month report
November 2024
Data as of Jun 4, 2026, 13:26 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
November 2024 closed with 4,154 published CVEs — +62.3% YoY . 348 criticals, 22 added to CISA KEV (5 ransomware-linked). сообщество свободного программного обеспечения led volume, mostly via linux. Biggest breakout: irfanview at ×17.4 their 12-month median. Top weakness class — CWE-79 (824 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
4,154
— MoM+62.3% YoY
Severity mix
348 / 1,472
critical / high
KEV added
22
5 ransomware-linked
Nuclei coverage
26.1%
1,083 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
475.7
n=1,083
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
6
n=15
Detection gap
KEV pressure, no Nuclei coverage
November 2024 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 3ао "нппкт"218 CVE
- KEV 3red hat inc.128 CVE
- KEV 3microsoft corp104 CVE
- KEV 3microsoft96 CVE
- KEV 2canonical ltd.165 CVE
- KEV 2google133 CVE
- KEV 1linux279 CVE
- KEV 1novell inc.44 CVE
Weakness × Vendor
What's spreading where in November 2024
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS862Missing Authorization89SQL Injection787Out-of-bounds Write125Out-of-bounds Read78OS Command Injection22Path Traversal120Buffer Overflow74Injection352CSRFсообщество свободного программного обеспечения61113233542linux10183ооо «русбитех-астра»611017242ооо «ред софт»14347132342ао "нппкт"77162canonical ltd.171623google611372611red hat inc.2413231microsoft corp57cisco21224721cisco systems inc.21224721microsoft27
Breakout vendors
CVE count ≥3× their own 12-period median.
- 17.4×irfanview87 CVE
- 7.5×netgear49 CVE
- 5.3×anisha32 CVE
- 5.2×cisco103 CVE
- 5.0×cisco systems inc.102 CVE
- 4.0×мартин догиамас22 CVE
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #13irfanview87 CVE
- #36anisha32 CVE
- #39tungsten automation32 CVE
- #49trimble24 CVE
- #501000 projects23 CVE
- #53advantech21 CVE
- #60advantech co., ltd19 CVE
- #651000projects18 CVE
- #66allegra18 CVE
- #67alltena18 CVE
Top vendors
Ranked by distinct CVE count this period.
- 375 CVE12 critCVSS 6.2KEV 4Nuclei 3PoC 17linux (281) · debian gnu/linux (212) · needrestart (4)
- 279 CVECVSS 6.0KEV 1PoC 1linux kernel (279) · linux (274)
- 263 CVE12 critCVSS 6.3KEV 3Nuclei 1PoC 14astra linux special edition (261) · astra linux common edition (51) · astra linux special edition для «эльбрус» (2)
- 246 CVE11 critCVSS 6.2KEV 1Nuclei 3PoC 17ред ос (241) · ред база данных (5)
- 218 CVE8 critCVSS 6.4KEV 3PoC 6осон основа оnyx (218)
- 165 CVE2 critCVSS 6.2KEV 2PoC 5ubuntu (164) · ubuntu's pulseaudio (1)
- 133 CVE5 critCVSS 7.2KEV 2PoC 2android (117) · chrome (13) · andrioid (2)
- 128 CVE2 critCVSS 6.5KEV 3PoC 5red hat enterprise linux (114) · red hat build of keycloak (4) · red hat openshift container platform (4)
- 104 CVE5 critCVSS 7.7KEV 3PoC 2windows server 2022 (server core installation) (34) · windows server 2022 (34) · windows server 2025 (server core installation) (32)
- 103 CVE3 critCVSS 5.9×5.2Nuclei 2PoC 103cisco catalyst sd-wan manager (18) · catalyst sd-wan manager (16) · identity services engine (13)
- 102 CVE3 critCVSS 6.1×5.0Nuclei 2PoC 102cisco sd-wan (17) · cisco identity services engine (12) · telepresence collaboration endpoint (ce) (8)
