month report
March 2019
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
March 2019 closed with 1,675 published CVEs. 181 criticals, сообщество свободного программного обеспечения led volume, mostly via debian gnu/linux. Top weakness class — CWE-79 (197 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
1,675
— MoM— YoY
Severity mix
181 / 547
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
3.3%
56 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
2543.6
n=56
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
1059
n=12
Detection gap
KEV pressure, no Nuclei coverage
March 2019 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 2jenkins project20 CVE
- KEV 2jenkins19 CVE
- KEV 1apple31 CVE
- KEV 1apple inc.11 CVE
Weakness × Vendor
What's spreading where in March 2019
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS787Out-of-bounds Write20Improper Input Validation125Out-of-bounds Read119Memory Buffer Bounds22Path Traversal352CSRF200Information Exposure89SQL Injection78OS Command Injectionсообщество свободного программного обеспечения13421441ооо «русбитех-астра»9217241microsoft31751microsoft corp21751opensuse1114142312debian11011632cisco22421114cisco systems inc.22121114novell inc.113312221fedoraproject292713ibm2415311redhat27342
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #18intel corporation39 CVE
- #23[unknown]23 CVE
- #24uvnc22 CVE
- #26jenkins project20 CVE
- #27jenkins19 CVE
- #29kaspersky lab18 CVE
- #30team ultravnc17 CVE
- #37cmsmadesimple12 CVE
- #43ics-cert11 CVE
- #44npm11 CVE
Top vendors
Ranked by distinct CVE count this period.
- 91 CVE17 critCVSS 7.4KEV 1Nuclei 3PoC 31debian gnu/linux (81) · rdesktop (9) · libssh2 (9)
- 85 CVE6 critCVSS 6.6KEV 1Nuclei 3PoC 24astra linux special edition (80) · astra linux special edition для «эльбрус» (50) · astra linux common edition (15)
- 78 CVE3 critCVSS 7.1KEV 2Nuclei 1windows (32) · windows server (32) · windows 10 (30)
- 72 CVE2 critCVSS 7.1KEV 2Nuclei 1windows 10 1709 (29) · windows server 1709 (server core installation) (29) · windows server 1803 (server core installation) (29)
- 70 CVE9 critCVSS 7.3KEV 1Nuclei 3PoC 27leap (62) · backports sle (12) · supportutils (5)
- 67 CVE11 critCVSS 7.3KEV 1Nuclei 4PoC 28debian linux (67) · cron (1)
- 64 CVE1 critCVSS 7.3Nuclei 1PoC 63nx-os (29) · ios xe (23) · nexus 3000 series switches (21)
- 59 CVE1 critCVSS 7.3Nuclei 1PoC 57nx-os (21) · cisco ios xe (15) · cisco ios (9)
- 58 CVE6 critCVSS 7.1KEV 1Nuclei 2PoC 16opensuse leap (55) · suse linux enterprise server for sap applications (15) · suse linux enterprise desktop (14)
- 51 CVE9 critCVSS 7.2KEV 1Nuclei 4PoC 18fedora (50) · sssd (1)
- 51 CVE1 critCVSS 6.0rational quality manager (10) · rational collaborative lifecycle management (9) · db2 for linux, unix and windows (7)
- 49 CVE10 critCVSS 7.4KEV 4Nuclei 3PoC 18enterprise linux (18) · enterprise linux server (15) · enterprise linux server aus (15)
- 41 CVE11 critCVSS 7.7KEV 2Nuclei 4PoC 4org.jenkins-ci.plugins:azure-vm-agents (3) · org.apache.mesos:mesos (2) · org.jenkins-ci.plugins:script-security (2)
- 40 CVECVSS 6.4graphics driver (19) · converged security management engine firmware (9) · trusted execution engine firmware (6)
