month report
May 2023
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
May 2023 closed with 2,766 published CVEs. 259 criticals, 19 added to CISA KEV (1 ransomware-linked). сообщество свободного программного обеспечения led volume, mostly via debian gnu/linux. Top weakness class — CWE-79 (462 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
2,766
— MoM— YoY
Severity mix
259 / 796
critical / high
KEV added
19
1 ransomware-linked
Nuclei coverage
16.2%
447 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
1025.5
n=447
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
14
n=8
Detection gap
KEV pressure, no Nuclei coverage
May 2023 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 2microsoft corp61 CVE
- KEV 2microsoft56 CVE
- KEV 1samsung32 CVE
- KEV 1samsung mobile31 CVE
Weakness × Vendor
What's spreading where in May 2023
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS787Out-of-bounds Write89SQL Injection352CSRF20Improper Input Validation22Path Traversal120Buffer Overflow125Out-of-bounds Read77Command Injection862Missing Authorizationсообщество свободного программного обеспечения51127411042google331281127maven2021113312intel713123ооо «ред софт»626211631ао "нппкт"711311unknown2132ооо «русбитех-астра»712711apple82861unisoc (shanghai) technologies co., ltd.228326microsoft corp122sourcecodester1639
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #1сообщество свободного программного обеспечения149 CVE
- #2google138 CVE
- #3maven99 CVE
- #4intel94 CVE
- #5ооо «ред софт»92 CVE
- #6ао "нппкт"88 CVE
- #7unknown85 CVE
- #8ооо «русбитех-астра»80 CVE
- #9apple71 CVE
- #10unisoc (shanghai) technologies co., ltd.66 CVE
Top vendors
Ranked by distinct CVE count this period.
- 149 CVE11 critCVSS 7.1NEWNuclei 2PoC 54debian gnu/linux (92) · linux (25) · openemr (10)
- 138 CVE1 critCVSS 6.2NEWNuclei 1PoC 4android (106) · chrome (31) · web stories (1)
- 99 CVE15 critCVSS 7.1NEWKEV 2Nuclei 4PoC 5com.liferay.portal:release.portal.bom (14) · org.apache.inlong:manager-service (8) · org.apache.inlong:manager-pojo (7)
- 94 CVECVSS 5.9NEWserver system d50tnp1mhcrac firmware (10) · server system d50tnp1mhcrlc firmware (10) · server system d50tnp2mfalac firmware (10)
- 92 CVE5 critCVSS 6.8NEWKEV 1Nuclei 1PoC 40ред ос (92)
- 88 CVE3 critCVSS 6.8NEWPoC 17осон основа оnyx (88)
- 85 CVE7 critCVSS 6.3NEWNuclei 83PoC 83ai chatbot (5) · clock in portal- staff & attendance management (3) · product catalog feed by pixelyoursite (2)
- 80 CVE1 critCVSS 6.6NEWPoC 14astra linux special edition (77) · astra linux special edition для «эльбрус» (4) · astra linux common edition (4)
- 71 CVE4 critCVSS 6.5NEWPoC 3macos (64) · ipados (41) · iphone os (41)
- 66 CVECVSS 5.5NEWsc9863a/sc9832e/sc7731e/t610/t310/t606/t760/t610/t618/t606/t612/t616/t760/t770/t820/s8000 (66)
- 61 CVE3 critCVSS 7.4NEWKEV 2PoC 2windows server 2019 (server core installation) (36) · windows server 2019 (36) · windows 10 20h2 (35)
- 57 CVECVSS 5.5NEWPoC 55lost and found information system (12) · online exam system (8) · online computer and laptop store (5)
