month report
April 2021
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
April 2021 closed with 1,970 published CVEs. 228 criticals, oracle led volume, mostly via mysql. Top weakness class — CWE-79 (198 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
1,970
— MoM— YoY
Severity mix
228 / 792
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
8.2%
161 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
1789.3
n=161
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
208
n=18
Detection gap
KEV pressure, no Nuclei coverage
April 2021 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 5apple130 CVE
- KEV 3fedora project30 CVE
- KEV 2red hat inc.31 CVE
- KEV 1canonical ltd.25 CVE
- KEV 1novell inc.19 CVE
Weakness × Vendor
What's spreading where in April 2021
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS787Out-of-bounds Write125Out-of-bounds Read120Buffer Overflow89SQL Injection78OS Command Injection20Improper Input Validation22Path Traversal200Information Exposure352CSRForacle1113oracle corp.12oracle corporation1сообщество свободного программного обеспечения4181131723microsoft corp1614apple2332822fedoraproject212721513debian51362623ооо «русбитех-астра»21582522microsoft121ао "нппкт"21171524ао «ивк»46151
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #6apple130 CVE
- #15unknown66 CVE
- #18juniper networks53 CVE
- #23google inc41 CVE
- #24asus38 CVE
- #31gpac25 CVE
- #34arubanetworks21 CVE
- #35dell21 CVE
- #36samsung mobile20 CVE
- #37crates.io19 CVE
Top vendors
Ranked by distinct CVE count this period.
- 191 CVE16 critCVSS 6.2Nuclei 12PoC 7mysql (39) · vm virtualbox (21) · istore (11)
- 183 CVE15 critCVSS 6.5Nuclei 12PoC 6mysql server (39) · e-business suite (28) · vm virtualbox (21)
- 179 CVE15 critCVSS 6.7Nuclei 10PoC 3mysql server (39) · vm virtualbox (21) · istore (11)
- 144 CVE17 critCVSS 7.1KEV 8Nuclei 3PoC 23debian gnu/linux (133) · linux (14) · mediawiki (6)
- 136 CVE5 critCVSS 7.6KEV 2Nuclei 3PoC 7windows 10 2004 (78) · windows server 2004 (server core installation) (78) · windows 10 20h2 (78)
- 130 CVE6 critCVSS 7.3NEWKEV 5PoC 1macos (119) · mac os x (102) · iphone os (89)
- 124 CVE8 critCVSS 6.7KEV 7Nuclei 1PoC 18fedora (124)
- 116 CVE17 critCVSS 7.2KEV 3Nuclei 4PoC 17debian linux (116)
- 111 CVE15 critCVSS 7.1KEV 5Nuclei 1PoC 20astra linux special edition (108) · astra linux special edition для «эльбрус» (32) · astra linux common edition (4)
- 109 CVE3 critCVSS 7.6KEV 1Nuclei 2PoC 7windows server version 20h2 (79) · windows server version 2004 (79) · windows 10 version 2004 (79)
- 91 CVE5 critCVSS 6.9KEV 4Nuclei 3PoC 18осон основа оnyx (91)
- 86 CVE1 critCVSS 6.0PoC 6альт 8 сп (86) · альт сп 10 (1)
- 78 CVE8 critCVSS 7.1KEV 2Nuclei 1PoC 10ос он «стрелец» (78)
- 76 CVE5 critCVSS 7.5KEV 3Nuclei 1PoC 5chrome (39) · android (35) · bazel (1)
- 66 CVE9 critCVSS 6.8NEWNuclei 66PoC 27elementor website builder (6) · tutor lms – elearning and online course solution (6) · patreon wordpress (5)
- 55 CVECVSS 5.6Nuclei 2PoC 6active iq unified manager (46) · snapcenter (42) · oncommand workflow automation (39)
- 53 CVE2 critCVSS 7.0PoC 52junos (48) · junos os evolved (8) · appformix (1)
