month report
April 2023
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
April 2023 closed with 2,356 published CVEs. 284 criticals, 17 added to CISA KEV (6 ransomware-linked). microsoft corp led volume, mostly via windows server 2022 (server core installation). Top weakness class — CWE-79 (412 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
2,356
— MoM— YoY
Severity mix
284 / 711
critical / high
KEV added
17
6 ransomware-linked
Nuclei coverage
13.3%
314 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
1060.3
n=314
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
36
n=17
Detection gap
KEV pressure, no Nuclei coverage
April 2023 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 4microsoft corp111 CVE
- KEV 3ооо «русбитех-астра»77 CVE
- KEV 2microsoft104 CVE
- KEV 2google100 CVE
- KEV 2debian48 CVE
- KEV 2google inc22 CVE
- KEV 1netapp32 CVE
- KEV 1novell inc.25 CVE
Weakness × Vendor
What's spreading where in April 2023
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS89SQL Injection787Out-of-bounds Write125Out-of-bounds Read20Improper Input Validation22Path Traversal416Use After Free77Command Injection400Resource Consumption434Unrestricted File Uploadmicrosoft corp3448192microsoft314892сообщество свободного программного обеспечения31124321023google22101161sourcecodester236613maven15311121oracle corp.3oracle3oracle corporation3packagist4473314ао "нппкт"10422134ооо «русбитех-астра»15311141
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #1microsoft corp111 CVE
- #2microsoft104 CVE
- #3сообщество свободного программного обеспечения102 CVE
- #4google100 CVE
- #5sourcecodester98 CVE
- #6maven94 CVE
- #7oracle corp.92 CVE
- #8oracle91 CVE
- #9oracle corporation91 CVE
- #10packagist91 CVE
Top vendors
Ranked by distinct CVE count this period.
- 111 CVE3 critCVSS 7.4NEWKEV 4PoC 6windows server 2022 (server core installation) (73) · windows server 2022 (73) · windows server 2019 (server core installation) (70)
- 104 CVE3 critCVSS 7.4NEWKEV 2PoC 6windows server 2022 (73) · windows server 2019 (server core installation) (70) · windows server 2019 (70)
- 102 CVE15 critCVSS 6.7NEWNuclei 3PoC 32debian gnu/linux (47) · linux (32) · xwiki platform (13)
- 100 CVE2 critCVSS 7.1NEWKEV 2android (79) · chrome (20) · espv2 (1)
- 98 CVECVSS 5.4NEWNuclei 1PoC 90online computer and laptop store (19) · vehicle service management system (9) · online payroll system (9)
- 94 CVE40 critCVSS 7.7NEWNuclei 9PoC 20org.xwiki.platform:xwiki-platform-oldcore (5) · tech.powerjob:powerjob (5) · org.xwiki.platform:xwiki-platform-web-templates (4)
- 92 CVECVSS 5.5NEWNuclei 3PoC 2mysql server (23) · vm virtualbox (10) · graalvm enterprise edition (8)
- 91 CVECVSS 5.4NEWNuclei 3PoC 1mysql server (18) · vm virtualbox (10) · graalvm (8)
- 91 CVECVSS 5.5NEWNuclei 3PoC 1mysql server (23) · vm virtualbox (10) · java se jdk and jre (7)
- 91 CVE8 critCVSS 6.4NEWNuclei 10PoC 27pimcore/pimcore (16) · thorsten/phpmyfaq (15) · concrete5/concrete5 (10)
- 81 CVE2 critCVSS 6.4NEWKEV 3Nuclei 1PoC 6осон основа оnyx (81)
