month report
May 2021
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
May 2021 closed with 1,580 published CVEs. 196 criticals, сообщество свободного программного обеспечения led volume, mostly via debian gnu/linux. Top weakness class — CWE-79 (203 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
1,580
— MoM— YoY
Severity mix
196 / 563
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
10.5%
166 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
1760.0
n=166
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
180
n=19
Detection gap
KEV pressure, no Nuclei coverage
May 2021 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 2qualcomm20 CVE
- KEV 2qualcomm, inc.20 CVE
Weakness × Vendor
What's spreading where in May 2021
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS787Out-of-bounds Write125Out-of-bounds Read20Improper Input Validation416Use After Free369CWE-369476NULL Pointer Dereference89SQL Injection352CSRF119Memory Buffer Boundsсообщество свободного программного обеспечения83413171869110pypi92214132155ао "нппкт"12713812354ооо «русбитех-астра»12814910576google2213132155tensorflow2213132155debian2210711466fedoraproject19891346redhat481184313ао «концерн вниинс»151452411ibm13311cisco systems inc.31124
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #6tensorflow108 CVE
- #25foxit33 CVE
- #28unknown28 CVE
- #29ао «нтц ит роса»28 CVE
- #30ffmpeg27 CVE
- #32ffmpeg team26 CVE
- #34gnu general public license22 CVE
- #35exim21 CVE
- #39ibm corp.19 CVE
- #42wago18 CVE
Top vendors
Ranked by distinct CVE count this period.
- 239 CVE26 critCVSS 7.0Nuclei 21PoC 46debian gnu/linux (205) · linux (36) · drupal (4)
- 138 CVE4 critCVSS 3.2Nuclei 2PoC 40tensorflow-gpu (108) · tensorflow (108) · tensorflow-cpu (108)
- 127 CVE19 critCVSS 7.3Nuclei 9PoC 26осон основа оnyx (127)
- 126 CVE21 critCVSS 7.5Nuclei 9PoC 25astra linux special edition (121) · astra linux special edition для «эльбрус» (71) · astra linux common edition (26)
- 109 CVECVSS 2.9PoC 36tensorflow (108) · cloud iot device sdk for embedded c (1)
- 108 CVECVSS 2.9NEWPoC 36tensorflow (108)
- 100 CVE7 critCVSS 7.2Nuclei 2PoC 24debian linux (100)
- 92 CVE7 critCVSS 6.7Nuclei 2PoC 14fedora (92)
- 80 CVE15 critCVSS 6.4PoC 6enterprise linux (38) · ansible tower (8) · certification (5)
- 76 CVE17 critCVSS 7.7Nuclei 9PoC 11ос он «стрелец» (76)
- 71 CVE7 critCVSS 6.6PoC 1qradar siem (12) · cognos analytics (10) · qradar security information and event manager (8)
- 70 CVE7 critCVSS 5.1KEV 2Nuclei 3PoC 61cisco sd-wan (13) · small business wap125 (11) · small business wap131 (11)
- 65 CVE8 critCVSS 6.5Nuclei 1PoC 12com.liferay.portal:release.portal.bom (11) · com.liferay.portal:release.dxp.bom (11) · org.opennms:opennms (5)
- 64 CVE7 critCVSS 5.3KEV 2Nuclei 3PoC 60sd-wan vmanage (12) · wap125 firmware (11) · cisco business wireless access point software (11)
- 55 CVE2 critCVSS 7.0KEV 2Nuclei 1PoC 10windows 10 2004 (24) · windows 10 20h2 (23) · windows server 2004 (server core installation) (22)
- 55 CVE18 critCVSS 7.8Nuclei 8PoC 5ред ос (55)
