month report
September 2022
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
September 2022 closed with 2,210 published CVEs. 299 criticals, 24 added to CISA KEV (5 ransomware-linked). google led volume, mostly via android. Top weakness class — CWE-787 (268 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
2,210
— MoM— YoY
Severity mix
299 / 905
critical / high
KEV added
24
5 ransomware-linked
Nuclei coverage
10.0%
221 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
1267.5
n=221
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
97
n=8
Detection gap
KEV pressure, no Nuclei coverage
September 2022 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 4microsoft corp88 CVE
- KEV 3google166 CVE
- KEV 3ао "нппкт"115 CVE
- KEV 3ооо «русбитех-астра»115 CVE
- KEV 3google inc63 CVE
- KEV 3ао «концерн вниинс»44 CVE
- KEV 1apple72 CVE
- KEV 1microsoft66 CVE
Weakness × Vendor
What's spreading where in September 2022
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
787Out-of-bounds Write79XSS89SQL Injection125Out-of-bounds Read352CSRF20Improper Input Validation416Use After Free22Path Traversal287Improper Authentication200Information Exposuregoogle3516119202сообщество свободного программного обеспечения2231962211ао "нппкт"26151728ооо «русбитех-астра»19251732pypi31151631maven7187134fedoraproject17512162011microsoft corp4111129ооо «ред софт»17436481debian161174111apple16110424adobe151326151
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #12adobe66 CVE
- #14adobe systems inc.65 CVE
- #15google inc63 CVE
- #17unknown55 CVE
- #18qualcomm54 CVE
- #19qualcomm, inc.54 CVE
- #25samsung mobile40 CVE
- #26tenda39 CVE
- #30samsung35 CVE
- #31jenkins32 CVE
Top vendors
Ranked by distinct CVE count this period.
- 166 CVE10 critCVSS 6.9KEV 3PoC 4android (64) · tensorflow (59) · chrome (42)
- 128 CVE9 critCVSS 7.0KEV 1Nuclei 3PoC 31debian gnu/linux (81) · linux (36) · vim (11)
- 115 CVE2 critCVSS 7.2KEV 3PoC 22осон основа оnyx (115)
- 115 CVE3 critCVSS 7.1KEV 3PoC 28astra linux special edition (108) · astra linux special edition для «эльбрус» (16) · astra linux common edition (2)
- 114 CVE4 critCVSS 6.1PoC 10tensorflow (58) · tensorflow-cpu (56) · tensorflow-gpu (56)
- 108 CVE14 critCVSS 7.0Nuclei 1PoC 6com.fasterxml.woodstox:woodstox-core (5) · com.liferay.portal:release.dxp.bom (5) · org.yaml:snakeyaml (4)
- 98 CVE3 critCVSS 7.5KEV 3Nuclei 1PoC 19fedora (98) · extra packages for enterprise linux (4)
- 88 CVE4 critCVSS 8.0KEV 4PoC 3windows server 2022 (server core installation) (44) · windows server 2022 (44) · windows server 2019 (server core installation) (43)
- 83 CVE8 critCVSS 6.6KEV 1Nuclei 2PoC 18ред ос (83)
- 80 CVE3 critCVSS 6.5Nuclei 1PoC 18debian linux (79) · logcheck (1)
- 72 CVE5 critCVSS 7.2KEV 1macos (64) · iphone os (42) · ipados (38)
- 66 CVECVSS 6.6NEWNuclei 1indesign (17) · experience manager (14) · bridge (12)
- 66 CVE3 critCVSS 8.0KEV 1windows server 2022 (44) · windows server 2019 (server core installation) (43) · windows server 2019 (43)
- 65 CVECVSS 6.7NEWadobe indesign (17) · adobe experience manager (14) · adobe bridge (12)
- 63 CVE1 critCVSS 8.0NEWKEV 3PoC 4google chrome (41) · android (20) · chrome os (3)