- 77 CVE1 critCVSS 6.6NEWKEV 3PoC 13astra linux special edition (77) · astra linux special edition для «эльбрус» (6) · astra linux common edition (4)
- 65 CVE2 critCVSS 5.5NEWPoC 10альт 8 сп (63) · альт сп 10 (45)
- 57 CVE1 critCVSS 7.3NEWacrobat (16) · acrobat dc (16) · acrobat reader (16)
- 57 CVE1 critCVSS 7.4NEWadobe acrobat reader document cloud (16) · adobe acrobat 2020 (16) · adobe acrobat reader 2020 (16)
- 54 CVE1 critCVSS 6.5NEWKEV 2Nuclei 1PoC 4fedora (54) · extra packages for enterprise linux (1)
- 54 CVE2 critCVSS 6.1NEWNuclei 54PoC 54w4 post list (3) · simple giveaways (3) · gallery by bestwebsoft (2)
- 54 CVE5 critCVSS 6.5NEWPoC 6ред ос (54)
- 48 CVE1 critCVSS 6.6NEWKEV 2PoC 6debian linux (48)
- 43 CVECVSS 5.9NEWPoC 5linux kernel (43)
- 42 CVECVSS 6.2NEWKEV 1Nuclei 1PoC 40cisco small business rv325 (19) · cisco small business rv320 (19) · cisco small business rv016 (17)
- 40 CVECVSS 6.2NEWKEV 1Nuclei 1PoC 40cisco small business rv series router firmware (20) · rv325 firmware (19) · rv320 firmware (19)
- 40 CVECVSS 5.7NEWPoC 38online computer and laptop store (19) · service provider management system (7) · ac repair and services system (6)
- 38 CVECVSS 6.3NEWvirtual gpu (15) · nvidia dgx servers (11) · vgpu software (guest driver - windows), nvidia cloud gaming (guest driver - windows) (5)
- 38 CVE27 critCVSS 8.8NEWNuclei 4PoC 16xwiki (37) · xwiki-platform (36) · xwiki-commons (2)
- 37 CVECVSS 6.0NEWPoC 37advanced online voting system (9) · coffee shop pos system (8) · online thesis archiving system (6)
- 37 CVE9 critCVSS 7.0NEWNuclei 2PoC 8vm2 (3) · @strapi/plugin-users-permissions (3) · @openzeppelin/contracts-upgradeable (2)
- 34 CVE6 critCVSS 6.9NEWKEV 1Nuclei 3PoC 6apache-superset (4) · modoboa (3) · wagtail (2)
- 34 CVECVSS 6.4NEWPoC 4rosa virtualization 3.0 (16) · роса кобальт (10) · роса хром (9)
- 33 CVE8 critCVSS 8.0NEWqca4004 firmware (23) · wcd9306 firmware (23) · snapdragon x5 lte modem firmware (23)
- 33 CVE8 critCVSS 8.1NEWsnapdragon (33)
- 33 CVE2 critCVSS 6.8NEWKEV 1Nuclei 1PoC 8red hat enterprise linux (30) · openshift serverless (4) · openshift developer tools and services (4)
- 32 CVECVSS 5.3NEWKEV 1PoC 1oncommand insight (21) · active iq unified manager (18) · snapcenter (14)
- 32 CVE31 critCVSS 9.7NEWPoC 6ac5 firmware (12) · ac10 firmware (10) · ac15 firmware (8)
- 30 CVECVSS 6.1NEWmt5221, mt6781, mt6789, mt6833, mt6855, mt6877, mt6879, mt6895, mt6983, mt7663, mt7668, mt7902, mt7921, mt8167s, mt8168, mt8169, mt8175, mt8185, mt8362a, mt8365, mt8385, mt8518, mt8532, mt8675, mt8695, mt8766, mt8768, mt8771, mt8781, mt8786, mt8788, mt8789, mt8791t, mt8797, mt8798 (5) · mt5221, mt6879, mt6895, mt6983, mt7902, mt7921, mt8167s, mt8168, mt8175, mt8362a, mt8365, mt8385, mt8518, mt8532, mt8696, mt8766, mt8768, mt8771, mt8781, mt8786, mt8788, mt8789, mt8791t, mt8795t, mt8797, mt8798 (4) · mt6580, mt6731, mt6735, mt6737, mt6739, mt6753, mt6757, mt6757c, mt6757cd, mt6757ch, mt6761, mt6762, mt6763, mt6765, mt6768, mt6769, mt6771, mt6779, mt6781, mt6785, mt6789, mt6833, mt6853, mt6853t, mt6855, mt6873, mt6875, mt6877, mt6879, mt6883, mt6885, mt6889, mt6891, mt6893, mt6895, mt6983, mt8185, mt8192, mt8321, mt8385, mt8666, mt8667, mt8673, mt8675, mt8765, mt8766, mt8768, mt8771, mt8781, mt8786, mt8788, mt8789, mt8791, mt8791t, mt8795t, mt8797, mt8798, mt8871, mt8891 (3)