- 54 CVE2 critCVSS 7.4KEV 2Nuclei 1PoC 10windows 10 (23) · windows 10 version 2004 (21) · windows 10 version 20h2 (20)
- 49 CVE6 critCVSS 7.6Nuclei 1PoC 8cloud backup (18) · h300s firmware (16) · h410s firmware (16)
- 45 CVE1 critCVSS 6.3Nuclei 1PoC 6red hat enterprise linux (30) · libvirt (3) · ansible (3)
- 44 CVE7 critCVSS 7.5Nuclei 8PoC 3ubuntu (44)
- 41 CVE2 critCVSS 6.5PoC 11альт 8 сп (39) · альт сп 10 (5) · альт 8 сп рабочая станция (1)
- 39 CVE8 critCVSS 7.5Nuclei 2PoC 7mixme (2) · tinymce (2) · matrix-react-sdk (2)
- 34 CVECVSS 6.4PoC 1phantompdf (22) · foxit reader (16) · 3d (11)
- 34 CVECVSS 6.2PoC 6linux kernel (34) · mac80211 (3) · kernel (1)
- 33 CVECVSS 6.2NEWreader (33)
- 29 CVE2 critCVSS 7.3PoC 2simatic hmi ktp mobile panels ktp400f firmware (7) · simatic hmi ktp mobile panels ktp700 firmware (7) · simatic hmi ktp mobile panels ktp700f firmware (7)
- 28 CVE4 critCVSS 7.1Nuclei 10teamcity (14) · youtrack (4) · intellij idea (3)
- 28 CVE1 critCVSS 5.8NEWNuclei 28PoC 12404 seo redirection (2) · all 404 redirect to homepage (1) · all-in-one addons for elementor – widgetkit (1)
- 28 CVE12 critCVSS 8.5NEWPoC 6rosa virtualization (18) · rosa virtualization 3.0 (13) · роса кобальт (6)
- 27 CVECVSS 7.7NEWPoC 10ffmpeg (27)
- 27 CVE1 critCVSS 8.0PoC 10libredwg (23) · binutils (1) · cflow (1)
- 26 CVECVSS 7.7NEWPoC 10ffmpeg (26)
- 25 CVE3 critCVSS 7.5PoC 3github.com/nats-io/nats-server/v2 (4) · github.com/dutchcoders/transfer.sh (2) · golang.org/x/net (2)
- 22 CVE6 critCVSS 8.2NEWNuclei 8exim (21) · gnu binutils (1)
- 21 CVE6 critCVSS 8.2NEWNuclei 8exim (21)
- 21 CVE2 critCVSS 6.5Nuclei 2PoC 7drupal/core (5) · drupal/drupal (5) · shopware/shopware (2)
- 20 CVECVSS 7.4KEV 2qbt2000 firmware (18) · pm6150l firmware (18) · qtm525 firmware (18)
- 20 CVECVSS 7.3KEV 2snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon mobile, snapdragon voice & music, snapdragon wearables (3) · snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon mobile (2) · snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon iot, snapdragon mobile, snapdragon voice & music, snapdragon wearables (2)
- 19 CVE2 critCVSS 7.0NEWcognos analytics (10) · security guardium (6) · ibm security verify access docker (3)
- 19 CVE3 critCVSS 7.4spacelynk firmware (9) · homelynk firmware (9) · tcm 4351b firmware (6)
- 18 CVECVSS 6.7PoC 1fedora (17) · 389 directory server (1)
- 18 CVE8 critCVSS 8.1NEW750-829 firmware (12) · 750-831 firmware (12) · 750-832 firmware (12)
- 16 CVECVSS 6.5NEWPoC 13routeros (16)
- 15 CVE6 critCVSS 7.7NEWPoC 1v2 web server (6) · development system (3) · runtime toolkit (3)
- 14 CVE8 critCVSS 7.7nport iaw5250a-6i/o (10) · nport ia5450a (4) · nport ia5250a (4)
- 13 CVE2 critCVSS 7.1Nuclei 1integrated lights-out 5 (10) · integrated lights-out 4 (10) · laserjet mfp m436 w7u01a (1)
- 13 CVE1 critCVSS 6.3PoC 4xray - test management for jira (2) · s3 publisher (2) · p4 (2)
- 13 CVE1 critCVSS 6.3PoC 4jenkins xray - test management for jira plugin (2) · jenkins p4 plugin (2) · jenkins s3 publisher plugin (2)
- 12 CVECVSS 6.2NEWliferay portal (11) · dxp (10) · digital experience platform (5)