- 40 CVECVSS 6.4intel graphics driver (17) · intel converged security and manageability engine (9) · intel trusted execution engine (6)
- 39 CVE4 critCVSS 7.4PoC 13ubuntu linux (39)
- 39 CVE7 critCVSS 7.5PoC 14ubuntu (39)
- 39 CVECVSS 6.2NEWintel(r) graphics driver for windows (19) · intel(r) csme, server platform services, trusted execution engine and intel(r) active management technology (12) · intel platform sample / silicon reference firmware (5)
- 38 CVE7 critCVSS 7.5KEV 1Nuclei 1PoC 11red hat enterprise linux (27) · openshift container platform (8) · red hat software collections (5)
- 31 CVE2 critCVSS 8.1KEV 1PoC 10ios (29) · iphone os (29) · tvos (21)
- 31 CVE7 critCVSS 7.4Nuclei 2PoC 11ontap select deploy administration utility (9) · storage automation store (6) · active iq performance analytics services (5)
- 28 CVE5 critCVSS 7.5KEV 1Nuclei 3PoC 9fedora (28)
- 23 CVECVSS 6.3NEWNuclei 1PoC 2moodle (9) · openwsman (2) · dropbear (1)
- 22 CVE15 critCVSS 9.0NEWultravnc (22)
- 21 CVE15 critCVSS 8.4televisgo (16) · ecostruxure hybrid distributed control system (3) · ecostruxure machine expert (3)
- 20 CVE7 critCVSS 7.8NEWKEV 2PoC 3jenkins azure vm agents plugin (3) · jenkins script security plugin (2) · jenkins pipeline: groovy plugin (2)
- 19 CVE7 critCVSS 7.9NEWKEV 2PoC 3azure vm agents (3) · script security (2) · fortify on demand uploader (2)
- 19 CVE1 critCVSS 6.1Nuclei 1PoC 6moodle/moodle (10) · dolibarr/dolibarr (2) · librenms/librenms (1)
- 18 CVE10 critCVSS 8.5NEWultravnc (16) · invision power board (1) · vanilla forums (1)
- 17 CVE15 critCVSS 9.5NEWultravnc (17)
- 16 CVE9 critCVSS 8.7sinumerik pcu base win10 software\/ipc (13) · sinumerik pcu base win7 software\/ipc (13) · sinumerik access mymachine\/p2p (13)
- 16 CVE3 critCVSS 7.2PoC 6ос он «стрелец» (16)
- 14 CVE2 critCVSS 7.5Nuclei 2apache jspwiki (2) · mesos (2) · jspwiki (2)
- 13 CVECVSS 6.3big-ip access policy manager (11) · big-ip application acceleration manager (10) · big-ip application security manager (10)
- 13 CVE2 critCVSS 7.6PoC 5libredwg (10) · bash (1) · gnutls (1)
- 13 CVE2 critCVSS 7.4Nuclei 4PoC 3peoplesoft enterprise peopletools (3) · oracle communications unified inventory management (2) · java se (2)
- 12 CVECVSS 7.2NEWPoC 4cms made simple (12)
- 12 CVE3 critCVSS 9.6arcsight logger (6) · color laserjet enterprise m651 firmware (1) · color laserjet enterprise m652dn firmware (1)
- 12 CVE4 critCVSS 8.0eds-405a firmware (9) · eds-408a firmware (9) · eds-510a firmware (9)
- 12 CVE1 critCVSS 6.9PoC 2notebook (2) · matrix-synapse (1) · neutron (1)
- 11 CVECVSS 8.3KEV 1PoC 2ios (11) · tvos (10) · icloud (9)
- 11 CVE2 critCVSS 8.3KEV 1Nuclei 1PoC 4crowd (5) · sourcetree (3) · confluence server (2)
- 11 CVE4 critCVSS 8.4NEWmoxa iks, eds (9) · psi gridconnect gmbh (formerly known as psi nentec gmbh) telecontrol gateway and smart telecontrol unit family, iec104 security proxy. (1) · gpsd and microjson (open source project) (1)
- 11 CVE2 critCVSS 7.5NEWserve (2) · highcharts (1) · kill-port (1)
- 11 CVE1 critCVSS 7.8Nuclei 2PoC 2peoplesoft enterprise peopletools (3) · communications lsms (3) · jd edwards enterpriseone tools (2)
- 11 CVECVSS 5.9NEWPoC 6xpdf (11)
- 11 CVE5 critCVSS 8.3NEWPoC 4альт 8 сп (11)
- 10 CVECVSS 5.6Nuclei 1PoC 1moodle (10)
