month report
May 2019
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
May 2019 closed with 1,366 published CVEs. 260 criticals, adobe led volume, mostly via acrobat dc. Top weakness class — CWE-79 (181 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
1,366
— MoM— YoY
Severity mix
260 / 560
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
3.4%
47 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
2488.2
n=47
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
1045
n=14
Detection gap
KEV pressure, no Nuclei coverage
May 2019 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 3microsoft80 CVE
- KEV 2microsoft corp78 CVE
- KEV 1intel corp.32 CVE
- KEV 1siemens ag23 CVE
- KEV 1siemens18 CVE
- KEV 1sierrawireless12 CVE
Weakness × Vendor
What's spreading where in May 2019
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS125Out-of-bounds Read787Out-of-bounds Write416Use After Free20Improper Input Validation22Path Traversal200Information Exposure89SQL Injection78OS Command Injection119Memory Buffer Boundsadobe280366128adobe systems inc.248315626cisco5118632135cisco systems inc.5117622115microsoft721131microsoft corp7213сообщество свободного программного обеспечения37776233ооо «русбитех-астра»25545321schneider electric22311novell inc.55433qualcomm26136schneider-electric22211
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #11qualcomm41 CVE
- #14intel34 CVE
- #23gitlab26 CVE
- #25siemens ag23 CVE
- #32open-xchange20 CVE
- #33zohocorp20 CVE
- #39ооо «доктор веб»16 CVE
- #43jenkins project12 CVE
- #44sierrawireless12 CVE
- #45anker-in11 CVE
Top vendors
Ranked by distinct CVE count this period.
- 207 CVE78 critCVSS 8.4PoC 1acrobat dc (175) · adobe acrobat and reader (175) · acrobat reader dc (175)
- 158 CVE71 critCVSS 8.7PoC 1adobe acrobat document cloud (129) · adobe acrobat reader document cloud (129) · adobe acrobat 2017 (127)
- 98 CVE2 critCVSS 7.3Nuclei 1PoC 98nx-os (38) · cisco nx-os software (32) · firepower threat defense (15)
- 94 CVE2 critCVSS 7.0Nuclei 1PoC 94nx-os (37) · firepower threat defense (16) · adaptive security appliance (13)
- 80 CVE3 critCVSS 7.4KEV 3PoC 3windows server (31) · windows (30) · windows server 2016 (30)
- 78 CVE2 critCVSS 7.5KEV 2PoC 2windows server 2019 (29) · windows 10 1709 (28) · windows 10 1809 (28)
- 65 CVE10 critCVSS 7.2Nuclei 2PoC 21debian gnu/linux (58) · linux (17) · freeimages (2)
- 48 CVE7 critCVSS 7.6Nuclei 1PoC 14astra linux special edition (44) · astra linux special edition для «эльбрус» (10) · astra linux common edition (8)
- 42 CVE8 critCVSS 7.8KEV 1Nuclei 1PoC 12modicon quantum (18) · modicon quantum safety controller (18) · plc simulator (18)
- 41 CVE4 critCVSS 7.7PoC 8opensuse leap (39) · suse linux enterprise module for open buildservice development tools (6) · suse openstack cloud (3)
- 41 CVE12 critCVSS 8.2NEWmdm9607 firmware (38) · mdm9206 firmware (38) · mdm9650 firmware (37)
- 41 CVE8 critCVSS 7.8KEV 1Nuclei 1PoC 11modicon quantum firmware (23) · modicon premium firmware (21) · modicon m580 firmware (20)
- 38 CVE4 critCVSS 7.6Nuclei 1PoC 3leap (38) · backports (16) · backports sle (5)
- 34 CVE2 critCVSS 6.4NEWPoC 3active management technology firmware (4) · graphics driver (4) · converged security management engine firmware (4)
