month report
February 2024
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
February 2024 closed with 2,983 published CVEs. 322 criticals, 9 added to CISA KEV (4 ransomware-linked). сообщество свободного программного обеспечения led volume, mostly via linux. Top weakness class — CWE-79 (438 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
2,983
— MoM— YoY
Severity mix
322 / 892
critical / high
KEV added
9
4 ransomware-linked
Nuclei coverage
15.4%
459 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
753.2
n=459
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
20
n=11
Detection gap
KEV pressure, no Nuclei coverage
February 2024 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 5microsoft corp88 CVE
Weakness × Vendor
What's spreading where in February 2024
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS89SQL Injection787Out-of-bounds Write352CSRF284CWE-284416Use After Free476NULL Pointer Dereference862Missing Authorization22Path Traversal125Out-of-bounds Readсообщество свободного программного обеспечения221115262219linux9445815ооо «ред софт»21131253118ооо «русбитех-астра»215126258ао "нппкт"1181954ао «ивк»169156maven1631313microsoft corp8115733ibm811212microsoft824522canonical ltd.6954intel12411
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #22oracle corp.45 CVE
- #23oracle43 CVE
- #24oracle corporation43 CVE
- #27liferay35 CVE
- #30qnap32 CVE
- #31qnap systems inc.32 CVE
- #32qnap systems, inc.32 CVE
- #36code-projects28 CVE
- #37siemens28 CVE
- #39red hat27 CVE
Top vendors
Ranked by distinct CVE count this period.
- 405 CVE10 critCVSS 6.4PoC 28linux (303) · debian gnu/linux (194) · gguf (5)
- 299 CVECVSS 6.1PoC 4linux kernel (299) · linux (279)
- 205 CVE4 critCVSS 6.6PoC 21ред ос (205)
- 183 CVE3 critCVSS 6.5PoC 17astra linux special edition (144) · astra linux special edition для «эльбрус» (60) · astra linux common edition (8)
- 96 CVE4 critCVSS 6.7PoC 12осон основа оnyx (96)
- 92 CVECVSS 6.3PoC 10альт сп 10 (84) · альт 8 сп (56)
- 89 CVE20 critCVSS 7.2Nuclei 1PoC 6com.liferay.portal:release.portal.bom (33) · com.liferay.portal:release.dxp.bom (32) · org.apache.dolphinscheduler:dolphinscheduler (4)
- 88 CVE9 critCVSS 7.9KEV 5PoC 4windows server 2022, 23h2 edition (server core installation) (44) · windows 11 23h2 (43) · windows 11 22h2 (43)
- 86 CVE2 critCVSS 6.0Nuclei 2PoC 1powersc (13) · security verify access appliance (12) · security verify access docker (12)
- 81 CVE8 critCVSS 7.8KEV 5Nuclei 1PoC 3windows server 2022 23h2 (43) · windows server 2022, 23h2 edition (server core installation) (42) · windows 11 version 22h2 (41)
- 76 CVECVSS 6.4PoC 8ubuntu (74) · ubuntu edk ii (1) · lxd (1)
- 75 CVECVSS 6.1thunderbolt dch driver (20) · proset\/wireless (9) · killer (9)
- 72 CVECVSS 5.6thunderbolt dch driver (21) · intel killer wi-fi (10) · intel proset/wireless wifi (10)
- 71 CVE1 critCVSS 6.5PoC 6rosa virtualization 3.0 (53) · роса хром (19) · роса кобальт (12)
- 69 CVE11 critCVSS 7.1PoC 16fedora (68) · unbound (1)
- 66 CVE12 critCVSS 6.9Nuclei 4PoC 9vyper (6) · apache-superset (6) · clearml (3)
