month report
June 2024
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
June 2024 closed with 3,333 published CVEs. 313 criticals, 9 added to CISA KEV (2 ransomware-linked). сообщество свободного программного обеспечения led volume, mostly via linux. Top weakness class — CWE-79 (643 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
3,333
— MoM— YoY
Severity mix
313 / 942
critical / high
KEV added
9
2 ransomware-linked
Nuclei coverage
27.4%
914 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
634.2
n=914
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
58
n=13
Detection gap
KEV pressure, no Nuclei coverage
June 2024 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 2microsoft57 CVE
- KEV 1linux285 CVE
- KEV 1ооо «русбитех-астра»227 CVE
- KEV 1canonical ltd.94 CVE
- KEV 1google79 CVE
- KEV 1ао «ивк»53 CVE
- KEV 1ао «нтц ит роса»45 CVE
- KEV 1google inc34 CVE
Weakness × Vendor
What's spreading where in June 2024
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS862Missing Authorization89SQL Injection787Out-of-bounds Write22Path Traversal352CSRF476NULL Pointer Dereference125Out-of-bounds Read416Use After Free94Code Injectionсообщество свободного программного обеспечения421836022385ооо «ред софт»3115314416381linux12601829ооо «русбитех-астра»1133314311ао "нппкт"133214302adobe1421113adobe systems inc.1421113packagist4028364red hat inc.5176141canonical ltd.381468pypi9321418unknown541314
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #19itsourcecode44 CVE
- #20toshiba tec corporation43 CVE
- #29autodesk29 CVE
- #31autodesk inc.27 CVE
- #33parisneo27 CVE
- #35ibm corp.22 CVE
- #37lollms21 CVE
- #38lunary18 CVE
- #39lunary-ai18 CVE
- #40mozilla18 CVE
Top vendors
Ranked by distinct CVE count this period.
- 360 CVE16 critCVSS 6.5KEV 2Nuclei 3PoC 14linux (282) · debian gnu/linux (214) · webkitgtk (5)
- 286 CVE11 critCVSS 6.6KEV 2Nuclei 1PoC 10ред ос (286)
- 285 CVE5 critCVSS 6.2KEV 1linux (285) · linux kernel (285)
- 227 CVE13 critCVSS 6.8KEV 1PoC 6astra linux special edition (226) · astra linux common edition (25) · astra linux special edition для «эльбрус» (6)
- 211 CVE12 critCVSS 6.7PoC 5осон основа оnyx (211)
- 167 CVE4 critCVSS 5.7KEV 1Nuclei 1PoC 1experience manager (145) · adobe experience manager (145) · adobe commerce (10)
- 167 CVE4 critCVSS 5.8KEV 1Nuclei 1PoC 1adobe experience manager (145) · magento open source (10) · adobe commerce (10)
- 165 CVE2 critCVSS 6.4KEV 1Nuclei 3PoC 10typo3/cms (62) · zendframework/zendframework1 (20) · zendframework/zendframework (12)
- 113 CVE5 critCVSS 6.9PoC 4red hat enterprise linux (108) · red hat satellite (3) · red hat openshift container platform (2)
- 94 CVE4 critCVSS 6.3KEV 1PoC 4ubuntu (82) · apport (8) · snapd (1)
- 83 CVE15 critCVSS 7.5Nuclei 8PoC 15mlflow (13) · lollms (8) · zenml (8)
- 82 CVE3 critCVSS 5.6Nuclei 79PoC 81arforms - premium wordpress form builder plugin (3) · widget bundle (3) · wp logs book (3)
- 81 CVE2 critCVSS 7.4KEV 3Nuclei 1PoC 4microsoft edge (31) · windows server 2019 (server core installation) (30) · windows server 2019 (30)
- 79 CVE4 critCVSS 7.4KEV 1PoC 2android (48) · chrome (26) · nearby (2)
