month report
January 2021
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
January 2021 closed with 1,970 published CVEs. 202 criticals, oracle led volume, mostly via mysql. Top weakness class — CWE-79 (190 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
1,970
— MoM— YoY
Severity mix
202 / 695
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
4.6%
90 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
1881.6
n=90
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
361
n=9
Detection gap
KEV pressure, no Nuclei coverage
January 2021 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 3google77 CVE
- KEV 3google inc46 CVE
- KEV 2novell inc.43 CVE
- KEV 1microsoft84 CVE
- KEV 1microsoft corp84 CVE
Weakness × Vendor
What's spreading where in January 2021
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS787Out-of-bounds Write121CWE-12120Improper Input Validation269Improper Privilege Mgmt22Path Traversal125Out-of-bounds Read502Deserialization78OS Command Injection89SQL Injectionoracle21312cisco1861612612127cisco systems inc.1861612612127oracle corp.1oracle corporationсообщество свободного программного обеспечения31815138121ао "нппкт"221413812ао «концерн вниинс»22241811ооо «русбитех-астра»21641381ibm172141microsoft13311microsoft corp1331
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #20google inc46 CVE
- #24crates.io34 CVE
- #28ао «нтц ит роса»32 CVE
- #32nvidia21 CVE
- #36juniper networks19 CVE
- #39hpe16 CVE
- #47k7computing13 CVE
- #48quest13 CVE
- #49fasterxml12 CVE
- #50fasterxml, llc12 CVE
Top vendors
Ranked by distinct CVE count this period.
- 169 CVE11 critCVSS 7.6KEV 1Nuclei 8PoC 9mysql (38) · vm virtualbox (17) · agile plm (14)
- 156 CVE10 critCVSS 7.0PoC 155cisco small business rv series router firmware (74) · rv130w firmware (73) · rv110w firmware (73)
- 155 CVE10 critCVSS 7.0PoC 155cisco rv130 (74) · cisco rv110w (66) · cisco rv215w (66)
- 144 CVE10 critCVSS 6.5Nuclei 6PoC 1mysql server (34) · vm virtualbox (17) · weblogic server (9)
- 136 CVE9 critCVSS 6.5Nuclei 6PoC 1mysql server (38) · vm virtualbox (17) · weblogic server (9)
- 120 CVE15 critCVSS 7.2KEV 4Nuclei 1PoC 22debian gnu/linux (108) · linux (7) · openjpeg (6)
- 112 CVE14 critCVSS 7.5KEV 4Nuclei 1PoC 27осон основа оnyx (112)
- 99 CVE14 critCVSS 7.6KEV 4Nuclei 1PoC 19ос он «стрелец» (99)
- 96 CVE14 critCVSS 6.8KEV 4Nuclei 1PoC 15astra linux special edition (91) · astra linux special edition для «эльбрус» (34) · astra linux common edition (22)
- 84 CVE4 critCVSS 5.6rational engineering lifecycle manager (10) · rational collaborative lifecycle management (10) · collaborative lifecycle management (10)
- 84 CVECVSS 7.5KEV 1PoC 2windows 10 (63) · windows 10 version 2004 (63) · windows 10 version 1909 (60)
- 84 CVECVSS 7.5KEV 1PoC 1windows 10 2004 (62) · windows 10 20h2 (62) · windows 10 1909 (59)
- 82 CVE9 critCVSS 7.4KEV 2Nuclei 2PoC 15debian linux (82)
- 77 CVE16 critCVSS 7.8KEV 3PoC 9chrome (46) · android (29) · secret manager provider for secret store csi driver (1)
- 76 CVE11 critCVSS 7.6KEV 1Nuclei 1PoC 14альт 8 сп (71) · альт 8 сп сервер (3) · альт сп 10 (2)
- 72 CVE9 critCVSS 6.6KEV 2Nuclei 1PoC 10fedora (72) · extra packages for enterprise linux (1)
- 72 CVE4 critCVSS 5.8KEV 1Nuclei 2PoC 7oncommand workflow automation (40) · oncommand insight (39) · snapcenter (35)