- 53 CVE2 critCVSS 7.0NEWPoC 52junos os (48) · junos os evolved (8) · paragon active assurance (1)
- 53 CVE6 critCVSS 6.2Nuclei 7PoC 4com.vaadin:vaadin-bom (12) · com.vaadin:flow-server (7) · org.jenkins-ci.plugins:hp-application-automation-tools-plugin (4)
- 46 CVE1 critCVSS 6.8Nuclei 2PoC 42firepower threat defense (10) · cisco small business rv series router firmware (9) · rv340 firmware (8)
- 46 CVE8 critCVSS 7.2Nuclei 4PoC 14postcss (2) · @azure/ms-rest-nodeauth (1) · backbone-query-parameters (1)
- 43 CVE1 critCVSS 6.8Nuclei 2PoC 42firepower threat defense (10) · cisco rv340w (8) · cisco rv345 (8)
- 41 CVE4 critCVSS 7.8NEWKEV 3Nuclei 1PoC 3google chrome (39) · android studio (2)
- 38 CVECVSS 5.0NEWz10pr-d16 firmware (18) · bmc firmware for z10pr-d16 (18) · bmc firmware for asmb8-ikvm (18)
- 31 CVE6 critCVSS 7.1KEV 2PoC 5red hat enterprise linux (27) · ansible (2) · red hat ceph storage (1)
- 30 CVE2 critCVSS 6.0KEV 3PoC 6fedora (30)
- 27 CVECVSS 5.9collaborative lifecycle management (4) · doors next (4) · engineering insights (4)
- 27 CVE1 critCVSS 6.5PoC 1matrix-sydent (4) · matrix-synapse (3) · vyper (2)
- 27 CVE4 critCVSS 8.4PoC 3nucleus net (9) · nucleus source code (9) · nucleus readystart v3 (7)
- 25 CVE5 critCVSS 7.2KEV 1PoC 4ubuntu (25)
- 25 CVE1 critCVSS 6.4NEWPoC 10gpac (25)
- 25 CVE5 critCVSS 7.1Nuclei 1PoC 11tribalsystems/zenario (3) · openmage/magento-lts (2) · shopware/core (2)
- 22 CVE1 critCVSS 6.3PoC 7ред ос (22)
- 21 CVE1 critCVSS 7.4NEWairwave (11) · clearpass (9) · clearpass policy manager (1)
- 21 CVE1 critCVSS 6.8NEWintegrated dell remote access controller (idrac) (6) · idrac9 firmware (6) · dell hybrid client (dhc) (4)
- 20 CVE1 critCVSS 5.7NEWPoC 1samsung mobile devices (11) · samsung email (2) · customization service (1)
- 19 CVE7 critCVSS 8.3NEWPoC 4id-map (3) · arenavec (2) · reorder (2)
- 19 CVECVSS 7.6KEV 1PoC 5opensuse leap (16) · suse linux enterprise server (9) · suse linux enterprise server for sap applications (7)
- 19 CVECVSS 7.0NEWdesktop (19) · parallels desktop (19)
- 18 CVECVSS 5.3PoC 2mediawiki (18)
- 16 CVECVSS 7.0Nuclei 1bridge (6) · gocart (3) · genuine service (3)
- 15 CVE6 critCVSS 7.5Nuclei 4PoC 2solr (4) · ofbiz (2) · tapestry (2)
- 15 CVECVSS 6.3Nuclei 1github.com/pomerium/pomerium (2) · github.com/cortexproject/cortex (1) · github.com/filecoin-project/lotus (1)
- 15 CVE1 critCVSS 8.0wcn3998 firmware (14) · wsa8815 firmware (14) · wcd9341 firmware (14)
- 15 CVE1 critCVSS 8.1snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon mobile (3) · snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon iot, snapdragon mobile, snapdragon voice & music, snapdragon wearables (2) · snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon iot, snapdragon mobile, snapdragon wearables (1)
- 14 CVECVSS 7.0Nuclei 1adobe bridge (6) · adobe genuine service (3) · photoshop 2020 (2)
- 14 CVECVSS 7.0NEWnvidia virtual gpu software (8) · virtual gpu manager (8) · gpu display driver (5)
- 14 CVECVSS 6.4PoC 2enterprise linux (10) · ansible tower (2) · ansible engine (1)
- 14 CVE1 critCVSS 6.3netweaver application server java (4) · netweaver process integration (2) · focused run (1)