- 56 CVE3 critCVSS 7.4NEWKEV 2PoC 1windows 11 21h2 (37) · windows server 2022 (37) · windows 11 version 21h2 (36)
- 51 CVE3 critCVSS 6.4NEWNuclei 4PoC 14pimcore/pimcore (11) · craftcms/cms (8) · thorsten/phpmyfaq (6)
- 48 CVECVSS 6.4NEWPoC 8debian linux (48)
- 45 CVE2 critCVSS 6.6NEWNuclei 1PoC 9fedora (45) · extra packages for enterprise linux (5)
- 38 CVE1 critCVSS 6.2NEWPoC 8альт 8 сп (31) · альт сп 10 (27)
- 36 CVECVSS 5.8NEWcode dx (5) · jenkins code dx plugin (5) · saml single sign on (5)
- 35 CVE4 critCVSS 5.8NEWNuclei 1PoC 5github.com/kyverno/kyverno (2) · github.com/sigstore/rekor (2) · github.com/pydio/cells (2)
- 33 CVECVSS 7.4NEWPoC 4google chrome (31) · chromeos flex (2) · chrome os (2)
- 32 CVE1 critCVSS 6.2NEWmq (5) · infosphere information server (4) · mq appliance (3)
- 32 CVECVSS 5.6NEWKEV 1android (21) · samsung blockchain keystore (6) · galaxy store (3)
- 31 CVE10 critCVSS 7.9NEWKEV 1Nuclei 1PoC 1inlong (11) · streampark (3) · openmeetings (3)
- 31 CVE10 critCVSS 7.8NEWKEV 1Nuclei 1PoC 1apache inlong (11) · inlong (6) · apache streampark (incubating) (3)
- 31 CVECVSS 6.1NEWjenkins saml single sign on(sso) plugin (6) · jenkins azure vm agents plugin (3) · jenkins appspider plugin (2)
- 31 CVE5 critCVSS 6.9NEWNuclei 1PoC 5vyper (5) · mlflow (3) · matrix-synapse (3)
- 31 CVECVSS 5.9NEWKEV 1samsung mobile devices (21) · samsung blockchain keystore (6) · galaxy store (3)
- 29 CVE1 critCVSS 7.3NEWPoC 26ubuntu (29) · ubuntu-linux (1)
- 28 CVE1 critCVSS 8.5NEWPoC 28identity services engine (11) · cisco identity services engine software (11) · business 350-48t-4x firmware (9)
- 28 CVE1 critCVSS 7.8NEWPoC 28cisco identity services engine (11) · business 250 series smart switches (9) · business 350 series managed switches (9)
- 28 CVE4 critCVSS 7.5NEWPoC 7red hat enterprise linux (23) · red hat openstack platform (4) · red hat jboss core services (4)
- 27 CVE4 critCVSS 7.3NEWNuclei 2PoC 3n8n (3) · vm2 (2) · ghost (2)
- 26 CVE6 critCVSS 7.4NEWepyc 7443 firmware (14) · epyc 7413 firmware (14) · epyc 7543p firmware (14)
- 26 CVE3 critCVSS 6.3NEWPoC 22lost and found information system (12) · online computer and laptop store (6) · establishment billing management system (2)
- 25 CVECVSS 5.7NEWmt6853, mt6853t, mt6873, mt6875, mt6877, mt6879, mt6883, mt6885, mt6889, mt6891, mt6893, mt8183, mt8195 (4) · mt6580, mt6731, mt6735, mt6737, mt6739, mt6753, mt6757, mt6757c, mt6757cd, mt6757ch, mt6761, mt6762, mt6763, mt6765, mt6768, mt6769, mt6771, mt6779, mt6781, mt6785, mt6789, mt6833, mt6853, mt6853t, mt6855, mt6873, mt6875, mt6877, mt6879, mt6883, mt6885, mt6889, mt6891, mt6893, mt6895, mt6983, mt8185, mt8321, mt8385, mt8666, mt8667, mt8765, mt8766, mt8768, mt8781, mt8786, mt8788, mt8789, mt8791, mt8791t, mt8797 (3) · mt6580, mt6731, mt6735, mt6737, mt6739, mt6753, mt6757, mt6757c, mt6757cd, mt6757ch, mt6761, mt6762, mt6763, mt6765, mt6768, mt6769, mt6771, mt6779, mt6781, mt6785, mt6789, mt6833, mt6853, mt6853t, mt6855, mt6873, mt6875, mt6877, mt6879, mt6883, mt6885, mt6889, mt6891, mt6893, mt6895, mt6983, mt8185, mt8321, mt8385, mt8666, mt8667, mt8673, mt8675, mt8765, mt8766, mt8768, mt8781, mt8786, mt8788, mt8789, mt8791, mt8791t, mt8797 (2)