- 59 CVECVSS 6.0tensorflow (59)
- 55 CVE2 critCVSS 5.9NEWNuclei 55PoC 20ketchup restaurant reservations (2) · wp popup builder – popup forms , marketing popup & newsletter (2) · classified listing pro - classified ads & business directory plugin (2)
- 54 CVE5 critCVSS 7.8NEWwcd9370 firmware (41) · wcd9380 firmware (40) · wsa8830 firmware (40)
- 54 CVE5 critCVSS 7.9NEWsnapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon mobile, snapdragon voice & music, snapdragon wearables (10) · snapdragon auto (8) · snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon industrial iot, snapdragon mobile, snapdragon wearables (5)
- 51 CVE6 critCVSS 6.2Nuclei 8PoC 18typo3/cms-core (7) · typo3/cms (6) · moodle/moodle (5)
- 47 CVE6 critCVSS 7.2Nuclei 2PoC 11github.com/rancher/rancher (3) · github.com/hashicorp/consul (2) · github.com/grafana/grafana (2)
- 44 CVE1 critCVSS 8.0KEV 3PoC 5ос он «стрелец» (44)
- 43 CVE10 critCVSS 7.4PoC 11steal (8) · matrix-js-sdk (4) · parse-server (3)
- 42 CVE2 critCVSS 6.8PoC 11red hat enterprise linux (36) · red hat virtualization (6) · red hat integration camel for spring boot (3)
- 40 CVECVSS 4.5NEWsamsung mobile devices (21) · samsung pay (3) · com.samsung.android.waterplugin (2)
- 39 CVE21 critCVSS 8.7NEWPoC 23ac21 firmware (10) · i9 firmware (8) · ac18 firmware (8)
- 37 CVE9 critCVSS 7.8emui (32) · harmonyos (27) · magic ui (20)
- 36 CVECVSS 6.2PoC 8linux kernel (36) · kernel (6)
- 36 CVECVSS 6.7PoC 11альт 8 сп (33) · альт сп 10 (5)
- 35 CVECVSS 5.8NEWPoC 3mtower (11) · tizenrt (4) · samsung pay (3)
- 32 CVE4 critCVSS 6.9NEWcons3rt (4) · build-publisher (3) · ns-nd integration performance publisher (3)
- 32 CVE4 critCVSS 6.9NEWjenkins cons3rt plugin (4) · jenkins build-publisher plugin (3) · jenkins ns-nd integration performance publisher plugin (3)
- 30 CVE5 critCVSS 7.3Nuclei 2PoC 1apache ofbiz (5) · apache airflow (4) · apache pulsar (4)
- 29 CVECVSS 6.4cognos analytics (7) · websphere application server (3) · aix (2)
- 29 CVECVSS 6.5NEWPoC 29otfcc (29)
- 26 CVE5 critCVSS 7.3Nuclei 2PoC 1ofbiz (5) · pulsar (4) · airflow (4)
- 26 CVECVSS 7.3clearpass policy manager (14) · aos-cx (12)
- 25 CVECVSS 6.9PoC 9ubuntu (25)
- 23 CVE3 critCVSS 6.5NEWvostro 3710 firmware (11) · inspiron 3910 firmware (11) · cpg bios (11)
- 23 CVE2 critCVSS 6.8PoC 7fedora (23) · fedora epel (1)
- 23 CVE1 critCVSS 6.5NEWmt6833, mt6853, mt6855, mt6873, mt6877, mt6879, mt6883, mt6885, mt6889, mt6893, mt6895, mt6983, mt8791, mt8797 (6) · mt6879, mt6895, mt6983 (2) · mt6761, mt6765, mt6768, mt6771, mt6779, mt6781, mt6785, mt6833, mt6853, mt6875, mt6877, mt6879, mt6885, mt6893, mt6895, mt6983 (2)
- 23 CVECVSS 6.6Nuclei 1PoC 3enterprise linux (9) · openshift container platform (4) · single sign-on (3)
- 23 CVE1 critCVSS 6.6parasolid v35.0 (20) · parasolid (20) · parasolid v33.1 (20)
- 22 CVE2 critCVSS 6.5NEWPoC 8ikus060/rdiffweb (20) · ikus060/minarca (2)
- 22 CVE2 critCVSS 6.5NEWPoC 8rdiffweb (20) · minarca (2)
- 21 CVECVSS 5.8NEWKEV 1PoC 19cisco ios xe (9) · catalyst sd-wan manager (5) · sd-wan vbond orchestrator software (3)
- 21 CVE2 critCVSS 7.8NEWPoC 13jfinal cms (21)