- 96 CVE4 critCVSS 7.9KEV 3PoC 1windows server 2022 (34) · windows server 2025 (32) · windows server 2022, 23h2 edition (server core installation) (32)
- 87 CVECVSS 7.8NEW×17.4irfanview (87) · formats (4)
- 74 CVE2 critCVSS 5.7Nuclei 4PoC 20moodle/moodle (25) · librenms/librenms (13) · symfony/symfony (5)
- 57 CVECVSS 6.8substance3d - painter (23) · substance 3d painter (23) · illustrator (9)
- 51 CVECVSS 6.8adobe substance 3d painter (22) · illustrator 2025 (9) · illustrator 2024 (9)
- 51 CVE5 critCVSS 7.1Nuclei 3PoC 8calibreweb (3) · transformers (3) · octoprint (2)
- 50 CVECVSS 5.5fedora (50)
- 49 CVECVSS 6.2intel iris xe graphics (4) · intel neural compressor (4) · intel arc graphics (4)
- 49 CVE8 critCVSS 7.6endpoint manager (18) · connect secure (18) · policy secure (15)
- 49 CVECVSS 6.2×7.5r7000p (27) · r7000p firmware (26) · r8500 firmware (25)
- 48 CVE5 critCVSS 7.3PoC 4org.keycloak:keycloak-quarkus-server (6) · org.keycloak:keycloak-services (4) · ca.uhn.hapi.fhir:org.hl7.fhir.dstu3 (2)
- 47 CVE7 critCVSS 6.7PoC 3альт сп 10 (35) · альт 8 сп (18)
- 46 CVECVSS 5.9PoC 46e-health care system (10) · farmacia (10) · job recruitment (6)
- 44 CVE1 critCVSS 5.8KEV 1PoC 2opensuse leap (34) · suse linux enterprise server (33) · suse linux enterprise server for sap applications (32)
- 42 CVE5 critCVSS 7.1Nuclei 1PoC 5github.com/goharbor/harbor (6) · github.com/moby/moby (3) · github.com/cli/cli/v2 (2)
- 39 CVECVSS 6.6pdf-xchange editor (39) · pdf-tools (38)
- 39 CVE2 critCVSS 5.4Nuclei 39PoC 38yadisk files (2) · rss feed widget (2) · logo slider (2)
- 38 CVECVSS 6.7pdf-xchange editor (38) · pdf-xchange pro (11) · pdf-tools (11)
- 36 CVE3 critCVSS 7.7wsa8835 firmware (21) · wsa8830 firmware (21) · fastconnect 7800 firmware (20)
- 36 CVE3 critCVSS 7.8snapdragon (36)
- 36 CVECVSS 6.4power pdf (36)
- 35 CVECVSS 6.2PoC 1red hat enterprise linux 9 (17) · red hat enterprise linux 8 (17) · red hat enterprise linux 7 (15)
- 34 CVE2 critCVSS 5.0PoC 33online shopping portal (11) · complaint management system (4) · user registration \& login and user management system (4)
- 34 CVE3 critCVSS 5.8KEV 1tecnomatix plant simulation (10) · teamcenter visualization v2406 (10) · tecnomatix plant simulation v2404 (10)
- 32 CVECVSS 6.0NEW×5.3PoC 32e-health care system (10) · farmacia (8) · job recruitment (6)
- 32 CVE4 critCVSS 6.3concert software (5) · concert (5) · security verify access (4)
- 32 CVE3 critCVSS 6.0tecnomatix plant simulation (10) · sinec ins (6) · scalance s615 lan-router (4)
- 32 CVECVSS 6.3NEWpower pdf (32)
- 32 CVE1 critCVSS 6.4KEV 1PoC 2rosa virtualization 3.0 (21) · роса кобальт (12) · роса хром (7)
- 29 CVE3 critCVSS 6.9qts (16) · quts hero (16) · notes station 3 (4)
- 29 CVE3 critCVSS 6.9quts hero (16) · qts (16) · photo station (4)
- 28 CVE4 critCVSS 7.4Nuclei 3PoC 15dsl6740c firmware (7) · di-8003 firmware (7) · dwr-2000m firmware (3)
- 26 CVE6 critCVSS 7.4tomcat (4) · traffic server (4) · nimble (4)
- 26 CVE3 critCVSS 7.5Nuclei 3PoC 13di-8003 (7) · dsl6740c (6) · dns-320lw (3)
- 25 CVE6 critCVSS 7.6apache tomcat (4) · apache nimble (4) · tomcat (4)
- 25 CVECVSS 5.9Nuclei 1PoC 1moodle (25)