- 57 CVE1 critCVSS 7.3KEV 2PoC 2windows server 2019 (server core installation) (30) · windows server 2019 (30) · windows server 2022 (29)
- 53 CVE7 critCVSS 7.2KEV 1PoC 2альт сп 10 (49) · альт 8 сп (10)
- 51 CVECVSS 5.9infosphere information server (12) · security access manager (7) · mq (5)
- 45 CVE6 critCVSS 7.0KEV 1PoC 2rosa virtualization 3.0 (44) · rosa virtualization (7) · роса хром (2)
- 44 CVE2 critCVSS 7.0NEWPoC 41pool of bethesda online reservation system (4) · tailoring management system (4) · bakery online ordering system (4)
- 43 CVE6 critCVSS 8.0NEWPoC 43toshiba tec e-studio multi-function peripheral (mfp) (43) · toshiba e-studio 2510ac series (3) · toshiba e-studio 2520ac series (3)
- 41 CVECVSS 7.0macos (33) · iphone os (29) · ios and ipados (29)
- 40 CVECVSS 6.3exynos 1330 firmware (22) · exynos 1380 firmware (22) · exynos 1280 firmware (22)
- 34 CVECVSS 5.9data domain operating system (10) · powerprotect dd (10) · cpg bios (8)
- 34 CVE2 critCVSS 8.2KEV 1PoC 3google chrome (26) · android (2) · google quick share (2)
- 33 CVE3 critCVSS 5.9Nuclei 1PoC 3github.com/evmos/evmos/v13 (3) · github.com/evmos/evmos/v6 (3) · github.com/evmos/evmos/v7 (3)
- 33 CVE6 critCVSS 6.8Nuclei 3PoC 9@janhq/core (3) · lunary (3) · tinymce (2)
- 31 CVE8 critCVSS 6.9Nuclei 3PoC 6com.reposilite:reposilite-backend (3) · org.keycloak:keycloak-services (2) · org.apache.submarine:submarine-server-core (2)
- 30 CVE1 critCVSS 8.0KEV 1Nuclei 1PoC 3fedora (30)
- 29 CVECVSS 7.8NEWautocad electrical (29) · autocad map 3d (29) · autocad mechanical (29)
- 28 CVECVSS 8.0PoC 2fedora (28)
- 27 CVECVSS 7.8NEWautocad map 3d (27) · autocad (27) · autocad architecture (27)
- 27 CVE3 critCVSS 6.8Nuclei 1PoC 2opensuse leap (26) · suse linux enterprise server for sap applications (25) · suse linux enterprise server (25)
- 27 CVE11 critCVSS 7.9NEWNuclei 2PoC 13parisneo/lollms-webui (18) · parisneo/lollms (9) · lollms web ui (1)
- 24 CVECVSS 6.1PoC 24food ordering management system (5) · employee and visitor gate pass logging system (4) · simple online bidding system (2)
- 22 CVECVSS 5.8NEWinfosphere information server (12) · ibm db2 connect server (3) · ibm i (3)
- 22 CVE2 critCVSS 6.3PoC 21food ordering management system (5) · employee and visitor gate pass logging system (4) · simple online bidding system (2)
- 21 CVE9 critCVSS 7.8NEWNuclei 2PoC 12lollms web ui (14) · lollms (4) · lollms-webui (3)
- 18 CVE2 critCVSS 7.2NEWPoC 4lunary (18)
- 18 CVE2 critCVSS 7.2NEWPoC 4lunary-ai/lunary (18)
- 18 CVE3 critCVSS 6.6NEWPoC 2firefox (18) · firefox esr (8) · thunderbird (8)
- 18 CVE3 critCVSS 6.7NEWPoC 2firefox (18) · firefox esr (8) · thunderbird (8)
- 18 CVE5 critCVSS 7.9NEWKEV 1Nuclei 1PoC 3whatsup gold (15) · moveit transfer (1) · moveit gateway (1)
- 16 CVECVSS 6.3NEWfortios (5) · fortiwebmanager (4) · fortiproxy (3)
- 16 CVE1 critCVSS 6.1Nuclei 1PoC 4gitlab (16)
- 16 CVE4 critCVSS 7.8NEWKEV 1Nuclei 1PoC 2whatsup gold (15) · moveit transfer (1)
- 15 CVECVSS 7.0NEWred hat enterprise linux 8 (8) · red hat enterprise linux 9 (8) · red hat enterprise linux 7 (6)
- 15 CVECVSS 5.9samsung mobile devices (13) · galaxybudsmanager pc (1) · samsung live wallpaper pc (1)