- 20 CVECVSS 5.4NEWKEV 1PoC 19ios xe (8) · cisco ios xe software (6) · sd-wan (5)
- 20 CVECVSS 7.8NEWwcd9375 (18) · sd 8 gen1 5g (18) · wcn6855 (18)
- 19 CVECVSS 7.8NEWspaceclaim (19)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | 166 | 10 | 3 | · | KEV 3PoC 4 | android (64) · tensorflow (59) · chrome (42) | — | ||
| 2 | сообщество свободного программного обеспечения | 128 | 9 | 1 | 3 | KEV 1Nuclei 3PoC 31 | debian gnu/linux (81) · linux (36) · vim (11) | — | |
| 3 | ао "нппкт" | 115 | 2 | 3 | · | KEV 3PoC 22 | осон основа оnyx (115) | — | |
| 4 | ооо «русбитех-астра» | 115 | 3 | 3 | · | KEV 3PoC 28 | astra linux special edition (108) · astra linux special edition для «эльбрус» (16) · astra linux common edition (2) | — | |
| 5 | pypi | 114 | 4 | · | · | PoC 10 | tensorflow (58) · tensorflow-cpu (56) · tensorflow-gpu (56) | — | |
| 6 | maven | 108 | 14 | · | 1 | Nuclei 1PoC 6 | com.fasterxml.woodstox:woodstox-core (5) · com.liferay.portal:release.dxp.bom (5) · org.yaml:snakeyaml (4) | — | |
| 7 | fedoraproject | 98 | 3 | 3 | 1 | KEV 3Nuclei 1PoC 19 | fedora (98) · extra packages for enterprise linux (4) | — | |
| 8 | microsoft corp | 88 | 4 | 4 | · | KEV 4PoC 3 | windows server 2022 (server core installation) (44) · windows server 2022 (44) · windows server 2019 (server core installation) (43) | — | |
| 9 | ооо «ред софт» | 83 | 8 | 1 | 2 | KEV 1Nuclei 2PoC 18 | ред ос (83) | — | |
| 10 | debian | 80 | 3 | · | 1 | Nuclei 1PoC 18 | debian linux (79) · logcheck (1) | — | |
| 11 | apple | 72 | 5 | 1 | · | KEV 1 | macos (64) · iphone os (42) · ipados (38) | — | |
| 12 | adobe | 66 | · | · | 1 | NEWNuclei 1 | indesign (17) · experience manager (14) · bridge (12) | — | |
| 13 | microsoft | 66 | 3 | 1 | · | KEV 1 | windows server 2022 (44) · windows server 2019 (server core installation) (43) · windows server 2019 (43) | — | |
| 14 | adobe systems inc. | 65 | · | · | · | NEW | adobe indesign (17) · adobe experience manager (14) · adobe bridge (12) | — | |
| 15 | google inc | 63 | 1 | 3 | · | NEWKEV 3PoC 4 | google chrome (41) · android (20) · chrome os (3) | — | |
| 16 | tensorflow | 59 | · | · | · | tensorflow (59) | — | ||
| 17 | unknown | 55 | 2 | · | 55 | NEWNuclei 55PoC 20 | ketchup restaurant reservations (2) · wp popup builder – popup forms , marketing popup & newsletter (2) · classified listing pro - classified ads & business directory plugin (2) | — | |
| 18 | qualcomm | 54 | 5 | · | · | NEW | wcd9370 firmware (41) · wcd9380 firmware (40) · wsa8830 firmware (40) | — | |
| 19 | qualcomm, inc. | 54 | 5 | · | · | NEW | snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon mobile, snapdragon voice & music, snapdragon wearables (10) · snapdragon auto (8) · snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon industrial iot, snapdragon mobile, snapdragon wearables (5) | — | |
| 20 | packagist | 51 | 6 | · | 8 | Nuclei 8PoC 18 | typo3/cms-core (7) · typo3/cms (6) · moodle/moodle (5) | — | |
| 21 | go | 47 | 6 | · | 2 | Nuclei 2PoC 11 | github.com/rancher/rancher (3) · github.com/hashicorp/consul (2) · github.com/grafana/grafana (2) | — | |
| 22 | ао «концерн вниинс» | 44 | 1 | 3 | · | KEV 3PoC 5 | ос он «стрелец» (44) | — | |
