21 | packagist | 11 | 1 | · | · | ×3.7PoC 1 | phpmyadmin/phpmyadmin (11) | — | |
| 22 | php | 11 | 6 | · | · | PoC 4 | php (11) | — | |
| 23 | apache software foundation | 10 | 1 | · | · | ×3.3PoC 1 | struts (7) · xerces c++ (1) · commons fileupload (1) | — | |
| 24 | fedoraproject | 10 | 4 | · | · | fedora (10) | — | ||
| 25 | siemens | 10 | 1 | · | · | ×5.0PoC 4 | simatic net cp 443-1 opc ua firmware (4) · simatic wincc (2) · sicam pas\/pqs (2) | — | |
| 26 | canonical ltd. | 9 | 5 | · | · | PoC 3 | ubuntu (9) | — | |
| 27 | oracle corp. | 9 | 5 | · | · | java platform (8) · weblogic server (1) | — | ||
| 28 | php group | 9 | 5 | · | · | ×4.5PoC 4 | php (9) | — | |
| 29 | mariadb | 8 | · | · | · | mariadb (8) | — | ||
| 30 | cisco systems inc. | 7 | 1 | · | · | prime infrastructure (3) · cisco evolved programmable network manager (2) · cisco private internet exchange (2) | — | ||
| 31 | linux | 7 | 1 | · | · | PoC 1 | linux kernel (7) | — | |
| 32 | suse | 7 | · | · | · | PoC 4 | manager proxy (5) · linux enterprise desktop (5) · linux enterprise server (5) | — | |
| 33 | hp | 6 | 1 | · | · | PoC 1 | system management homepage (3) · intelligent management center application performance manager (1) · intelligent management center branch intelligent management system (1) | — | |
| 34 | ао «нтц ит роса» | 6 | · | · | · | ×3.0PoC 5 | роса кобальт (5) · rosa virtualization (1) · rosa virtualization 3.0 (1) | — | |
| 35 | ооо «1с-софт» | 6 | 1 | · | · | NEW | 1с:предприятие (6) | — | |
| 36 | ibm corp. | 5 | · | · | · | websphere application server (4) · ibm maximo asset management (1) | — | ||
| 37 | novell | 5 | · | · | · | PoC 3 | suse manager (3) · suse linux enterprise live patching (1) · suse linux enterprise module for public cloud (1) | — | |
| 38 | ntp | 5 | · | · | · | ×3.3PoC 4 | ntp (5) | — | |
| 39 | nuget | 5 | · | · | · | ×5.0 | microsoft.chakracore (5) | — | |
| 40 | solarwinds inc. | 5 | · | · | · | NEW×5.0 | serv-u file server (5) | — | |
| 41 | vmware | 5 | · | · | · | ×5.0 | vrealize log insight (2) · nsx edge (1) · spring framework (1) | — | |
| 42 | xmlsoft | 5 | 4 | · | · | ×3.3 | libxslt (4) · libxml2 (1) | — | |
| 43 | nixu corp. | 4 | 1 | · | · | NEW | namesurfer (4) | — | |
| 44 | opera software asa | 4 | 2 | · | · | NEW | opera (4) | — | |
| 45 | meinberg | 3 | · | · | · | NEWPoC 2 | ims-lantime m1000 (3) · ims-lantime m3000 (3) · ims-lantime m500 (3) | — | |
| 46 | misys | 3 | · | · | · | NEW | fusioncapital opics plus (3) | — | |
| 47 | solare datensysteme gmbh | 3 | 1 | · | · | NEW | микропрограммное обеспечение звена фотоэлектрической системы solar-log (2) · solar-log web (1) | — | |
| 48 | symantec | 3 | · | · | · | workspace virtualization (2) · workspace streaming (2) · client intrusion detection system (1) | — | ||
| 49 | accela | 2 | · | · | · | NEW | civic platform citizen access portal (1) · civic platform (1) | — | |
| 50 | bosch | 2 | · | · | · | NEW | bladecontrol-webvis (2) | — |