- 64 CVE6 critCVSS 6.2Nuclei 2PoC 8moodle/moodle (7) · getkirby/cms (6) · typo3/cms-core (4)
- 63 CVE3 critCVSS 6.8PoC 6red hat enterprise linux (59) · red hat enterprise linux workstation (6) · red hat enterprise linux server (6)
- 62 CVE4 critCVSS 7.2PoC 2android (50) · chrome (12)
- 52 CVE2 critCVSS 5.5PoC 3github.com/mattermost/mattermost/server/v8 (11) · github.com/greenpau/caddy-security (10) · github.com/apache/incubator-answer (3)
- 47 CVE5 critCVSS 6.8unity (16) · unity operating environment (16) · supportassist for home pcs (3)
- 45 CVECVSS 5.6NEWKEV 1Nuclei 1PoC 1mysql server (10) · e-business suite (9) · graalvm enterprise edition (5)
- 43 CVECVSS 5.3NEWKEV 1Nuclei 1mysql server (12) · graalvm (5) · jre (5)
- 43 CVECVSS 5.5NEWKEV 1Nuclei 1mysql server (12) · java se jdk and jre (5) · installed base (4)
- 41 CVE11 critCVSS 7.3PoC 4superset (6) · dolphinscheduler (5) · solr (4)
- 38 CVE8 critCVSS 7.3PoC 2apache superset (6) · apache dolphinscheduler (5) · apache solr (4)
- 35 CVE13 critCVSS 7.1NEWNuclei 1digital experience platform (35) · liferay portal (34) · dxp (33)
- 34 CVE3 critCVSS 7.5PoC 7fedora (34)
- 33 CVE2 critCVSS 6.5PoC 7debian linux (33)
- 32 CVE1 critCVSS 5.6NEWNuclei 1PoC 2qts (29) · qutscloud (29) · quts hero (28)
- 32 CVE1 critCVSS 5.7NEWNuclei 1PoC 2quts hero (29) · qts (29) · qutscloud (28)
- 32 CVE1 critCVSS 5.7NEWNuclei 1PoC 2qts (29) · quts hero (28) · qutscloud (28)
- 31 CVE3 critCVSS 6.8acrobat (14) · acrobat dc (14) · acrobat reader (14)
- 31 CVE3 critCVSS 6.8adobe acrobat 2020 (14) · adobe acrobat document cloud (14) · adobe acrobat reader 2020 (14)
- 29 CVE4 critCVSS 7.0Nuclei 1PoC 8stimulsoft-dashboards-js (3) · ckeditor4 (2) · undici (2)
- 28 CVE6 critCVSS 7.7NEWPoC 14simple school management system (8) · library system (5) · task manager (5)
- 28 CVE1 critCVSS 7.1NEWtecnomatix plant simulation v2201 (10) · tecnomatix plant simulation (10) · tecnomatix plant simulation v2302 (10)
- 27 CVECVSS 5.9macos (23) · iphone os (17) · ios and ipados (16)
- 27 CVECVSS 6.7NEWred hat enterprise linux 9 (19) · red hat enterprise linux 7 (19) · red hat enterprise linux 8 (19)
- 27 CVE1 critCVSS 7.4NEWtecnomatix plant simulation (10) · simcenter femap (6) · simatic wincc runtime professional (2)
- 26 CVE4 critCVSS 7.2harmonyos (26) · emui (25)
- 26 CVE1 critCVSS 7.4NEWfastconnect 6900 firmware (25) · fastconnect 7800 firmware (25) · wcd9380 firmware (25)
- 26 CVE1 critCVSS 7.5NEWsnapdragon (26)
- 25 CVECVSS 6.6enterprise linux (19) · enterprise linux eus (6) · enterprise linux for arm 64 eus (5)
- 25 CVE2 critCVSS 6.1Nuclei 25PoC 24wp jobsearch (2) · chartjs (2) · mappress maps for wordpress (2)
- 24 CVECVSS 6.3PoC 6active iq unified manager (10) · oncommand insight (5) · h615c firmware (3)
- 22 CVE1 critCVSS 5.5PoC 20employee management system (5) · online job portal (3) · web-based student clearance system (2)
- 21 CVE1 critCVSS 7.3NEWemc unity operating environment (15) · powerprotect data manager (2) · encryption (1)
- 21 CVE2 critCVSS 7.9PoC 3google chrome (12) · chrome os (5) · android (3)