- 10 CVECVSS 7.6NEWPoC 2ofcms (10)
- 10 CVECVSS 5.8PoC 2supportutils (5) · linux enterprise server (1) · backports (1)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | сообщество свободного программного обеспечения | 91 | 17 | 1 | 3 | KEV 1Nuclei 3PoC 31 | debian gnu/linux (81) · rdesktop (9) · libssh2 (9) | — | |
| 2 | ооо «русбитех-астра» | 85 | 6 | 1 | 3 | KEV 1Nuclei 3PoC 24 | astra linux special edition (80) · astra linux special edition для «эльбрус» (50) · astra linux common edition (15) | — | |
| 3 | microsoft | 78 | 3 | 2 | 1 | KEV 2Nuclei 1 | windows (32) · windows server (32) · windows 10 (30) | — | |
| 4 | microsoft corp | 72 | 2 | 2 | 1 | KEV 2Nuclei 1 | windows 10 1709 (29) · windows server 1709 (server core installation) (29) · windows server 1803 (server core installation) (29) | — | |
| 5 | opensuse | 70 | 9 | 1 | 3 | KEV 1Nuclei 3PoC 27 | leap (62) · backports sle (12) · supportutils (5) | — | |
| 6 | debian | 67 | 11 | 1 | 4 | KEV 1Nuclei 4PoC 28 | debian linux (67) · cron (1) | — | |
| 7 | cisco | 64 | 1 | · | 1 | Nuclei 1PoC 63 | nx-os (29) · ios xe (23) · nexus 3000 series switches (21) | — | |
| 8 | cisco systems inc. | 59 | 1 | · | 1 | Nuclei 1PoC 57 | nx-os (21) · cisco ios xe (15) · cisco ios (9) | — | |
| 9 | novell inc. | 58 | 6 | 1 | 2 | KEV 1Nuclei 2PoC 16 | opensuse leap (55) · suse linux enterprise server for sap applications (15) · suse linux enterprise desktop (14) | — | |
| 10 | fedoraproject | 51 | 9 | 1 | 4 | KEV 1Nuclei 4PoC 18 | fedora (50) · sssd (1) | — | |
| 11 | ibm | 51 | 1 | · | · | rational quality manager (10) · rational collaborative lifecycle management (9) · db2 for linux, unix and windows (7) | — | ||
| 12 | redhat | 49 | 10 | 4 | 3 | KEV 4Nuclei 3PoC 18 | enterprise linux (18) · enterprise linux server (15) · enterprise linux server aus (15) | — | |
| 13 | maven | 41 | 11 | 2 | 4 | KEV 2Nuclei 4PoC 4 | org.jenkins-ci.plugins:azure-vm-agents (3) · org.apache.mesos:mesos (2) · org.jenkins-ci.plugins:script-security (2) | — | |
| 14 | intel | 40 | · | · | · | graphics driver (19) · converged security management engine firmware (9) · trusted execution engine firmware (6) | — | ||
| 15 | intel corp. | 40 | · | · | · | intel graphics driver (17) · intel converged security and manageability engine (9) · intel trusted execution engine (6) | — | ||
| 16 | canonical | 39 | 4 | · | · | PoC 13 | ubuntu linux (39) | — | |
| 17 | canonical ltd. | 39 | 7 | · | · | PoC 14 | ubuntu (39) | — | |
| 18 | intel corporation | 39 | · | · | · | NEW | intel(r) graphics driver for windows (19) · intel(r) csme, server platform services, trusted execution engine and intel(r) active management technology (12) · intel platform sample / silicon reference firmware (5) | — | |
| 19 | red hat inc. | 38 | 7 | 1 | 1 | KEV 1Nuclei 1PoC 11 | red hat enterprise linux (27) · openshift container platform (8) · red hat software collections (5) | — | |
| 20 | apple | 31 | 2 | 1 | · | KEV 1PoC 10 | ios (29) · iphone os (29) · tvos (21) | — | |
| 21 | netapp | 31 | 7 | · | 2 | Nuclei 2PoC 11 | ontap select deploy administration utility (9) · storage automation store (6) · active iq performance analytics services (5) | — | |
| 22 | fedora project | 28 | 5 | 1 | 3 | KEV 1Nuclei 3PoC 9 | fedora (28) | — | |