- 25 CVECVSS 7.5NEWPoC 25virtuoso (25)
- 24 CVE2 critCVSS 7.2NEWNuclei 1PoC 9fedora (24)
- 24 CVE8 critCVSS 7.5NEWaruba access points running instantos and arubaos 10 (13) · aruba edgeconnect enterprise software (10) · hpe proliant rl300 gen11 (1)
- 24 CVECVSS 7.5NEWPoC 24virtuoso-opensource (24)
- 24 CVE1 critCVSS 6.5NEWPoC 8роса хром (10) · rosa virtualization 3.0 (9) · rosa virtualization (7)
- 21 CVE2 critCVSS 7.3NEWPoC 5enterprise linux (18) · enterprise linux server aus (3) · enterprise linux eus (3)
- 20 CVE2 critCVSS 7.3NEWNuclei 1PoC 3magic r300-2100m firmware (17) · gr-1200w firmware (2) · magic r160 firmware (1)
- 20 CVE2 critCVSS 5.1NEWsel-3560s (19) · sel-3350 (19) · sel-3505 (19)
- 20 CVE2 critCVSS 5.2NEWsel-3555 firmware (20) · sel-3350 firmware (20) · sel-3532 firmware (20)
- 19 CVE3 critCVSS 7.4NEWemui (17) · harmonyos (17)
- 19 CVECVSS 6.5NEWPoC 3linux kernel (19)
- 18 CVECVSS 8.2NEWcontrol for beaglebone sl (17) · control for empc-a\/imx6 sl (17) · control for iot2000 sl (17)
- 17 CVECVSS 8.3NEWcodesys control for beaglebone sl (16) · codesys control for empc-a/imx6 sl (16) · codesys control for iot2000 sl (16)
- 17 CVE1 critCVSS 6.9NEWPoC 4suse linux enterprise server (14) · opensuse leap (13) · suse linux enterprise server for sap applications (13)
- 17 CVECVSS 8.4NEWmodicon m262 (15) · hmiscu (15) · modicon lmc058 (15)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | сообщество свободного программного обеспечения | 149 | 11 | · | 2 | NEWNuclei 2PoC 54 | debian gnu/linux (92) · linux (25) · openemr (10) | — | |
| 2 | 138 | 1 | · | 1 | NEWNuclei 1PoC 4 | android (106) · chrome (31) · web stories (1) | — | ||
| 3 | maven | 99 | 15 | 2 | 4 | NEWKEV 2Nuclei 4PoC 5 | com.liferay.portal:release.portal.bom (14) · org.apache.inlong:manager-service (8) · org.apache.inlong:manager-pojo (7) | — | |
| 4 | intel | 94 | · | · | · | NEW | server system d50tnp1mhcrac firmware (10) · server system d50tnp1mhcrlc firmware (10) · server system d50tnp2mfalac firmware (10) | — | |
| 5 | ооо «ред софт» | 92 | 5 | 1 | 1 | NEWKEV 1Nuclei 1PoC 40 | ред ос (92) | — | |
| 6 | ао "нппкт" | 88 | 3 | · | · | NEWPoC 17 | осон основа оnyx (88) | — | |
| 7 | unknown | 85 | 7 | · | 83 | NEWNuclei 83PoC 83 | ai chatbot (5) · clock in portal- staff & attendance management (3) · product catalog feed by pixelyoursite (2) | — | |
| 8 | ооо «русбитех-астра» | 80 | 1 | · | · | NEWPoC 14 | astra linux special edition (77) · astra linux special edition для «эльбрус» (4) · astra linux common edition (4) | — | |
| 9 | apple | 71 | 4 | · | · | NEWPoC 3 | macos (64) · ipados (41) · iphone os (41) | — | |
| 10 | unisoc (shanghai) technologies co., ltd. | 66 | · | · | · | NEW | sc9863a/sc9832e/sc7731e/t610/t310/t606/t760/t610/t618/t606/t612/t616/t760/t770/t820/s8000 (66) | — | |