- 20 CVECVSS 7.2big-ip (15) · big-ip application security manager (12) · big-ip advanced firewall manager (9)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | сообщество свободного программного обеспечения | 405 | 10 | · | · | PoC 28 | linux (303) · debian gnu/linux (194) · gguf (5) | — | |
| 2 | linux | 299 | · | · | · | PoC 4 | linux kernel (299) · linux (279) | — | |
| 3 | ооо «ред софт» | 205 | 4 | · | · | PoC 21 | ред ос (205) | — | |
| 4 | ооо «русбитех-астра» | 183 | 3 | · | · | PoC 17 | astra linux special edition (144) · astra linux special edition для «эльбрус» (60) · astra linux common edition (8) | — | |
| 5 | ао "нппкт" | 96 | 4 | · | · | PoC 12 | осон основа оnyx (96) | — | |
| 6 | ао «ивк» | 92 | · | · | · | PoC 10 | альт сп 10 (84) · альт 8 сп (56) | — | |
| 7 | maven | 89 | 20 | · | 1 | Nuclei 1PoC 6 | com.liferay.portal:release.portal.bom (33) · com.liferay.portal:release.dxp.bom (32) · org.apache.dolphinscheduler:dolphinscheduler (4) | — | |
| 8 | microsoft corp | 88 | 9 | 5 | · | KEV 5PoC 4 | windows server 2022, 23h2 edition (server core installation) (44) · windows 11 23h2 (43) · windows 11 22h2 (43) | — | |
| 9 | ibm | 86 | 2 | · | 2 | Nuclei 2PoC 1 | powersc (13) · security verify access appliance (12) · security verify access docker (12) | — | |
| 10 | microsoft | 81 | 8 | 5 | 1 | KEV 5Nuclei 1PoC 3 | windows server 2022 23h2 (43) · windows server 2022, 23h2 edition (server core installation) (42) · windows 11 version 22h2 (41) | — | |
| 11 | canonical ltd. | 76 | · | · | · | PoC 8 | ubuntu (74) · ubuntu edk ii (1) · lxd (1) | — | |
| 12 | intel | 75 | · | · | · | thunderbolt dch driver (20) · proset\/wireless (9) · killer (9) | — | ||
| 13 | intel corp. | 72 | · | · | · | thunderbolt dch driver (21) · intel killer wi-fi (10) · intel proset/wireless wifi (10) | — | ||
| 14 | ао «нтц ит роса» | 71 | 1 | · | · | PoC 6 | rosa virtualization 3.0 (53) · роса хром (19) · роса кобальт (12) | — | |
| 15 | fedoraproject | 69 | 11 | · | · | PoC 16 | fedora (68) · unbound (1) | — | |
| 16 | pypi | 66 | 12 | · | 4 | Nuclei 4PoC 9 | vyper (6) · apache-superset (6) · clearml (3) | — | |
| 17 | packagist | 64 | 6 | · | 2 | Nuclei 2PoC 8 | moodle/moodle (7) · getkirby/cms (6) · typo3/cms-core (4) | — | |
| 18 | red hat inc. | 63 | 3 | · | · | PoC 6 | red hat enterprise linux (59) · red hat enterprise linux workstation (6) · red hat enterprise linux server (6) | — | |
| 19 | 62 | 4 | · | · | PoC 2 | android (50) · chrome (12) | — | ||
| 20 | go | 52 | 2 | · | · | PoC 3 | github.com/mattermost/mattermost/server/v8 (11) · github.com/greenpau/caddy-security (10) · github.com/apache/incubator-answer (3) | — | |
| 21 | dell | 47 | 5 | · | · | unity (16) · unity operating environment (16) · supportassist for home pcs (3) | — | ||
| 22 | oracle corp. | 45 | · | 1 | 1 | NEWKEV 1Nuclei 1PoC 1 | mysql server (10) · e-business suite (9) · graalvm enterprise edition (5) | — | |
| 23 | oracle | 43 | · | 1 | 1 | NEWKEV 1Nuclei 1 | mysql server (12) · graalvm (5) · jre (5) | — | |
| 24 | oracle corporation | 43 | · | 1 | 1 | NEWKEV 1Nuclei 1 | mysql server (12) · java se jdk and jre (5) · installed base (4) | — | |