- 34 CVE2 critCVSS 6.5Nuclei 3PoC 6org.jenkins-ci.plugins:artifactory (4) · org.apache.jspwiki:jspwiki-main (3) · org.apache.jspwiki:jspwiki-war (3)
- 32 CVE3 critCVSS 6.5KEV 1PoC 4intel converged security and manageability engine (7) · intel celeron j series (7) · intel celeron n series (7)
- 31 CVE12 critCVSS 8.3snapdragon auto, snapdragon compute, snapdragon consumer iot, snapdragon industrial iot, snapdragon mobile (5) · snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon iot, snapdragon mobile, snapdragon wearables (3) · snapdragon auto, snapdragon compute, snapdragon consumer electronics connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon mobile, snapdragon voice & music, snapdragon wearables (3)
- 30 CVE3 critCVSS 7.6PoC 1chrome (17) · android (12) · api c\+\+ client (1)
- 30 CVE1 critCVSS 5.8spectrum control (4) · spectrum control standard edition (4) · api connect (3)
- 28 CVE5 critCVSS 7.4PoC 10debian linux (28)
- 26 CVE4 critCVSS 7.0Nuclei 1PoC 8fedora (26)
- 26 CVE4 critCVSS 7.3PoC 8fedora (26)
- 26 CVE5 critCVSS 7.0NEWPoC 7gitlab (26)
- 26 CVECVSS 6.4PoC 4remarkable (2) · harp (2) · webpack-bundle-analyzer (1)
- 23 CVE5 critCVSS 6.9NEWKEV 1PoC 7simatic wincc runtime professional (6) · simatic wincc (tia portal) (6) · simatic ipc547g (5)
- 21 CVE4 critCVSS 6.5PoC 6red hat enterprise linux (15) · red hat virtualization (6) · red hat enterprise mrg (4)
- 20 CVE4 critCVSS 7.4PoC 5ubuntu linux (20)
- 20 CVE4 critCVSS 7.5Nuclei 1PoC 9ubuntu (20)
- 20 CVE1 critCVSS 5.7garoon (20)
- 20 CVE1 critCVSS 5.7cybozu garoon (20)
- 20 CVE1 critCVSS 7.5microsoft.chakracore (14) · system.private.uri (2) · microsoft.aspnetcore.signalr.protocols.messagepack (1)
- 20 CVE5 critCVSS 7.3NEWopen-xchange appsuite (19) · ox cloud (1)
- 20 CVE2 critCVSS 6.7NEWPoC 12manageengine netflow analyzer (7) · manageengine applications manager (4) · manageengine opmanager (3)
- 20 CVE3 critCVSS 7.5Nuclei 1PoC 9ос он «стрелец» (20)
- 19 CVE6 critCVSS 6.6PoC 5big-ip policy enforcement manager (10) · big-ip advanced firewall manager (10) · big-ip application acceleration manager (10)
- 18 CVE5 critCVSS 8.0KEV 1PoC 4simatic wincc \(tia portal\) (6) · simatic wincc (4) · simatic pcs 7 (4)
- 17 CVECVSS 7.5PoC 1google chrome (16) · android (1)
- 16 CVE1 critCVSS 6.5PoC 3linux kernel (16)
- 16 CVECVSS 5.0NEWdr.web enterprise security suite (16)
- 15 CVE5 critCVSS 7.9Nuclei 1PoC 11symfony/symfony (6) · symfony/security (2) · drupal/core (2)
- 15 CVE2 critCVSS 6.5PoC 2enterprise linux (8) · enterprise linux server tus (5) · enterprise linux server aus (5)
- 14 CVE2 critCVSS 6.8Nuclei 2PoC 4jspwiki (3) · commons imaging (2) · activemq (2)
- 12 CVE1 critCVSS 6.0NEWjenkins artifactory plugin (4) · jenkins warnings ng plugin (2) · jenkins pam authentication plugin (1)
- 12 CVECVSS 7.9NEWKEV 1PoC 7airlink es450 firmware (11) · aleos (1)
- 11 CVE4 critCVSS 8.6NEWPoC 3roav dashcam a1 firmware (11)
- 11 CVE3 critCVSS 7.0NEWKEV 1Nuclei 2PoC 4zimbra collaboration suite (10) · zimbra collaboration server (1)
- 10 CVE2 critCVSS 8.2NEWsmart home controller firmware (6) · smart home controller (6) · video recording manager (3)
- 10 CVE1 critCVSS 7.7NEWPoC 5computrols building automation software (9) · computrols building automation system (1)