| 11 | microsoft corp | 61 | 3 | 2 | · | NEWKEV 2PoC 2 | windows server 2019 (server core installation) (36) · windows server 2019 (36) · windows 10 20h2 (35) | — | |
| 12 | sourcecodester | 57 | · | · | · | NEWPoC 55 | lost and found information system (12) · online exam system (8) · online computer and laptop store (5) | — | |
| 13 | microsoft | 56 | 3 | 2 | · | NEWKEV 2PoC 1 | windows 11 21h2 (37) · windows server 2022 (37) · windows 11 version 21h2 (36) | — | |
| 14 | packagist | 51 | 3 | · | 4 | NEWNuclei 4PoC 14 | pimcore/pimcore (11) · craftcms/cms (8) · thorsten/phpmyfaq (6) | — | |
| 15 | debian | 48 | · | · | · | NEWPoC 8 | debian linux (48) | — | |
| 16 | fedoraproject | 45 | 2 | · | 1 | NEWNuclei 1PoC 9 | fedora (45) · extra packages for enterprise linux (5) | — | |
| 17 | ао «ивк» | 38 | 1 | · | · | NEWPoC 8 | альт 8 сп (31) · альт сп 10 (27) | — | |
| 18 | jenkins | 36 | · | · | · | NEW | code dx (5) · jenkins code dx plugin (5) · saml single sign on (5) | — | |
| 19 | go | 35 | 4 | · | 1 | NEWNuclei 1PoC 5 | github.com/kyverno/kyverno (2) · github.com/sigstore/rekor (2) · github.com/pydio/cells (2) | — | |
| 20 | google inc | 33 | · | · | · | NEWPoC 4 | google chrome (31) · chromeos flex (2) · chrome os (2) | — | |
| 21 | ibm | 32 | 1 | · | · | NEW | mq (5) · infosphere information server (4) · mq appliance (3) | — | |
| 22 | samsung | 32 | · | 1 | · | NEWKEV 1 | android (21) · samsung blockchain keystore (6) · galaxy store (3) | — | |
| 23 | apache | 31 | 10 | 1 | 1 | NEWKEV 1Nuclei 1PoC 1 | inlong (11) · streampark (3) · openmeetings (3) | — | |
| 24 | apache software foundation | 31 | 10 | 1 | 1 | NEWKEV 1Nuclei 1PoC 1 | apache inlong (11) · inlong (6) · apache streampark (incubating) (3) | — | |
| 25 | jenkins project | 31 | · | · | · | NEW | jenkins saml single sign on(sso) plugin (6) · jenkins azure vm agents plugin (3) · jenkins appspider plugin (2) | — | |
| 26 | pypi | 31 | 5 | · | 1 | NEWNuclei 1PoC 5 | vyper (5) · mlflow (3) · matrix-synapse (3) | — | |
| 27 | samsung mobile | 31 | · | 1 | · | NEWKEV 1 | samsung mobile devices (21) · samsung blockchain keystore (6) · galaxy store (3) | — | |
| 28 | canonical ltd. | 29 | 1 | · | · | NEWPoC 26 | ubuntu (29) · ubuntu-linux (1) | — | |
| 29 | cisco | 28 | 1 | · | · | NEWPoC 28 | identity services engine (11) · cisco identity services engine software (11) · business 350-48t-4x firmware (9) | — | |
| 30 | cisco systems inc. | 28 | 1 | · | · | NEWPoC 28 | cisco identity services engine (11) · business 250 series smart switches (9) · business 350 series managed switches (9) | — | |
| 31 | red hat inc. | 28 | 4 | · | · | NEWPoC 7 | red hat enterprise linux (23) · red hat openstack platform (4) · red hat jboss core services (4) | — | |
| 32 | npm | 27 | 4 | · | 2 | NEWNuclei 2PoC 3 | n8n (3) · vm2 (2) · ghost (2) | — | |
| 33 | amd | 26 | 6 | · | · | NEW | epyc 7443 firmware (14) · epyc 7413 firmware (14) · epyc 7543p firmware (14) | — | |