- 24 CVE4 critCVSS 7.2PoC 2firefox (20) · thunderbird (17) · firefox esr (10)
- 24 CVECVSS 7.7NEWsketchup viewer (19) · sketchup (8) · sketchup pro (2)
- 23 CVECVSS 7.0NEWPoC 23beauty parlour management system (11) · bookstore management system (9) · portfolio management system mca (3)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | сообщество свободного программного обеспечения | 375 | 12 | 4 | 3 | KEV 4Nuclei 3PoC 17 | linux (281) · debian gnu/linux (212) · needrestart (4) | — | |
| 2 | linux | 279 | · | 1 | · | KEV 1PoC 1 | linux kernel (279) · linux (274) | — | |
| 3 | ооо «русбитех-астра» | 263 | 12 | 3 | 1 | KEV 3Nuclei 1PoC 14 | astra linux special edition (261) · astra linux common edition (51) · astra linux special edition для «эльбрус» (2) | — | |
| 4 | ооо «ред софт» | 246 | 11 | 1 | 3 | KEV 1Nuclei 3PoC 17 | ред ос (241) · ред база данных (5) | — | |
| 5 | ао "нппкт" | 218 | 8 | 3 | · | KEV 3PoC 6 | осон основа оnyx (218) | — | |
| 6 | canonical ltd. | 165 | 2 | 2 | · | KEV 2PoC 5 | ubuntu (164) · ubuntu's pulseaudio (1) | — | |
| 7 | 133 | 5 | 2 | · | KEV 2PoC 2 | android (117) · chrome (13) · andrioid (2) | — | ||
| 8 | red hat inc. | 128 | 2 | 3 | · | KEV 3PoC 5 | red hat enterprise linux (114) · red hat build of keycloak (4) · red hat openshift container platform (4) | — | |
| 9 | microsoft corp | 104 | 5 | 3 | · | KEV 3PoC 2 | windows server 2022 (server core installation) (34) · windows server 2022 (34) · windows server 2025 (server core installation) (32) | — | |
| 10 | cisco | 103 | 3 | · | 2 | ×5.2Nuclei 2PoC 103 | cisco catalyst sd-wan manager (18) · catalyst sd-wan manager (16) · identity services engine (13) | — | |
| 11 | cisco systems inc. | 102 | 3 | · | 2 | ×5.0Nuclei 2PoC 102 | cisco sd-wan (17) · cisco identity services engine (12) · telepresence collaboration endpoint (ce) (8) | — | |
| 12 | microsoft | 96 | 4 | 3 | · | KEV 3PoC 1 | windows server 2022 (34) · windows server 2025 (32) · windows server 2022, 23h2 edition (server core installation) (32) | — | |
| 13 | irfanview | 87 | · | · | · | NEW×17.4 | irfanview (87) · formats (4) | — | |
| 14 | packagist | 74 | 2 | · | 4 | Nuclei 4PoC 20 | moodle/moodle (25) · librenms/librenms (13) · symfony/symfony (5) | — | |
| 15 | adobe | 57 | · | · | · | substance3d - painter (23) · substance 3d painter (23) · illustrator (9) | — | ||
| 16 | adobe systems inc. | 51 | · | · | · | adobe substance 3d painter (22) · illustrator 2025 (9) · illustrator 2024 (9) | — | ||
| 17 | pypi | 51 | 5 | · | 3 | Nuclei 3PoC 8 | calibreweb (3) · transformers (3) · octoprint (2) | — | |
| 18 | fedora project | 50 | · | · | · | fedora (50) | — | ||
| 19 | intel corp. | 49 | · | · | · | intel iris xe graphics (4) · intel neural compressor (4) · intel arc graphics (4) | — | ||
| 20 | ivanti | 49 | 8 | · | · | endpoint manager (18) · connect secure (18) · policy secure (15) | — | ||
| 21 | netgear | 49 | · | · | · | ×7.5 | r7000p (27) · r7000p firmware (26) · r8500 firmware (25) | — | |
| 22 | maven | 48 | 5 | · | · | PoC 4 | org.keycloak:keycloak-quarkus-server (6) · org.keycloak:keycloak-services (4) · ca.uhn.hapi.fhir:org.hl7.fhir.dstu3 (2) | — | |