- 52 CVE6 critCVSS 7.3KEV 1Nuclei 5PoC 9com.fasterxml.jackson.core:jackson-databind (12) · org.jenkins-ci.main:jenkins-core (11) · com.mikesamuel:json-sanitizer (2)
- 48 CVE8 critCVSS 6.9KEV 3Nuclei 1PoC 7red hat enterprise linux (47) · red hat software collections (11) · red hat openstack platform (3)
- 46 CVE13 critCVSS 8.2NEWKEV 3PoC 6google chrome (45) · android (1)
- 43 CVE8 critCVSS 8.1KEV 2PoC 6opensuse leap (43) · suse linux enterprise server (5) · suse linux enterprise server for sap applications (5)
- 36 CVE4 critCVSS 7.0Nuclei 2PoC 4jointjs (2) · asciitable.js (1) · async-git (1)
- 36 CVE2 critCVSS 8.0teamcenter visualization (24) · jt2go (24) · solid edge se2021 (6)
- 34 CVE4 critCVSS 7.0NEWPoC 9raw-cpuid (2) · abi_stable (2) · late-static (1)
- 34 CVE15 critCVSS 8.7qet5100 (31) · wcd9341 (31) · wcn3980 (30)
- 34 CVE15 critCVSS 8.3snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon iot, snapdragon mobile, snapdragon voice & music, snapdragon wearables, snapdragon wired infrastructure and networking (9) · snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon mobile, snapdragon voice & music, snapdragon wearables (7) · snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer electronics connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon mobile, snapdragon voice & music, snapdragon wired infrastructure and networking (3)
- 32 CVE7 critCVSS 8.0KEV 3Nuclei 1PoC 8ubuntu (32)
- 32 CVE1 critCVSS 7.7NEWKEV 1Nuclei 1PoC 7rosa virtualization (13) · роса хром (13) · роса кобальт (11)
- 30 CVE6 critCVSS 7.0KEV 2Nuclei 4PoC 10moodle/moodle (5) · mautic/core (4) · wp-premium/gravityforms (3)
- 27 CVE1 critCVSS 7.8PoC 33d visual enterprise viewer (16) · business warehouse (3) · bw\/4hana (1)
- 27 CVE1 critCVSS 7.7PoC 3sap 3d visual enterprise viewer (16) · sap business warehouse (3) · sap businessobjects business intelligence platform (web intelligence html interface) (1)
- 21 CVECVSS 6.8NEWvirtual gpu manager (10) · nvidia virtual gpu manager (8) · nvidia gpu display driver (6)
- 20 CVE1 critCVSS 7.0KEV 1Nuclei 1PoC 1ред ос (20)
- 19 CVE3 critCVSS 7.7KEV 1Nuclei 4PoC 2activemq artemis (2) · traffic server (2) · flink (2)
- 19 CVE1 critCVSS 7.5PoC 18junos (16) · junos os evolved (3) · junos space (1)
- 19 CVE1 critCVSS 7.5NEWPoC 18junos os (16) · junos os evolved (3) · junos space (1)
- 18 CVE4 critCVSS 7.4emc powerstore firmware (3) · emc unity operating environment (3) · emc unity vsa operating environment (3)
- 18 CVE1 critCVSS 7.3PoC 17junos (16) · contrail networking (1) · junos os evolved (1)
- 16 CVECVSS 7.8NEWcloudline cl4100 gen10 server firmware (16) · cloudline cl3100 gen10 server firmware (16) · cloudline cl5200 gen9 server firmware (16)
- 15 CVE2 critCVSS 7.2PoC 2pillow (3) · pysaml2 (2) · crmsh (1)
- 14 CVECVSS 6.0jenkins (11) · tracetronic ecu-test (1) · bumblebee hp alm (1)
- 14 CVECVSS 6.0jenkins (11) · jenkins bumblebee hp alm plugin (1) · jenkins tics plugin (1)
- 14 CVE1 critCVSS 7.6PoC 2firefox (14) · firefox esr (7) · thunderbird (7)
- 13 CVE3 critCVSS 8.0KEV 1Nuclei 4PoC 2traffic server (2) · apache flink (2) · apache dolphinscheduler (1)
- 13 CVE1 critCVSS 7.7KEV 1Nuclei 1PoC 5fedora (13)
- 13 CVECVSS 6.3PoC 2github.com/tidwall/gjson (2) · github.com/deislabs/oras (1) · github.com/gin-gonic/gin (1)
- 13 CVECVSS 7.1NEWtotal security (13) · antivrius (13) · enterprise security (13)
- 13 CVE1 critCVSS 6.1NEWPoC 8policy authority for unified communications (13)