| 34 | oretnom23 | 26 | 3 | · | · | NEWPoC 22 | lost and found information system (12) · online computer and laptop store (6) · establishment billing management system (2) | — | |
| 35 | mediatek, inc. | 25 | · | · | · | NEW | mt6853, mt6853t, mt6873, mt6875, mt6877, mt6879, mt6883, mt6885, mt6889, mt6891, mt6893, mt8183, mt8195 (4) · mt6580, mt6731, mt6735, mt6737, mt6739, mt6753, mt6757, mt6757c, mt6757cd, mt6757ch, mt6761, mt6762, mt6763, mt6765, mt6768, mt6769, mt6771, mt6779, mt6781, mt6785, mt6789, mt6833, mt6853, mt6853t, mt6855, mt6873, mt6875, mt6877, mt6879, mt6883, mt6885, mt6889, mt6891, mt6893, mt6895, mt6983, mt8185, mt8321, mt8385, mt8666, mt8667, mt8765, mt8766, mt8768, mt8781, mt8786, mt8788, mt8789, mt8791, mt8791t, mt8797 (3) · mt6580, mt6731, mt6735, mt6737, mt6739, mt6753, mt6757, mt6757c, mt6757cd, mt6757ch, mt6761, mt6762, mt6763, mt6765, mt6768, mt6769, mt6771, mt6779, mt6781, mt6785, mt6789, mt6833, mt6853, mt6853t, mt6855, mt6873, mt6875, mt6877, mt6879, mt6883, mt6885, mt6889, mt6891, mt6893, mt6895, mt6983, mt8185, mt8321, mt8385, mt8666, mt8667, mt8673, mt8675, mt8765, mt8766, mt8768, mt8781, mt8786, mt8788, mt8789, mt8791, mt8791t, mt8797 (2) | — | |
| 36 | openlinksw | 25 | · | · | · | NEWPoC 25 | virtuoso (25) | — | |
| 37 | fedora project | 24 | 2 | · | 1 | NEWNuclei 1PoC 9 | fedora (24) | — | |
| 38 | hewlett packard enterprise (hpe) | 24 | 8 | · | · | NEW | aruba access points running instantos and arubaos 10 (13) · aruba edgeconnect enterprise software (10) · hpe proliant rl300 gen11 (1) | — | |
| 39 | openlink software | 24 | · | · | · | NEWPoC 24 | virtuoso-opensource (24) | — | |
| 40 | ао «нтц ит роса» | 24 | 1 | · | · | NEWPoC 8 | роса хром (10) · rosa virtualization 3.0 (9) · rosa virtualization (7) | — | |
| 41 | redhat | 21 | 2 | · | · | NEWPoC 5 | enterprise linux (18) · enterprise linux server aus (3) · enterprise linux eus (3) | — | |
| 42 | h3c | 20 | 2 | · | 1 | NEWNuclei 1PoC 3 | magic r300-2100m firmware (17) · gr-1200w firmware (2) · magic r160 firmware (1) | — | |
| 43 | schweitzer engineering laboratories | 20 | 2 | · | · | NEW | sel-3560s (19) · sel-3350 (19) · sel-3505 (19) | — | |
| 44 | selinc | 20 | 2 | · | · | NEW | sel-3555 firmware (20) · sel-3350 firmware (20) · sel-3532 firmware (20) | — | |
| 45 | huawei | 19 | 3 | · | · | NEW | emui (17) · harmonyos (17) | — | |
| 46 | linux | 19 | · | · | · | NEWPoC 3 | linux kernel (19) | — | |
| 47 | codesys | 18 | · | · | · | NEW | control for beaglebone sl (17) · control for empc-a\/imx6 sl (17) · control for iot2000 sl (17) | — | |
| 48 | codesys gmbh | 17 | · | · | · | NEW | codesys control for beaglebone sl (16) · codesys control for empc-a/imx6 sl (16) · codesys control for iot2000 sl (16) | — | |
| 49 | novell inc. | 17 | 1 | · | · | NEWPoC 4 | suse linux enterprise server (14) · opensuse leap (13) · suse linux enterprise server for sap applications (13) | — | |
| 50 | schneider electric | 17 | · | · | · | NEW | modicon m262 (15) · hmiscu (15) · modicon lmc058 (15) | — |