- 26 CVE1 critCVSS 5.4NEWNuclei 1PoC 1gitlab (26)
- 26 CVE3 critCVSS 7.4NEWPoC 6github.com/docker/docker (3) · github.com/bnb-chain/tss-lib (3) · github.com/binance-chain/tss-lib (3)
- 26 CVECVSS 6.5NEWPoC 1db2 for linux, unix and windows (7) · db2 (7) · safer payments (3)
- 25 CVECVSS 6.5NEWPoC 24junos (19) · junos os evolved (10) · appid service sigpack (1)
- 25 CVECVSS 6.5NEWPoC 24junos os (18) · junos os evolved (10) · jdpi-decoder engine (1)
- 25 CVE1 critCVSS 6.1NEWKEV 1PoC 6suse linux enterprise server for sap applications (24) · suse linux enterprise desktop (24) · suse linux enterprise server (24)
- 24 CVE3 critCVSS 7.6NEWstruxureware data center expert (9) · apc easy ups online monitoring software (windows 10, 11 windows server 2016, 2019, 2022) (3) · easy ups online (3)
- 24 CVE3 critCVSS 7.5NEWstruxureware data center expert (9) · easy ups online monitoring software (3) · netbotz 355 firmware (3)
- 22 CVE1 critCVSS 7.7NEWKEV 2google chrome (20) · protobuf-c (1) · android (1)
- 22 CVECVSS 4.9NEWmagic r200 firmware (13) · magic r100 firmware (9)
- 21 CVE8 critCVSS 7.6NEWKEV 1Nuclei 2PoC 1linkis (5) · superset (4) · apache-airflow-providers-apache-spark (1)
- 21 CVE8 critCVSS 7.8NEWKEV 1Nuclei 2PoC 1apache linkis (5) · apache superset (4) · apache spark (1)
- 20 CVE1 critCVSS 6.8NEWfortios (4) · fortiproxy (4) · forticlient (4)
- 20 CVECVSS 5.8NEWreport portal (4) · wso2 oauth (2) · consul kv builder (2)
- 20 CVECVSS 5.8NEWjenkins report portal plugin (4) · jenkins consul kv builder plugin (2) · jenkins quay.io trigger plugin (2)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | microsoft corp | 111 | 3 | 4 | · | NEWKEV 4PoC 6 | windows server 2022 (server core installation) (73) · windows server 2022 (73) · windows server 2019 (server core installation) (70) | — | |
| 2 | microsoft | 104 | 3 | 2 | · | NEWKEV 2PoC 6 | windows server 2022 (73) · windows server 2019 (server core installation) (70) · windows server 2019 (70) | — | |
| 3 | сообщество свободного программного обеспечения | 102 | 15 | · | 3 | NEWNuclei 3PoC 32 | debian gnu/linux (47) · linux (32) · xwiki platform (13) | — | |
| 4 | 100 | 2 | 2 | · | NEWKEV 2 | android (79) · chrome (20) · espv2 (1) | — | ||
| 5 | sourcecodester | 98 | · | · | 1 | NEWNuclei 1PoC 90 | online computer and laptop store (19) · vehicle service management system (9) · online payroll system (9) | — | |
| 6 | maven | 94 | 40 | · | 9 | NEWNuclei 9PoC 20 | org.xwiki.platform:xwiki-platform-oldcore (5) · tech.powerjob:powerjob (5) · org.xwiki.platform:xwiki-platform-web-templates (4) | — | |
| 7 | oracle corp. | 92 | · | · | 3 | NEWNuclei 3PoC 2 | mysql server (23) · vm virtualbox (10) · graalvm enterprise edition (8) | — | |
| 8 | oracle | 91 | · | · | 3 | NEWNuclei 3PoC 1 | mysql server (18) · vm virtualbox (10) · graalvm (8) | — | |
| 9 | oracle corporation | 91 | · | · | 3 | NEWNuclei 3PoC 1 | mysql server (23) · vm virtualbox (10) · java se jdk and jre (7) | — | |