| 23 | [unknown] | 23 | · | · | 1 | NEWNuclei 1PoC 2 | moodle (9) · openwsman (2) · dropbear (1) | — | |
| 24 | uvnc | 22 | 15 | · | · | NEW | ultravnc (22) | — | |
| 25 | schneider electric | 21 | 15 | · | · | televisgo (16) · ecostruxure hybrid distributed control system (3) · ecostruxure machine expert (3) | — | ||
| 26 | jenkins project | 20 | 7 | 2 | · | NEWKEV 2PoC 3 | jenkins azure vm agents plugin (3) · jenkins script security plugin (2) · jenkins pipeline: groovy plugin (2) | — | |
| 27 | jenkins | 19 | 7 | 2 | · | NEWKEV 2PoC 3 | azure vm agents (3) · script security (2) · fortify on demand uploader (2) | — | |
| 28 | packagist | 19 | 1 | · | 1 | Nuclei 1PoC 6 | moodle/moodle (10) · dolibarr/dolibarr (2) · librenms/librenms (1) | — | |
| 29 | kaspersky lab | 18 | 10 | · | · | NEW | ultravnc (16) · invision power board (1) · vanilla forums (1) | — | |
| 30 | team ultravnc | 17 | 15 | · | · | NEW | ultravnc (17) | — | |
| 31 | siemens | 16 | 9 | · | · | sinumerik pcu base win10 software\/ipc (13) · sinumerik pcu base win7 software\/ipc (13) · sinumerik access mymachine\/p2p (13) | — | ||
| 32 | ао «концерн вниинс» | 16 | 3 | · | · | PoC 6 | ос он «стрелец» (16) | — | |
| 33 | apache | 14 | 2 | · | 2 | Nuclei 2 | apache jspwiki (2) · mesos (2) · jspwiki (2) | — | |
| 34 | f5 | 13 | · | · | · | big-ip access policy manager (11) · big-ip application acceleration manager (10) · big-ip application security manager (10) | — | ||
| 35 | gnu | 13 | 2 | · | · | PoC 5 | libredwg (10) · bash (1) · gnutls (1) | — | |
| 36 | oracle corp. | 13 | 2 | · | 4 | Nuclei 4PoC 3 | peoplesoft enterprise peopletools (3) · oracle communications unified inventory management (2) · java se (2) | — | |
| 37 | cmsmadesimple | 12 | · | · | · | NEWPoC 4 | cms made simple (12) | — | |
| 38 | hp | 12 | 3 | · | · | arcsight logger (6) · color laserjet enterprise m651 firmware (1) · color laserjet enterprise m652dn firmware (1) | — | ||
| 39 | moxa | 12 | 4 | · | · | eds-405a firmware (9) · eds-408a firmware (9) · eds-510a firmware (9) | — | ||
| 40 | pypi | 12 | 1 | · | · | PoC 2 | notebook (2) · matrix-synapse (1) · neutron (1) | — | |
| 41 | apple inc. | 11 | · | 1 | · | KEV 1PoC 2 | ios (11) · tvos (10) · icloud (9) | — | |
| 42 | atlassian | 11 | 2 | 1 | 1 | KEV 1Nuclei 1PoC 4 | crowd (5) · sourcetree (3) · confluence server (2) | — | |
| 43 | ics-cert | 11 | 4 | · | · | NEW | moxa iks, eds (9) · psi gridconnect gmbh (formerly known as psi nentec gmbh) telecontrol gateway and smart telecontrol unit family, iec104 security proxy. (1) · gpsd and microjson (open source project) (1) | — | |
| 44 | npm | 11 | 2 | · | · | NEW | serve (2) · highcharts (1) · kill-port (1) | — | |
| 45 | oracle | 11 | 1 | · | 2 | Nuclei 2PoC 2 | peoplesoft enterprise peopletools (3) · communications lsms (3) · jd edwards enterpriseone tools (2) | — | |
| 46 | xpdfreader | 11 | · | · | · | NEWPoC 6 | xpdf (11) | — | |
| 47 | ао «ивк» | 11 | 5 | · | · | NEWPoC 4 | альт 8 сп (11) | — | |
| 48 | moodle | 10 | · | · | 1 | Nuclei 1PoC 1 | moodle (10) | — | |
| 49 | ofcms project | 10 | · | · | · | NEWPoC 2 | ofcms (10) | — | |
| 50 | suse | 10 | · | · | · | PoC 2 | supportutils (5) · linux enterprise server (1) · backports (1) | — |