- 12 CVECVSS 8.1NEWPoC 5jackson-databind (12)
- 12 CVECVSS 8.1NEWPoC 5jackson-databind (12)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | oracle | 169 | 11 | 1 | 8 | KEV 1Nuclei 8PoC 9 | mysql (38) · vm virtualbox (17) · agile plm (14) | — | |
| 2 | cisco | 156 | 10 | · | · | PoC 155 | cisco small business rv series router firmware (74) · rv130w firmware (73) · rv110w firmware (73) | — | |
| 3 | cisco systems inc. | 155 | 10 | · | · | PoC 155 | cisco rv130 (74) · cisco rv110w (66) · cisco rv215w (66) | — | |
| 4 | oracle corp. | 144 | 10 | · | 6 | Nuclei 6PoC 1 | mysql server (34) · vm virtualbox (17) · weblogic server (9) | — | |
| 5 | oracle corporation | 136 | 9 | · | 6 | Nuclei 6PoC 1 | mysql server (38) · vm virtualbox (17) · weblogic server (9) | — | |
| 6 | сообщество свободного программного обеспечения | 120 | 15 | 4 | 1 | KEV 4Nuclei 1PoC 22 | debian gnu/linux (108) · linux (7) · openjpeg (6) | — | |
| 7 | ао "нппкт" | 112 | 14 | 4 | 1 | KEV 4Nuclei 1PoC 27 | осон основа оnyx (112) | — | |
| 8 | ао «концерн вниинс» | 99 | 14 | 4 | 1 | KEV 4Nuclei 1PoC 19 | ос он «стрелец» (99) | — | |
| 9 | ооо «русбитех-астра» | 96 | 14 | 4 | 1 | KEV 4Nuclei 1PoC 15 | astra linux special edition (91) · astra linux special edition для «эльбрус» (34) · astra linux common edition (22) | — | |
| 10 | ibm | 84 | 4 | · | · | rational engineering lifecycle manager (10) · rational collaborative lifecycle management (10) · collaborative lifecycle management (10) | — | ||
| 11 | microsoft | 84 | · | 1 | · | KEV 1PoC 2 | windows 10 (63) · windows 10 version 2004 (63) · windows 10 version 1909 (60) | — | |
| 12 | microsoft corp | 84 | · | 1 | · | KEV 1PoC 1 | windows 10 2004 (62) · windows 10 20h2 (62) · windows 10 1909 (59) | — | |
| 13 | debian | 82 | 9 | 2 | 2 | KEV 2Nuclei 2PoC 15 | debian linux (82) | — | |
| 14 | 77 | 16 | 3 | · | KEV 3PoC 9 | chrome (46) · android (29) · secret manager provider for secret store csi driver (1) | — | ||
| 15 | ао «ивк» | 76 | 11 | 1 | 1 | KEV 1Nuclei 1PoC 14 | альт 8 сп (71) · альт 8 сп сервер (3) · альт сп 10 (2) | — | |
| 16 | fedoraproject | 72 | 9 | 2 | 1 | KEV 2Nuclei 1PoC 10 | fedora (72) · extra packages for enterprise linux (1) | — | |
| 17 | netapp | 72 | 4 | 1 | 2 | KEV 1Nuclei 2PoC 7 | oncommand workflow automation (40) · oncommand insight (39) · snapcenter (35) | — | |
| 18 | maven | 52 | 6 | 1 | 5 | KEV 1Nuclei 5PoC 9 | com.fasterxml.jackson.core:jackson-databind (12) · org.jenkins-ci.main:jenkins-core (11) · com.mikesamuel:json-sanitizer (2) | — | |
| 19 | red hat inc. | 48 | 8 | 3 | 1 | KEV 3Nuclei 1PoC 7 | red hat enterprise linux (47) · red hat software collections (11) · red hat openstack platform (3) | — | |
| 20 | google inc | 46 | 13 | 3 | · | NEWKEV 3PoC 6 | google chrome (45) · android (1) | — | |
| 21 | novell inc. | 43 | 8 | 2 | · | KEV 2PoC 6 | opensuse leap (43) · suse linux enterprise server (5) · suse linux enterprise server for sap applications (5) | — | |
| 22 | npm | 36 | 4 | · | 2 | Nuclei 2PoC 4 | jointjs (2) · asciitable.js (1) · async-git (1) | — | |
| 23 | siemens | 36 | 2 | · | · | teamcenter visualization (24) · jt2go (24) · solid edge se2021 (6) | — | ||
| 24 | crates.io | 34 | 4 | · | · | NEWPoC 9 | raw-cpuid (2) · abi_stable (2) · late-static (1) | — | |
| 25 | qualcomm | 34 | 15 | · | · | qet5100 (31) · wcd9341 (31) · wcn3980 (30) | — | ||