| 23 | ао «ивк» | 47 | 7 | · | · | PoC 3 | альт сп 10 (35) · альт 8 сп (18) | — | |
| 24 | code-projects | 46 | · | · | · | PoC 46 | e-health care system (10) · farmacia (10) · job recruitment (6) | — | |
| 25 | novell inc. | 44 | 1 | 1 | · | KEV 1PoC 2 | opensuse leap (34) · suse linux enterprise server (33) · suse linux enterprise server for sap applications (32) | — | |
| 26 | go | 42 | 5 | · | 1 | Nuclei 1PoC 5 | github.com/goharbor/harbor (6) · github.com/moby/moby (3) · github.com/cli/cli/v2 (2) | — | |
| 27 | pdf-xchange | 39 | · | · | · | pdf-xchange editor (39) · pdf-tools (38) | — | ||
| 28 | unknown | 39 | 2 | · | 39 | Nuclei 39PoC 38 | yadisk files (2) · rss feed widget (2) · logo slider (2) | — | |
| 29 | tracker software products ltd. | 38 | · | · | · | pdf-xchange editor (38) · pdf-xchange pro (11) · pdf-tools (11) | — | ||
| 30 | qualcomm | 36 | 3 | · | · | wsa8835 firmware (21) · wsa8830 firmware (21) · fastconnect 7800 firmware (20) | — | ||
| 31 | qualcomm, inc. | 36 | 3 | · | · | snapdragon (36) | — | ||
| 32 | tungstenautomation | 36 | · | · | · | power pdf (36) | — | ||
| 33 | red hat | 35 | · | · | · | PoC 1 | red hat enterprise linux 9 (17) · red hat enterprise linux 8 (17) · red hat enterprise linux 7 (15) | — | |
| 34 | phpgurukul | 34 | 2 | · | · | PoC 33 | online shopping portal (11) · complaint management system (4) · user registration \& login and user management system (4) | — | |
| 35 | siemens | 34 | 3 | 1 | · | KEV 1 | tecnomatix plant simulation (10) · teamcenter visualization v2406 (10) · tecnomatix plant simulation v2404 (10) | — | |
| 36 | anisha | 32 | · | · | · | NEW×5.3PoC 32 | e-health care system (10) · farmacia (8) · job recruitment (6) | — | |
| 37 | ibm | 32 | 4 | · | · | concert software (5) · concert (5) · security verify access (4) | — | ||
| 38 | siemens ag | 32 | 3 | · | · | tecnomatix plant simulation (10) · sinec ins (6) · scalance s615 lan-router (4) | — | ||
| 39 | tungsten automation | 32 | · | · | · | NEW | power pdf (32) | — | |
| 40 | ао «нтц ит роса» | 32 | 1 | 1 | · | KEV 1PoC 2 | rosa virtualization 3.0 (21) · роса кобальт (12) · роса хром (7) | — | |
| 41 | qnap | 29 | 3 | · | · | qts (16) · quts hero (16) · notes station 3 (4) | — | ||
| 42 | qnap systems inc. | 29 | 3 | · | · | quts hero (16) · qts (16) · photo station (4) | — | ||
| 43 | dlink | 28 | 4 | · | 3 | Nuclei 3PoC 15 | dsl6740c firmware (7) · di-8003 firmware (7) · dwr-2000m firmware (3) | — | |
| 44 | apache | 26 | 6 | · | · | tomcat (4) · traffic server (4) · nimble (4) | — | ||
| 45 | d-link corp. | 26 | 3 | · | 3 | Nuclei 3PoC 13 | di-8003 (7) · dsl6740c (6) · dns-320lw (3) | — | |
| 46 | apache software foundation | 25 | 6 | · | · | apache tomcat (4) · apache nimble (4) · tomcat (4) | — | ||
| 47 | moodle | 25 | · | · | 1 | Nuclei 1PoC 1 | moodle (25) | — | |
| 48 | mozilla | 24 | 4 | · | · | PoC 2 | firefox (20) · thunderbird (17) · firefox esr (10) | — | |
| 49 | trimble | 24 | · | · | · | NEW | sketchup viewer (19) · sketchup (8) · sketchup pro (2) | — | |
| 50 | 1000 projects | 23 | · | · | · | NEWPoC 23 | beauty parlour management system (11) · bookstore management system (9) · portfolio management system mca (3) | — |