- 14 CVE1 critCVSS 6.3sap commerce (1) · sap fiori apps 2.0 for travel management in sap erp (1) · sap focused run (1)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | oracle | 191 | 16 | · | 12 | Nuclei 12PoC 7 | mysql (39) · vm virtualbox (21) · istore (11) | — | |
| 2 | oracle corp. | 183 | 15 | · | 12 | Nuclei 12PoC 6 | mysql server (39) · e-business suite (28) · vm virtualbox (21) | — | |
| 3 | oracle corporation | 179 | 15 | · | 10 | Nuclei 10PoC 3 | mysql server (39) · vm virtualbox (21) · istore (11) | — | |
| 4 | сообщество свободного программного обеспечения | 144 | 17 | 8 | 3 | KEV 8Nuclei 3PoC 23 | debian gnu/linux (133) · linux (14) · mediawiki (6) | — | |
| 5 | microsoft corp | 136 | 5 | 2 | 3 | KEV 2Nuclei 3PoC 7 | windows 10 2004 (78) · windows server 2004 (server core installation) (78) · windows 10 20h2 (78) | — | |
| 6 | apple | 130 | 6 | 5 | · | NEWKEV 5PoC 1 | macos (119) · mac os x (102) · iphone os (89) | — | |
| 7 | fedoraproject | 124 | 8 | 7 | 1 | KEV 7Nuclei 1PoC 18 | fedora (124) | — | |
| 8 | debian | 116 | 17 | 3 | 4 | KEV 3Nuclei 4PoC 17 | debian linux (116) | — | |
| 9 | ооо «русбитех-астра» | 111 | 15 | 5 | 1 | KEV 5Nuclei 1PoC 20 | astra linux special edition (108) · astra linux special edition для «эльбрус» (32) · astra linux common edition (4) | — | |
| 10 | microsoft | 109 | 3 | 1 | 2 | KEV 1Nuclei 2PoC 7 | windows server version 20h2 (79) · windows server version 2004 (79) · windows 10 version 2004 (79) | — | |
| 11 | ао "нппкт" | 91 | 5 | 4 | 3 | KEV 4Nuclei 3PoC 18 | осон основа оnyx (91) | — | |
| 12 | ао «ивк» | 86 | 1 | · | · | PoC 6 | альт 8 сп (86) · альт сп 10 (1) | — | |
| 13 | ао «концерн вниинс» | 78 | 8 | 2 | 1 | KEV 2Nuclei 1PoC 10 | ос он «стрелец» (78) | — | |
| 14 | 76 | 5 | 3 | 1 | KEV 3Nuclei 1PoC 5 | chrome (39) · android (35) · bazel (1) | — | ||
| 15 | unknown | 66 | 9 | · | 66 | NEWNuclei 66PoC 27 | elementor website builder (6) · tutor lms – elearning and online course solution (6) · patreon wordpress (5) | — | |
| 16 | netapp | 55 | · | · | 2 | Nuclei 2PoC 6 | active iq unified manager (46) · snapcenter (42) · oncommand workflow automation (39) | — | |
| 17 | juniper | 53 | 2 | · | · | PoC 52 | junos (48) · junos os evolved (8) · appformix (1) | — | |
| 18 | juniper networks | 53 | 2 | · | · | NEWPoC 52 | junos os (48) · junos os evolved (8) · paragon active assurance (1) | — | |
| 19 | maven | 53 | 6 | · | 7 | Nuclei 7PoC 4 | com.vaadin:vaadin-bom (12) · com.vaadin:flow-server (7) · org.jenkins-ci.plugins:hp-application-automation-tools-plugin (4) | — | |
| 20 | cisco | 46 | 1 | · | 2 | Nuclei 2PoC 42 | firepower threat defense (10) · cisco small business rv series router firmware (9) · rv340 firmware (8) | — | |
| 21 | npm | 46 | 8 | · | 4 | Nuclei 4PoC 14 | postcss (2) · @azure/ms-rest-nodeauth (1) · backbone-query-parameters (1) | — | |
| 22 | cisco systems inc. | 43 | 1 | · | 2 | Nuclei 2PoC 42 | firepower threat defense (10) · cisco rv340w (8) · cisco rv345 (8) | — | |
| 23 | google inc | 41 | 4 | 3 | 1 | NEWKEV 3Nuclei 1PoC 3 | google chrome (39) · android studio (2) | — | |
| 24 | asus | 38 | · | · | · | NEW | z10pr-d16 firmware (18) · bmc firmware for z10pr-d16 (18) · bmc firmware for asmb8-ikvm (18) | — | |