- 10 CVE1 critCVSS 7.2Nuclei 2PoC 6mysql server (2) · enterprise manager base platform (2) · oracle flexcube private banking (2)
- 10 CVE1 critCVSS 6.8NEWNuclei 2PoC 6nas os (10)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | adobe | 207 | 78 | · | · | PoC 1 | acrobat dc (175) · adobe acrobat and reader (175) · acrobat reader dc (175) | — | |
| 2 | adobe systems inc. | 158 | 71 | · | · | PoC 1 | adobe acrobat document cloud (129) · adobe acrobat reader document cloud (129) · adobe acrobat 2017 (127) | — | |
| 3 | cisco | 98 | 2 | · | 1 | Nuclei 1PoC 98 | nx-os (38) · cisco nx-os software (32) · firepower threat defense (15) | — | |
| 4 | cisco systems inc. | 94 | 2 | · | 1 | Nuclei 1PoC 94 | nx-os (37) · firepower threat defense (16) · adaptive security appliance (13) | — | |
| 5 | microsoft | 80 | 3 | 3 | · | KEV 3PoC 3 | windows server (31) · windows (30) · windows server 2016 (30) | — | |
| 6 | microsoft corp | 78 | 2 | 2 | · | KEV 2PoC 2 | windows server 2019 (29) · windows 10 1709 (28) · windows 10 1809 (28) | — | |
| 7 | сообщество свободного программного обеспечения | 65 | 10 | · | 2 | Nuclei 2PoC 21 | debian gnu/linux (58) · linux (17) · freeimages (2) | — | |
| 8 | ооо «русбитех-астра» | 48 | 7 | · | 1 | Nuclei 1PoC 14 | astra linux special edition (44) · astra linux special edition для «эльбрус» (10) · astra linux common edition (8) | — | |
| 9 | schneider electric | 42 | 8 | 1 | 1 | KEV 1Nuclei 1PoC 12 | modicon quantum (18) · modicon quantum safety controller (18) · plc simulator (18) | — | |
| 10 | novell inc. | 41 | 4 | · | · | PoC 8 | opensuse leap (39) · suse linux enterprise module for open buildservice development tools (6) · suse openstack cloud (3) | — | |
| 11 | qualcomm | 41 | 12 | · | · | NEW | mdm9607 firmware (38) · mdm9206 firmware (38) · mdm9650 firmware (37) | — | |
| 12 | schneider-electric | 41 | 8 | 1 | 1 | KEV 1Nuclei 1PoC 11 | modicon quantum firmware (23) · modicon premium firmware (21) · modicon m580 firmware (20) | — | |
| 13 | opensuse | 38 | 4 | · | 1 | Nuclei 1PoC 3 | leap (38) · backports (16) · backports sle (5) | — | |
| 14 | intel | 34 | 2 | · | · | NEWPoC 3 | active management technology firmware (4) · graphics driver (4) · converged security management engine firmware (4) | — | |
| 15 | maven | 34 | 2 | · | 3 | Nuclei 3PoC 6 | org.jenkins-ci.plugins:artifactory (4) · org.apache.jspwiki:jspwiki-main (3) · org.apache.jspwiki:jspwiki-war (3) | — | |
| 16 | intel corp. | 32 | 3 | 1 | · | KEV 1PoC 4 | intel converged security and manageability engine (7) · intel celeron j series (7) · intel celeron n series (7) | — | |
| 17 | qualcomm, inc. | 31 | 12 | · | · | snapdragon auto, snapdragon compute, snapdragon consumer iot, snapdragon industrial iot, snapdragon mobile (5) · snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon iot, snapdragon mobile, snapdragon wearables (3) · snapdragon auto, snapdragon compute, snapdragon consumer electronics connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon mobile, snapdragon voice & music, snapdragon wearables (3) | — | ||
| 18 | 30 | 3 | · | · | PoC 1 | chrome (17) · android (12) · api c\+\+ client (1) | — | ||
| 19 | ibm | 30 | 1 | · | · | spectrum control (4) · spectrum control standard edition (4) · api connect (3) | — | ||
| 20 | debian | 28 | 5 | · | · | PoC 10 | debian linux (28) | — | |