- 12 CVE7 critCVSS 9.0NEWNuclei 1PoC 12fusion (11) · nagios xi (3)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | сообщество свободного программного обеспечения | 239 | 26 | · | 21 | Nuclei 21PoC 46 | debian gnu/linux (205) · linux (36) · drupal (4) | — | |
| 2 | pypi | 138 | 4 | · | 2 | Nuclei 2PoC 40 | tensorflow-gpu (108) · tensorflow (108) · tensorflow-cpu (108) | — | |
| 3 | ао "нппкт" | 127 | 19 | · | 9 | Nuclei 9PoC 26 | осон основа оnyx (127) | — | |
| 4 | ооо «русбитех-астра» | 126 | 21 | · | 9 | Nuclei 9PoC 25 | astra linux special edition (121) · astra linux special edition для «эльбрус» (71) · astra linux common edition (26) | — | |
| 5 | 109 | · | · | · | PoC 36 | tensorflow (108) · cloud iot device sdk for embedded c (1) | — | ||
| 6 | tensorflow | 108 | · | · | · | NEWPoC 36 | tensorflow (108) | — | |
| 7 | debian | 100 | 7 | · | 2 | Nuclei 2PoC 24 | debian linux (100) | — | |
| 8 | fedoraproject | 92 | 7 | · | 2 | Nuclei 2PoC 14 | fedora (92) | — | |
| 9 | redhat | 80 | 15 | · | · | PoC 6 | enterprise linux (38) · ansible tower (8) · certification (5) | — | |
| 10 | ао «концерн вниинс» | 76 | 17 | · | 9 | Nuclei 9PoC 11 | ос он «стрелец» (76) | — | |
| 11 | ibm | 71 | 7 | · | · | PoC 1 | qradar siem (12) · cognos analytics (10) · qradar security information and event manager (8) | — | |
| 12 | cisco systems inc. | 70 | 7 | 2 | 3 | KEV 2Nuclei 3PoC 61 | cisco sd-wan (13) · small business wap125 (11) · small business wap131 (11) | — | |
| 13 | maven | 65 | 8 | · | 1 | Nuclei 1PoC 12 | com.liferay.portal:release.portal.bom (11) · com.liferay.portal:release.dxp.bom (11) · org.opennms:opennms (5) | — | |
| 14 | cisco | 64 | 7 | 2 | 3 | KEV 2Nuclei 3PoC 60 | sd-wan vmanage (12) · wap125 firmware (11) · cisco business wireless access point software (11) | — | |
| 15 | microsoft corp | 55 | 2 | 2 | 1 | KEV 2Nuclei 1PoC 10 | windows 10 2004 (24) · windows 10 20h2 (23) · windows server 2004 (server core installation) (22) | — | |
| 16 | ооо «ред софт» | 55 | 18 | · | 8 | Nuclei 8PoC 5 | ред ос (55) | — | |
| 17 | microsoft | 54 | 2 | 2 | 1 | KEV 2Nuclei 1PoC 10 | windows 10 (23) · windows 10 version 2004 (21) · windows 10 version 20h2 (20) | — | |
| 18 | netapp | 49 | 6 | · | 1 | Nuclei 1PoC 8 | cloud backup (18) · h300s firmware (16) · h410s firmware (16) | — | |
| 19 | red hat inc. | 45 | 1 | · | 1 | Nuclei 1PoC 6 | red hat enterprise linux (30) · libvirt (3) · ansible (3) | — | |
| 20 | canonical ltd. | 44 | 7 | · | 8 | Nuclei 8PoC 3 | ubuntu (44) | — | |
| 21 | ао «ивк» | 41 | 2 | · | · | PoC 11 | альт 8 сп (39) · альт сп 10 (5) · альт 8 сп рабочая станция (1) | — | |
| 22 | npm | 39 | 8 | · | 2 | Nuclei 2PoC 7 | mixme (2) · tinymce (2) · matrix-react-sdk (2) | — | |
| 23 | foxitsoftware | 34 | · | · | · | PoC 1 | phantompdf (22) · foxit reader (16) · 3d (11) | — | |
| 24 | linux | 34 | · | · | · | PoC 6 | linux kernel (34) · mac80211 (3) · kernel (1) | — | |
| 25 | foxit | 33 | · | · | · | NEW | reader (33) | — | |