| 25 | apache | 41 | 11 | · | · | PoC 4 | superset (6) · dolphinscheduler (5) · solr (4) | — | |
| 26 | apache software foundation | 38 | 8 | · | · | PoC 2 | apache superset (6) · apache dolphinscheduler (5) · apache solr (4) | — | |
| 27 | liferay | 35 | 13 | · | 1 | NEWNuclei 1 | digital experience platform (35) · liferay portal (34) · dxp (33) | — | |
| 28 | fedora project | 34 | 3 | · | · | PoC 7 | fedora (34) | — | |
| 29 | debian | 33 | 2 | · | · | PoC 7 | debian linux (33) | — | |
| 30 | qnap | 32 | 1 | · | 1 | NEWNuclei 1PoC 2 | qts (29) · qutscloud (29) · quts hero (28) | — | |
| 31 | qnap systems inc. | 32 | 1 | · | 1 | NEWNuclei 1PoC 2 | quts hero (29) · qts (29) · qutscloud (28) | — | |
| 32 | qnap systems, inc. | 32 | 1 | · | 1 | NEWNuclei 1PoC 2 | qts (29) · quts hero (28) · qutscloud (28) | — | |
| 33 | adobe | 31 | 3 | · | · | acrobat (14) · acrobat dc (14) · acrobat reader (14) | — | ||
| 34 | adobe systems inc. | 31 | 3 | · | · | adobe acrobat 2020 (14) · adobe acrobat document cloud (14) · adobe acrobat reader 2020 (14) | — | ||
| 35 | npm | 29 | 4 | · | 1 | Nuclei 1PoC 8 | stimulsoft-dashboards-js (3) · ckeditor4 (2) · undici (2) | — | |
| 36 | code-projects | 28 | 6 | · | · | NEWPoC 14 | simple school management system (8) · library system (5) · task manager (5) | — | |
| 37 | siemens | 28 | 1 | · | · | NEW | tecnomatix plant simulation v2201 (10) · tecnomatix plant simulation (10) · tecnomatix plant simulation v2302 (10) | — | |
| 38 | apple | 27 | · | · | · | macos (23) · iphone os (17) · ios and ipados (16) | — | ||
| 39 | red hat | 27 | · | · | · | NEW | red hat enterprise linux 9 (19) · red hat enterprise linux 7 (19) · red hat enterprise linux 8 (19) | — | |
| 40 | siemens ag | 27 | 1 | · | · | NEW | tecnomatix plant simulation (10) · simcenter femap (6) · simatic wincc runtime professional (2) | — | |
| 41 | huawei | 26 | 4 | · | · | harmonyos (26) · emui (25) | — | ||
| 42 | qualcomm | 26 | 1 | · | · | NEW | fastconnect 6900 firmware (25) · fastconnect 7800 firmware (25) · wcd9380 firmware (25) | — | |
| 43 | qualcomm, inc. | 26 | 1 | · | · | NEW | snapdragon (26) | — | |
| 44 | redhat | 25 | · | · | · | enterprise linux (19) · enterprise linux eus (6) · enterprise linux for arm 64 eus (5) | — | ||
| 45 | unknown | 25 | 2 | · | 25 | Nuclei 25PoC 24 | wp jobsearch (2) · chartjs (2) · mappress maps for wordpress (2) | — | |
| 46 | netapp | 24 | · | · | · | PoC 6 | active iq unified manager (10) · oncommand insight (5) · h615c firmware (3) | — | |
| 47 | sourcecodester | 22 | 1 | · | · | PoC 20 | employee management system (5) · online job portal (3) · web-based student clearance system (2) | — | |
| 48 | dell technologies | 21 | 1 | · | · | NEW | emc unity operating environment (15) · powerprotect data manager (2) · encryption (1) | — | |
| 49 | google inc | 21 | 2 | · | · | PoC 3 | google chrome (12) · chrome os (5) · android (3) | — | |
| 50 | f5 | 20 | · | · | · | big-ip (15) · big-ip application security manager (12) · big-ip advanced firewall manager (9) | — |