| 10 | packagist | 91 | 8 | · | 10 | NEWNuclei 10PoC 27 | pimcore/pimcore (16) · thorsten/phpmyfaq (15) · concrete5/concrete5 (10) | — | |
| 11 | ао "нппкт" | 81 | 2 | 3 | 1 | NEWKEV 3Nuclei 1PoC 6 | осон основа оnyx (81) | — | |
| 12 | ооо «русбитех-астра» | 77 | 1 | 3 | · | NEWKEV 3PoC 13 | astra linux special edition (77) · astra linux special edition для «эльбрус» (6) · astra linux common edition (4) | — | |
| 13 | ао «ивк» | 65 | 2 | · | · | NEWPoC 10 | альт 8 сп (63) · альт сп 10 (45) | — | |
| 14 | adobe | 57 | 1 | · | · | NEW | acrobat (16) · acrobat dc (16) · acrobat reader (16) | — | |
| 15 | adobe systems inc. | 57 | 1 | · | · | NEW | adobe acrobat reader document cloud (16) · adobe acrobat 2020 (16) · adobe acrobat reader 2020 (16) | — | |
| 16 | fedoraproject | 54 | 1 | 2 | 1 | NEWKEV 2Nuclei 1PoC 4 | fedora (54) · extra packages for enterprise linux (1) | — | |
| 17 | unknown | 54 | 2 | · | 54 | NEWNuclei 54PoC 54 | w4 post list (3) · simple giveaways (3) · gallery by bestwebsoft (2) | — | |
| 18 | ооо «ред софт» | 54 | 5 | · | · | NEWPoC 6 | ред ос (54) | — | |
| 19 | debian | 48 | 1 | 2 | · | NEWKEV 2PoC 6 | debian linux (48) | — | |
| 20 | linux | 43 | · | · | · | NEWPoC 5 | linux kernel (43) | — | |
| 21 | cisco systems inc. | 42 | · | 1 | 1 | NEWKEV 1Nuclei 1PoC 40 | cisco small business rv325 (19) · cisco small business rv320 (19) · cisco small business rv016 (17) | — | |
| 22 | cisco | 40 | · | 1 | 1 | NEWKEV 1Nuclei 1PoC 40 | cisco small business rv series router firmware (20) · rv325 firmware (19) · rv320 firmware (19) | — | |
| 23 | oretnom23 | 40 | · | · | · | NEWPoC 38 | online computer and laptop store (19) · service provider management system (7) · ac repair and services system (6) | — | |
| 24 | nvidia | 38 | · | · | · | NEW | virtual gpu (15) · nvidia dgx servers (11) · vgpu software (guest driver - windows), nvidia cloud gaming (guest driver - windows) (5) | — | |
| 25 | xwiki | 38 | 27 | · | 4 | NEWNuclei 4PoC 16 | xwiki (37) · xwiki-platform (36) · xwiki-commons (2) | — | |
| 26 | campcodes | 37 | · | · | · | NEWPoC 37 | advanced online voting system (9) · coffee shop pos system (8) · online thesis archiving system (6) | — | |
| 27 | npm | 37 | 9 | · | 2 | NEWNuclei 2PoC 8 | vm2 (3) · @strapi/plugin-users-permissions (3) · @openzeppelin/contracts-upgradeable (2) | — | |
| 28 | pypi | 34 | 6 | 1 | 3 | NEWKEV 1Nuclei 3PoC 6 | apache-superset (4) · modoboa (3) · wagtail (2) | — | |
| 29 | ао «нтц ит роса» | 34 | · | · | · | NEWPoC 4 | rosa virtualization 3.0 (16) · роса кобальт (10) · роса хром (9) | — | |
| 30 | qualcomm | 33 | 8 | · | · | NEW | qca4004 firmware (23) · wcd9306 firmware (23) · snapdragon x5 lte modem firmware (23) | — | |
| 31 | qualcomm, inc. | 33 | 8 | · | · | NEW | snapdragon (33) | — | |
| 32 | red hat inc. | 33 | 2 | 1 | 1 | NEWKEV 1Nuclei 1PoC 8 | red hat enterprise linux (30) · openshift serverless (4) · openshift developer tools and services (4) | — | |
| 33 | netapp | 32 | · | 1 | · | NEWKEV 1PoC 1 | oncommand insight (21) · active iq unified manager (18) · snapcenter (14) | — | |