- 14 CVECVSS 6.3NEWfortios (5) · fortiweb manager (4) · fortiproxy (3)
- 14 CVE1 critCVSS 6.4NEWNuclei 1PoC 3gitlab (14)
- 14 CVE3 critCVSS 7.9NEWPoC 7mintplex-labs/anything-llm (14)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | сообщество свободного программного обеспечения | 360 | 16 | 2 | 3 | KEV 2Nuclei 3PoC 14 | linux (282) · debian gnu/linux (214) · webkitgtk (5) | — | |
| 2 | ооо «ред софт» | 286 | 11 | 2 | 1 | KEV 2Nuclei 1PoC 10 | ред ос (286) | — | |
| 3 | linux | 285 | 5 | 1 | · | KEV 1 | linux (285) · linux kernel (285) | — | |
| 4 | ооо «русбитех-астра» | 227 | 13 | 1 | · | KEV 1PoC 6 | astra linux special edition (226) · astra linux common edition (25) · astra linux special edition для «эльбрус» (6) | — | |
| 5 | ао "нппкт" | 211 | 12 | · | · | PoC 5 | осон основа оnyx (211) | — | |
| 6 | adobe | 167 | 4 | 1 | 1 | KEV 1Nuclei 1PoC 1 | experience manager (145) · adobe experience manager (145) · adobe commerce (10) | — | |
| 7 | adobe systems inc. | 167 | 4 | 1 | 1 | KEV 1Nuclei 1PoC 1 | adobe experience manager (145) · magento open source (10) · adobe commerce (10) | — | |
| 8 | packagist | 165 | 2 | 1 | 3 | KEV 1Nuclei 3PoC 10 | typo3/cms (62) · zendframework/zendframework1 (20) · zendframework/zendframework (12) | — | |
| 9 | red hat inc. | 113 | 5 | · | · | PoC 4 | red hat enterprise linux (108) · red hat satellite (3) · red hat openshift container platform (2) | — | |
| 10 | canonical ltd. | 94 | 4 | 1 | · | KEV 1PoC 4 | ubuntu (82) · apport (8) · snapd (1) | — | |
| 11 | pypi | 83 | 15 | · | 8 | Nuclei 8PoC 15 | mlflow (13) · lollms (8) · zenml (8) | — | |
| 12 | unknown | 82 | 3 | · | 79 | Nuclei 79PoC 81 | arforms - premium wordpress form builder plugin (3) · widget bundle (3) · wp logs book (3) | — | |
| 13 | microsoft corp | 81 | 2 | 3 | 1 | KEV 3Nuclei 1PoC 4 | microsoft edge (31) · windows server 2019 (server core installation) (30) · windows server 2019 (30) | — | |
| 14 | 79 | 4 | 1 | · | KEV 1PoC 2 | android (48) · chrome (26) · nearby (2) | — | ||
| 15 | microsoft | 57 | 1 | 2 | · | KEV 2PoC 2 | windows server 2019 (server core installation) (30) · windows server 2019 (30) · windows server 2022 (29) | — | |
| 16 | ао «ивк» | 53 | 7 | 1 | · | KEV 1PoC 2 | альт сп 10 (49) · альт 8 сп (10) | — | |
| 17 | ibm | 51 | · | · | · | infosphere information server (12) · security access manager (7) · mq (5) | — | ||
| 18 | ао «нтц ит роса» | 45 | 6 | 1 | · | KEV 1PoC 2 | rosa virtualization 3.0 (44) · rosa virtualization (7) · роса хром (2) | — | |
| 19 | itsourcecode | 44 | 2 | · | · | NEWPoC 41 | pool of bethesda online reservation system (4) · tailoring management system (4) · bakery online ordering system (4) | — | |
| 20 | toshiba tec corporation | 43 | 6 | · | · | NEWPoC 43 | toshiba tec e-studio multi-function peripheral (mfp) (43) · toshiba e-studio 2510ac series (3) · toshiba e-studio 2520ac series (3) | — | |
| 21 | apple | 41 | · | · | · | macos (33) · iphone os (29) · ios and ipados (29) | — | ||
| 22 | samsung | 40 | · | · | · | exynos 1330 firmware (22) · exynos 1380 firmware (22) · exynos 1280 firmware (22) | — | ||
| 23 | dell | 34 | · | · | · | data domain operating system (10) · powerprotect dd (10) · cpg bios (8) | — | ||