| 26 | qualcomm, inc. | 34 | 15 | · | · | snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon iot, snapdragon mobile, snapdragon voice & music, snapdragon wearables, snapdragon wired infrastructure and networking (9) · snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon mobile, snapdragon voice & music, snapdragon wearables (7) · snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer electronics connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon mobile, snapdragon voice & music, snapdragon wired infrastructure and networking (3) | — | ||
| 27 | canonical ltd. | 32 | 7 | 3 | 1 | KEV 3Nuclei 1PoC 8 | ubuntu (32) | — | |
| 28 | ао «нтц ит роса» | 32 | 1 | 1 | 1 | NEWKEV 1Nuclei 1PoC 7 | rosa virtualization (13) · роса хром (13) · роса кобальт (11) | — | |
| 29 | packagist | 30 | 6 | 2 | 4 | KEV 2Nuclei 4PoC 10 | moodle/moodle (5) · mautic/core (4) · wp-premium/gravityforms (3) | — | |
| 30 | sap | 27 | 1 | · | · | PoC 3 | 3d visual enterprise viewer (16) · business warehouse (3) · bw\/4hana (1) | — | |
| 31 | sap se | 27 | 1 | · | · | PoC 3 | sap 3d visual enterprise viewer (16) · sap business warehouse (3) · sap businessobjects business intelligence platform (web intelligence html interface) (1) | — | |
| 32 | nvidia | 21 | · | · | · | NEW | virtual gpu manager (10) · nvidia virtual gpu manager (8) · nvidia gpu display driver (6) | — | |
| 33 | ооо «ред софт» | 20 | 1 | 1 | 1 | KEV 1Nuclei 1PoC 1 | ред ос (20) | — | |
| 34 | apache | 19 | 3 | 1 | 4 | KEV 1Nuclei 4PoC 2 | activemq artemis (2) · traffic server (2) · flink (2) | — | |
| 35 | juniper | 19 | 1 | · | · | PoC 18 | junos (16) · junos os evolved (3) · junos space (1) | — | |
| 36 | juniper networks | 19 | 1 | · | · | NEWPoC 18 | junos os (16) · junos os evolved (3) · junos space (1) | — | |
| 37 | dell | 18 | 4 | · | · | emc powerstore firmware (3) · emc unity operating environment (3) · emc unity vsa operating environment (3) | — | ||
| 38 | juniper networks inc. | 18 | 1 | · | · | PoC 17 | junos (16) · contrail networking (1) · junos os evolved (1) | — | |
| 39 | hpe | 16 | · | · | · | NEW | cloudline cl4100 gen10 server firmware (16) · cloudline cl3100 gen10 server firmware (16) · cloudline cl5200 gen9 server firmware (16) | — | |
| 40 | pypi | 15 | 2 | · | · | PoC 2 | pillow (3) · pysaml2 (2) · crmsh (1) | — | |
| 41 | jenkins | 14 | · | · | · | jenkins (11) · tracetronic ecu-test (1) · bumblebee hp alm (1) | — | ||
| 42 | jenkins project | 14 | · | · | · | jenkins (11) · jenkins bumblebee hp alm plugin (1) · jenkins tics plugin (1) | — | ||
| 43 | mozilla | 14 | 1 | · | · | PoC 2 | firefox (14) · firefox esr (7) · thunderbird (7) | — | |
| 44 | apache software foundation | 13 | 3 | 1 | 4 | KEV 1Nuclei 4PoC 2 | traffic server (2) · apache flink (2) · apache dolphinscheduler (1) | — | |
| 45 | fedora project | 13 | 1 | 1 | 1 | KEV 1Nuclei 1PoC 5 | fedora (13) | — | |
| 46 | go | 13 | · | · | · | PoC 2 | github.com/tidwall/gjson (2) · github.com/deislabs/oras (1) · github.com/gin-gonic/gin (1) | — | |
| 47 | k7computing | 13 | · | · | · | NEW | total security (13) · antivrius (13) · enterprise security (13) | — | |
| 48 | quest | 13 | 1 | · | · | NEWPoC 8 | policy authority for unified communications (13) | — | |
| 49 | fasterxml | 12 | · | · | · | NEWPoC 5 | jackson-databind (12) | — | |
| 50 | fasterxml, llc | 12 | · | · | · | NEWPoC 5 | jackson-databind (12) | — |