| 26 | siemens | 29 | 2 | · | · | PoC 2 | simatic hmi ktp mobile panels ktp400f firmware (7) · simatic hmi ktp mobile panels ktp700 firmware (7) · simatic hmi ktp mobile panels ktp700f firmware (7) | — | |
| 27 | jetbrains | 28 | 4 | · | 10 | Nuclei 10 | teamcity (14) · youtrack (4) · intellij idea (3) | — | |
| 28 | unknown | 28 | 1 | · | 28 | NEWNuclei 28PoC 12 | 404 seo redirection (2) · all 404 redirect to homepage (1) · all-in-one addons for elementor – widgetkit (1) | — | |
| 29 | ао «нтц ит роса» | 28 | 12 | · | · | NEWPoC 6 | rosa virtualization (18) · rosa virtualization 3.0 (13) · роса кобальт (6) | — | |
| 30 | ffmpeg | 27 | · | · | · | NEWPoC 10 | ffmpeg (27) | — | |
| 31 | gnu | 27 | 1 | · | · | PoC 10 | libredwg (23) · binutils (1) · cflow (1) | — | |
| 32 | ffmpeg team | 26 | · | · | · | NEWPoC 10 | ffmpeg (26) | — | |
| 33 | go | 25 | 3 | · | · | PoC 3 | github.com/nats-io/nats-server/v2 (4) · github.com/dutchcoders/transfer.sh (2) · golang.org/x/net (2) | — | |
| 34 | gnu general public license | 22 | 6 | · | 8 | NEWNuclei 8 | exim (21) · gnu binutils (1) | — | |
| 35 | exim | 21 | 6 | · | 8 | NEWNuclei 8 | exim (21) | — | |
| 36 | packagist | 21 | 2 | · | 2 | Nuclei 2PoC 7 | drupal/core (5) · drupal/drupal (5) · shopware/shopware (2) | — | |
| 37 | qualcomm | 20 | · | 2 | · | KEV 2 | qbt2000 firmware (18) · pm6150l firmware (18) · qtm525 firmware (18) | — | |
| 38 | qualcomm, inc. | 20 | · | 2 | · | KEV 2 | snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon mobile, snapdragon voice & music, snapdragon wearables (3) · snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon mobile (2) · snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon iot, snapdragon mobile, snapdragon voice & music, snapdragon wearables (2) | — | |
| 39 | ibm corp. | 19 | 2 | · | · | NEW | cognos analytics (10) · security guardium (6) · ibm security verify access docker (3) | — | |
| 40 | schneider-electric | 19 | 3 | · | · | spacelynk firmware (9) · homelynk firmware (9) · tcm 4351b firmware (6) | — | ||
| 41 | fedora project | 18 | · | · | · | PoC 1 | fedora (17) · 389 directory server (1) | — | |
| 42 | wago | 18 | 8 | · | · | NEW | 750-829 firmware (12) · 750-831 firmware (12) · 750-832 firmware (12) | — | |
| 43 | mikrotik | 16 | · | · | · | NEWPoC 13 | routeros (16) | — | |
| 44 | codesys | 15 | 6 | · | · | NEWPoC 1 | v2 web server (6) · development system (3) · runtime toolkit (3) | — | |
| 45 | moxa inc. | 14 | 8 | · | · | nport iaw5250a-6i/o (10) · nport ia5450a (4) · nport ia5250a (4) | — | ||
| 46 | hp | 13 | 2 | · | 1 | Nuclei 1 | integrated lights-out 5 (10) · integrated lights-out 4 (10) · laserjet mfp m436 w7u01a (1) | — | |
| 47 | jenkins | 13 | 1 | · | · | PoC 4 | xray - test management for jira (2) · s3 publisher (2) · p4 (2) | — | |
| 48 | jenkins project | 13 | 1 | · | · | PoC 4 | jenkins xray - test management for jira plugin (2) · jenkins p4 plugin (2) · jenkins s3 publisher plugin (2) | — | |
| 49 | liferay | 12 | · | · | · | NEW | liferay portal (11) · dxp (10) · digital experience platform (5) | — | |
| 50 | nagios | 12 | 7 | · | 1 | NEWNuclei 1PoC 12 | fusion (11) · nagios xi (3) | — |