| 21 | fedora project | 26 | 4 | · | 1 | Nuclei 1PoC 8 | fedora (26) | — | |
| 22 | fedoraproject | 26 | 4 | · | · | PoC 8 | fedora (26) | — | |
| 23 | gitlab | 26 | 5 | · | · | NEWPoC 7 | gitlab (26) | — | |
| 24 | npm | 26 | · | · | · | PoC 4 | remarkable (2) · harp (2) · webpack-bundle-analyzer (1) | — | |
| 25 | siemens ag | 23 | 5 | 1 | · | NEWKEV 1PoC 7 | simatic wincc runtime professional (6) · simatic wincc (tia portal) (6) · simatic ipc547g (5) | — | |
| 26 | red hat inc. | 21 | 4 | · | · | PoC 6 | red hat enterprise linux (15) · red hat virtualization (6) · red hat enterprise mrg (4) | — | |
| 27 | canonical | 20 | 4 | · | · | PoC 5 | ubuntu linux (20) | — | |
| 28 | canonical ltd. | 20 | 4 | · | 1 | Nuclei 1PoC 9 | ubuntu (20) | — | |
| 29 | cybozu | 20 | 1 | · | · | garoon (20) | — | ||
| 30 | cybozu, inc. | 20 | 1 | · | · | cybozu garoon (20) | — | ||
| 31 | nuget | 20 | 1 | · | · | microsoft.chakracore (14) · system.private.uri (2) · microsoft.aspnetcore.signalr.protocols.messagepack (1) | — | ||
| 32 | open-xchange | 20 | 5 | · | · | NEW | open-xchange appsuite (19) · ox cloud (1) | — | |
| 33 | zohocorp | 20 | 2 | · | · | NEWPoC 12 | manageengine netflow analyzer (7) · manageengine applications manager (4) · manageengine opmanager (3) | — | |
| 34 | ао «концерн вниинс» | 20 | 3 | · | 1 | Nuclei 1PoC 9 | ос он «стрелец» (20) | — | |
| 35 | f5 | 19 | 6 | · | · | PoC 5 | big-ip policy enforcement manager (10) · big-ip advanced firewall manager (10) · big-ip application acceleration manager (10) | — | |
| 36 | siemens | 18 | 5 | 1 | · | KEV 1PoC 4 | simatic wincc \(tia portal\) (6) · simatic wincc (4) · simatic pcs 7 (4) | — | |
| 37 | google inc | 17 | · | · | · | PoC 1 | google chrome (16) · android (1) | — | |
| 38 | linux | 16 | 1 | · | · | PoC 3 | linux kernel (16) | — | |
| 39 | ооо «доктор веб» | 16 | · | · | · | NEW | dr.web enterprise security suite (16) | — | |
| 40 | packagist | 15 | 5 | · | 1 | Nuclei 1PoC 11 | symfony/symfony (6) · symfony/security (2) · drupal/core (2) | — | |
| 41 | redhat | 15 | 2 | · | · | PoC 2 | enterprise linux (8) · enterprise linux server tus (5) · enterprise linux server aus (5) | — | |
| 42 | apache | 14 | 2 | · | 2 | Nuclei 2PoC 4 | jspwiki (3) · commons imaging (2) · activemq (2) | — | |
| 43 | jenkins project | 12 | 1 | · | · | NEW | jenkins artifactory plugin (4) · jenkins warnings ng plugin (2) · jenkins pam authentication plugin (1) | — | |
| 44 | sierrawireless | 12 | · | 1 | · | NEWKEV 1PoC 7 | airlink es450 firmware (11) · aleos (1) | — | |
| 45 | anker-in | 11 | 4 | · | · | NEWPoC 3 | roav dashcam a1 firmware (11) | — | |
| 46 | synacor | 11 | 3 | 1 | 2 | NEWKEV 1Nuclei 2PoC 4 | zimbra collaboration suite (10) · zimbra collaboration server (1) | — | |
| 47 | bosch | 10 | 2 | · | · | NEW | smart home controller firmware (6) · smart home controller (6) · video recording manager (3) | — | |
| 48 | computrols | 10 | 1 | · | · | NEWPoC 5 | computrols building automation software (9) · computrols building automation system (1) | — | |
| 49 | oracle corp. | 10 | 1 | · | 2 | Nuclei 2PoC 6 | mysql server (2) · enterprise manager base platform (2) · oracle flexcube private banking (2) | — | |
| 50 | seagate | 10 | 1 | · | 2 | NEWNuclei 2PoC 6 | nas os (10) | — |