| 25 | red hat inc. | 31 | 6 | 2 | · | KEV 2PoC 5 | red hat enterprise linux (27) · ansible (2) · red hat ceph storage (1) | — | |
| 26 | fedora project | 30 | 2 | 3 | · | KEV 3PoC 6 | fedora (30) | — | |
| 27 | ibm | 27 | · | · | · | collaborative lifecycle management (4) · doors next (4) · engineering insights (4) | — | ||
| 28 | pypi | 27 | 1 | · | · | PoC 1 | matrix-sydent (4) · matrix-synapse (3) · vyper (2) | — | |
| 29 | siemens | 27 | 4 | · | · | PoC 3 | nucleus net (9) · nucleus source code (9) · nucleus readystart v3 (7) | — | |
| 30 | canonical ltd. | 25 | 5 | 1 | · | KEV 1PoC 4 | ubuntu (25) | — | |
| 31 | gpac | 25 | 1 | · | · | NEWPoC 10 | gpac (25) | — | |
| 32 | packagist | 25 | 5 | · | 1 | Nuclei 1PoC 11 | tribalsystems/zenario (3) · openmage/magento-lts (2) · shopware/core (2) | — | |
| 33 | ооо «ред софт» | 22 | 1 | · | · | PoC 7 | ред ос (22) | — | |
| 34 | arubanetworks | 21 | 1 | · | · | NEW | airwave (11) · clearpass (9) · clearpass policy manager (1) | — | |
| 35 | dell | 21 | 1 | · | · | NEW | integrated dell remote access controller (idrac) (6) · idrac9 firmware (6) · dell hybrid client (dhc) (4) | — | |
| 36 | samsung mobile | 20 | 1 | · | · | NEWPoC 1 | samsung mobile devices (11) · samsung email (2) · customization service (1) | — | |
| 37 | crates.io | 19 | 7 | · | · | NEWPoC 4 | id-map (3) · arenavec (2) · reorder (2) | — | |
| 38 | novell inc. | 19 | · | 1 | · | KEV 1PoC 5 | opensuse leap (16) · suse linux enterprise server (9) · suse linux enterprise server for sap applications (7) | — | |
| 39 | parallels | 19 | · | · | · | NEW | desktop (19) · parallels desktop (19) | — | |
| 40 | mediawiki | 18 | · | · | · | PoC 2 | mediawiki (18) | — | |
| 41 | adobe | 16 | · | · | 1 | Nuclei 1 | bridge (6) · gocart (3) · genuine service (3) | — | |
| 42 | apache | 15 | 6 | · | 4 | Nuclei 4PoC 2 | solr (4) · ofbiz (2) · tapestry (2) | — | |
| 43 | go | 15 | · | · | 1 | Nuclei 1 | github.com/pomerium/pomerium (2) · github.com/cortexproject/cortex (1) · github.com/filecoin-project/lotus (1) | — | |
| 44 | qualcomm | 15 | 1 | · | · | wcn3998 firmware (14) · wsa8815 firmware (14) · wcd9341 firmware (14) | — | ||
| 45 | qualcomm, inc. | 15 | 1 | · | · | snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon mobile (3) · snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon iot, snapdragon mobile, snapdragon voice & music, snapdragon wearables (2) · snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon iot, snapdragon mobile, snapdragon wearables (1) | — | ||
| 46 | adobe systems inc. | 14 | · | · | 1 | Nuclei 1 | adobe bridge (6) · adobe genuine service (3) · photoshop 2020 (2) | — | |
| 47 | nvidia | 14 | · | · | · | NEW | nvidia virtual gpu software (8) · virtual gpu manager (8) · gpu display driver (5) | — | |
| 48 | redhat | 14 | · | · | · | PoC 2 | enterprise linux (10) · ansible tower (2) · ansible engine (1) | — | |
| 49 | sap | 14 | 1 | · | · | netweaver application server java (4) · netweaver process integration (2) · focused run (1) | — | ||
| 50 | sap se | 14 | 1 | · | · | sap commerce (1) · sap fiori apps 2.0 for travel management in sap erp (1) · sap focused run (1) | — |