| 24 | google inc | 34 | 2 | 1 | · | KEV 1PoC 3 | google chrome (26) · android (2) · google quick share (2) | — | |
| 25 | go | 33 | 3 | · | 1 | Nuclei 1PoC 3 | github.com/evmos/evmos/v13 (3) · github.com/evmos/evmos/v6 (3) · github.com/evmos/evmos/v7 (3) | — | |
| 26 | npm | 33 | 6 | · | 3 | Nuclei 3PoC 9 | @janhq/core (3) · lunary (3) · tinymce (2) | — | |
| 27 | maven | 31 | 8 | · | 3 | Nuclei 3PoC 6 | com.reposilite:reposilite-backend (3) · org.keycloak:keycloak-services (2) · org.apache.submarine:submarine-server-core (2) | — | |
| 28 | fedoraproject | 30 | 1 | 1 | 1 | KEV 1Nuclei 1PoC 3 | fedora (30) | — | |
| 29 | autodesk | 29 | · | · | · | NEW | autocad electrical (29) · autocad map 3d (29) · autocad mechanical (29) | — | |
| 30 | fedora project | 28 | · | · | · | PoC 2 | fedora (28) | — | |
| 31 | autodesk inc. | 27 | · | · | · | NEW | autocad map 3d (27) · autocad (27) · autocad architecture (27) | — | |
| 32 | novell inc. | 27 | 3 | · | 1 | Nuclei 1PoC 2 | opensuse leap (26) · suse linux enterprise server for sap applications (25) · suse linux enterprise server (25) | — | |
| 33 | parisneo | 27 | 11 | · | 2 | NEWNuclei 2PoC 13 | parisneo/lollms-webui (18) · parisneo/lollms (9) · lollms web ui (1) | — | |
| 34 | sourcecodester | 24 | · | · | · | PoC 24 | food ordering management system (5) · employee and visitor gate pass logging system (4) · simple online bidding system (2) | — | |
| 35 | ibm corp. | 22 | · | · | · | NEW | infosphere information server (12) · ibm db2 connect server (3) · ibm i (3) | — | |
| 36 | oretnom23 | 22 | 2 | · | · | PoC 21 | food ordering management system (5) · employee and visitor gate pass logging system (4) · simple online bidding system (2) | — | |
| 37 | lollms | 21 | 9 | · | 2 | NEWNuclei 2PoC 12 | lollms web ui (14) · lollms (4) · lollms-webui (3) | — | |
| 38 | lunary | 18 | 2 | · | · | NEWPoC 4 | lunary (18) | — | |
| 39 | lunary-ai | 18 | 2 | · | · | NEWPoC 4 | lunary-ai/lunary (18) | — | |
| 40 | mozilla | 18 | 3 | · | · | NEWPoC 2 | firefox (18) · firefox esr (8) · thunderbird (8) | — | |
| 41 | mozilla corp. | 18 | 3 | · | · | NEWPoC 2 | firefox (18) · firefox esr (8) · thunderbird (8) | — | |
| 42 | progress | 18 | 5 | 1 | 1 | NEWKEV 1Nuclei 1PoC 3 | whatsup gold (15) · moveit transfer (1) · moveit gateway (1) | — | |
| 43 | fortinet | 16 | · | · | · | NEW | fortios (5) · fortiwebmanager (4) · fortiproxy (3) | — | |
| 44 | gitlab | 16 | 1 | · | 1 | Nuclei 1PoC 4 | gitlab (16) | — | |
| 45 | progress software corporation | 16 | 4 | 1 | 1 | NEWKEV 1Nuclei 1PoC 2 | whatsup gold (15) · moveit transfer (1) | — | |
| 46 | red hat | 15 | · | · | · | NEW | red hat enterprise linux 8 (8) · red hat enterprise linux 9 (8) · red hat enterprise linux 7 (6) | — | |
| 47 | samsung mobile | 15 | · | · | · | samsung mobile devices (13) · galaxybudsmanager pc (1) · samsung live wallpaper pc (1) | — | ||
| 48 | fortinet inc. | 14 | · | · | · | NEW | fortios (5) · fortiweb manager (4) · fortiproxy (3) | — | |
| 49 | gitlab inc. | 14 | 1 | · | 1 | NEWNuclei 1PoC 3 | gitlab (14) | — | |
| 50 | mintplex-labs | 14 | 3 | · | · | NEWPoC 7 | mintplex-labs/anything-llm (14) | — |