| 34 | tenda | 32 | 31 | · | · | NEWPoC 6 | ac5 firmware (12) · ac10 firmware (10) · ac15 firmware (8) | — | |
| 35 | mediatek, inc. | 30 | · | · | · | NEW | mt5221, mt6781, mt6789, mt6833, mt6855, mt6877, mt6879, mt6895, mt6983, mt7663, mt7668, mt7902, mt7921, mt8167s, mt8168, mt8169, mt8175, mt8185, mt8362a, mt8365, mt8385, mt8518, mt8532, mt8675, mt8695, mt8766, mt8768, mt8771, mt8781, mt8786, mt8788, mt8789, mt8791t, mt8797, mt8798 (5) · mt5221, mt6879, mt6895, mt6983, mt7902, mt7921, mt8167s, mt8168, mt8175, mt8362a, mt8365, mt8385, mt8518, mt8532, mt8696, mt8766, mt8768, mt8771, mt8781, mt8786, mt8788, mt8789, mt8791t, mt8795t, mt8797, mt8798 (4) · mt6580, mt6731, mt6735, mt6737, mt6739, mt6753, mt6757, mt6757c, mt6757cd, mt6757ch, mt6761, mt6762, mt6763, mt6765, mt6768, mt6769, mt6771, mt6779, mt6781, mt6785, mt6789, mt6833, mt6853, mt6853t, mt6855, mt6873, mt6875, mt6877, mt6879, mt6883, mt6885, mt6889, mt6891, mt6893, mt6895, mt6983, mt8185, mt8192, mt8321, mt8385, mt8666, mt8667, mt8673, mt8675, mt8765, mt8766, mt8768, mt8771, mt8781, mt8786, mt8788, mt8789, mt8791, mt8791t, mt8795t, mt8797, mt8798, mt8871, mt8891 (3) | — | |
| 36 | gitlab | 26 | 1 | · | 1 | NEWNuclei 1PoC 1 | gitlab (26) | — | |
| 37 | go | 26 | 3 | · | · | NEWPoC 6 | github.com/docker/docker (3) · github.com/bnb-chain/tss-lib (3) · github.com/binance-chain/tss-lib (3) | — | |
| 38 | ibm | 26 | · | · | · | NEWPoC 1 | db2 for linux, unix and windows (7) · db2 (7) · safer payments (3) | — | |
| 39 | juniper | 25 | · | · | · | NEWPoC 24 | junos (19) · junos os evolved (10) · appid service sigpack (1) | — | |
| 40 | juniper networks | 25 | · | · | · | NEWPoC 24 | junos os (18) · junos os evolved (10) · jdpi-decoder engine (1) | — | |
| 41 | novell inc. | 25 | 1 | 1 | · | NEWKEV 1PoC 6 | suse linux enterprise server for sap applications (24) · suse linux enterprise desktop (24) · suse linux enterprise server (24) | — | |
| 42 | schneider electric | 24 | 3 | · | · | NEW | struxureware data center expert (9) · apc easy ups online monitoring software (windows 10, 11 windows server 2016, 2019, 2022) (3) · easy ups online (3) | — | |
| 43 | schneider-electric | 24 | 3 | · | · | NEW | struxureware data center expert (9) · easy ups online monitoring software (3) · netbotz 355 firmware (3) | — | |
| 44 | google inc | 22 | 1 | 2 | · | NEWKEV 2 | google chrome (20) · protobuf-c (1) · android (1) | — | |
| 45 | h3c | 22 | · | · | · | NEW | magic r200 firmware (13) · magic r100 firmware (9) | — | |
| 46 | apache | 21 | 8 | 1 | 2 | NEWKEV 1Nuclei 2PoC 1 | linkis (5) · superset (4) · apache-airflow-providers-apache-spark (1) | — | |
| 47 | apache software foundation | 21 | 8 | 1 | 2 | NEWKEV 1Nuclei 2PoC 1 | apache linkis (5) · apache superset (4) · apache spark (1) | — | |
| 48 | fortinet | 20 | 1 | · | · | NEW | fortios (4) · fortiproxy (4) · forticlient (4) | — | |
| 49 | jenkins | 20 | · | · | · | NEW | report portal (4) · wso2 oauth (2) · consul kv builder (2) | — | |
| 50 | jenkins project | 20 | · | · | · | NEW | jenkins report portal plugin (4) · jenkins consul kv builder plugin (2) · jenkins quay.io trigger plugin (2) | — |