| 23 | npm | 43 | 10 | · | · | PoC 11 | steal (8) · matrix-js-sdk (4) · parse-server (3) | — | |
| 24 | red hat inc. | 42 | 2 | · | · | PoC 11 | red hat enterprise linux (36) · red hat virtualization (6) · red hat integration camel for spring boot (3) | — | |
| 25 | samsung mobile | 40 | · | · | · | NEW | samsung mobile devices (21) · samsung pay (3) · com.samsung.android.waterplugin (2) | — | |
| 26 | tenda | 39 | 21 | · | · | NEWPoC 23 | ac21 firmware (10) · i9 firmware (8) · ac18 firmware (8) | — | |
| 27 | huawei | 37 | 9 | · | · | emui (32) · harmonyos (27) · magic ui (20) | — | ||
| 28 | linux | 36 | · | · | · | PoC 8 | linux kernel (36) · kernel (6) | — | |
| 29 | ао «ивк» | 36 | · | · | · | PoC 11 | альт 8 сп (33) · альт сп 10 (5) | — | |
| 30 | samsung | 35 | · | · | · | NEWPoC 3 | mtower (11) · tizenrt (4) · samsung pay (3) | — | |
| 31 | jenkins | 32 | 4 | · | · | NEW | cons3rt (4) · build-publisher (3) · ns-nd integration performance publisher (3) | — | |
| 32 | jenkins project | 32 | 4 | · | · | NEW | jenkins cons3rt plugin (4) · jenkins build-publisher plugin (3) · jenkins ns-nd integration performance publisher plugin (3) | — | |
| 33 | apache software foundation | 30 | 5 | · | 2 | Nuclei 2PoC 1 | apache ofbiz (5) · apache airflow (4) · apache pulsar (4) | — | |
| 34 | ibm | 29 | · | · | · | cognos analytics (7) · websphere application server (3) · aix (2) | — | ||
| 35 | otfcc project | 29 | · | · | · | NEWPoC 29 | otfcc (29) | — | |
| 36 | apache | 26 | 5 | · | 2 | Nuclei 2PoC 1 | ofbiz (5) · pulsar (4) · airflow (4) | — | |
| 37 | arubanetworks | 26 | · | · | · | clearpass policy manager (14) · aos-cx (12) | — | ||
| 38 | canonical ltd. | 25 | · | · | · | PoC 9 | ubuntu (25) | — | |
| 39 | dell | 23 | 3 | · | · | NEW | vostro 3710 firmware (11) · inspiron 3910 firmware (11) · cpg bios (11) | — | |
| 40 | fedora project | 23 | 2 | · | · | PoC 7 | fedora (23) · fedora epel (1) | — | |
| 41 | mediatek, inc. | 23 | 1 | · | · | NEW | mt6833, mt6853, mt6855, mt6873, mt6877, mt6879, mt6883, mt6885, mt6889, mt6893, mt6895, mt6983, mt8791, mt8797 (6) · mt6879, mt6895, mt6983 (2) · mt6761, mt6765, mt6768, mt6771, mt6779, mt6781, mt6785, mt6833, mt6853, mt6875, mt6877, mt6879, mt6885, mt6893, mt6895, mt6983 (2) | — | |
| 42 | redhat | 23 | · | · | 1 | Nuclei 1PoC 3 | enterprise linux (9) · openshift container platform (4) · single sign-on (3) | — | |
| 43 | siemens | 23 | 1 | · | · | parasolid v35.0 (20) · parasolid (20) · parasolid v33.1 (20) | — | ||
| 44 | ikus060 | 22 | 2 | · | · | NEWPoC 8 | ikus060/rdiffweb (20) · ikus060/minarca (2) | — | |
| 45 | ikus-soft | 22 | 2 | · | · | NEWPoC 8 | rdiffweb (20) · minarca (2) | — | |
| 46 | cisco systems inc. | 21 | · | 1 | · | NEWKEV 1PoC 19 | cisco ios xe (9) · catalyst sd-wan manager (5) · sd-wan vbond orchestrator software (3) | — | |
| 47 | jflyfox | 21 | 2 | · | · | NEWPoC 13 | jfinal cms (21) | — | |
| 48 | cisco | 20 | · | 1 | · | NEWKEV 1PoC 19 | ios xe (8) · cisco ios xe software (6) · sd-wan (5) | — | |
| 49 | qualcomm technologies inc. | 20 | · | · | · | NEW | wcd9375 (18) · sd 8 gen1 5g (18) · wcn6855 (18) | — | |
| 50 | ansys | 19 | · | · | · | NEW | spaceclaim (19) | — |