month report
July 2025
Data as of Jun 4, 2026, 13:26 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
July 2025 closed with 4,086 published CVEs — +25.8% YoY . 368 criticals, 20 added to CISA KEV (4 ransomware-linked). сообщество свободного программного обеспечения led volume, mostly via linux. Biggest breakout: debian at ×40.2 their 12-month median. Top weakness class — CWE-79 (483 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
4,086
— MoM+25.8% YoY
Severity mix
368 / 1,455
critical / high
KEV added
20
4 ransomware-linked
Nuclei coverage
11.4%
467 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
233.4
n=467
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
14
n=14
Detection gap
KEV pressure, no Nuclei coverage
July 2025 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 3ооо «русбитех-астра»372 CVE
- KEV 3ао "нппкт"236 CVE
- KEV 3debian201 CVE
- KEV 3apple84 CVE
- KEV 2ао «сбертех»228 CVE
- KEV 2ао «ивк»178 CVE
- KEV 1linux401 CVE
Weakness × Vendor
What's spreading where in July 2025
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS89SQL Injection74Injection119Memory Buffer Bounds94Code Injection476NULL Pointer Dereference121CWE-12122Path Traversal434Unrestricted File Upload125Out-of-bounds Readсообщество свободного программного обеспечения373211016132linux8626ооо «ред софт»215276223ооо «русбитех-астра»110170224red hat inc.414519ао "нппкт"5139218ао «сбертех»241211debian4416ао «ивк»1613317code-projects4134134414microsoft corp12313microsoft12313
Breakout vendors
CVE count ≥3× their own 12-period median.
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #14cadsofttools91 CVE
- #15irfanview91 CVE
- #32irfan skiljan42 CVE
- #34anisha37 CVE
- #42labredescefetrj31 CVE
- #43wegia31 CVE
- #45wikimedia foundation30 CVE
- #55samsung electronics25 CVE
- #58carmelo24 CVE
- #66huawei technologies co., ltd.20 CVE
Top vendors
Ranked by distinct CVE count this period.
- 536 CVE18 critCVSS 6.3KEV 1Nuclei 2PoC 26linux (406) · debian gnu/linux (140) · gpac (22)
- 401 CVECVSS 6.1KEV 1PoC 1linux (401) · linux kernel (401)
- 395 CVE6 critCVSS 6.3KEV 3Nuclei 2PoC 15ред ос (395)
- 372 CVE8 critCVSS 6.5KEV 3PoC 11astra linux special edition (372) · astra linux common edition (47)
- 282 CVE2 critCVSS 6.2PoC 7red hat enterprise linux (275) · red hat openshift container platform (7) · red hat jboss core services (6)
- 236 CVE6 critCVSS 6.4KEV 3PoC 7осон основа оnyx (236)
- 228 CVE3 critCVSS 6.2KEV 2PoC 5platform v sberlinux os server (228)
- 201 CVECVSS 6.2×40.2KEV 3PoC 1debian linux (200) · dpkg (1)
- 178 CVE8 critCVSS 6.5KEV 2PoC 7альт 8 сп (131) · альт сп 10 (53)
- 154 CVECVSS 7.0×14.7PoC 154exam form submission (20) · online appointment booking system (14) · church donation system (14)
- 145 CVE3 critCVSS 7.6KEV 4Nuclei 3PoC 4windows server 2025 (server core installation) (97) · windows server 2025 (97) · windows server 2022, 23h2 edition (server core installation) (94)
- 141 CVE5 critCVSS 7.6KEV 3Nuclei 3PoC 3windows server 2025 (97) · windows server 2025 (server core installation) (97) · windows server 2022 23h2 (94)
- 113 CVE2 critCVSS 6.3PoC 5ubuntu (112) · maas (1)
- 91 CVECVSS 7.8NEWcadimage (91)
- 91 CVECVSS 7.8NEW×18.2irfanview (91)
- 86 CVECVSS 5.8Nuclei 1PoC 84vehicle parking management system (13) · apartment visitors management system (9) · online fire reporting system (9)
- 85 CVE1 critCVSS 6.0mysql server (20) · mysql (9) · e-business suite (9)
- 84 CVE25 critCVSS 7.2KEV 3macos (78) · ipados (29) · ios and ipados (25)
- 77 CVE1 critCVSS 5.9mysql (28) · jdk (7) · vm virtualbox (7)
- 77 CVE1 critCVSS 5.7mysql server (29) · oracle vm virtualbox (7) · oracle java se (7)
- 73 CVE3 critCVSS 6.8Nuclei 1adobe framemaker (15) · coldfusion (13) · illustrator 2025 (10)
- 71 CVE3 critCVSS 6.8Nuclei 1framemaker (15) · adobe framemaker (15) · coldfusion (13)
- 69 CVE6 critCVSS 6.7Nuclei 1PoC 1org.glassfish.main.admingui:console-common (5) · org.keycloak:keycloak-services (4) · org.jenkins-ci.plugins:applitools-eyes (3)
- 68 CVE2 critCVSS 6.3PoC 8opensuse leap (61) · suse linux enterprise server (60) · suse linux enterprise server for sap applications (59)
- 65 CVECVSS 6.9×10.8PoC 63employee management system (10) · payroll management system (9) · courier management system (8)
- 63 CVECVSS 8.5PoC 54fh451 firmware (15) · fh451 (15) · o3v2 (10)
- 59 CVE4 critCVSS 6.9KEV 1Nuclei 2PoC 7@haxtheweb/haxcms-nodejs (6) · directus (4) · @finos/git-proxy (4)
- 57 CVECVSS 8.5PoC 49tenda fh451 (14) · tenda o3 (10) · tenda fh1201 (8)
- 54 CVECVSS 6.1db2 (8) · openpages with watson (6) · smartcloud analytics log analysis (4)
- 51 CVE5 critCVSS 7.0Nuclei 1PoC 18transformers (5) · pyload-ng (5) · openexr (3)
- 44 CVE14 critCVSS 7.1macos (39) · ipados (21) · ios (17)
- 42 CVECVSS 7.7NEWirfanview (42)
- 41 CVE12 critCVSS 7.9magicinfo 9 server (18) · android (12) · data management server firmware (6)
- 37 CVECVSS 7.3NEWPoC 37online appointment booking system (14) · job diary (5) · jonnys liquor (3)
- 36 CVECVSS 4.1sequoia-openpgp (4) · cosmwasm-std (2) · curve25519-dalek (2)
- 36 CVECVSS 6.5×4.5PoC 36voting system (7) · online ordering system (7) · chat system (5)
- 34 CVE7 critCVSS 7.3Nuclei 2PoC 4github.com/mattermost/mattermost/server/v8 (3) · github.com/lf-edge/ekuiper/v2 (3) · github.com/mattermost/mattermost-server (3)
- 33 CVE3 critCVSS 8.1PoC 30t6 firmware (13) · t6 (13) · a702r firmware (6)
- 32 CVECVSS 6.0applitools eyes (3) · xooa (2) · apica loadtest (2)
- 31 CVECVSS 5.9ibm db2 connect server (8) · ibm db2 (8) · ibm openpages (5)
- 31 CVECVSS 5.9jenkins applitools eyes plugin (3) · jenkins qmetry test management plugin (2) · jenkins readyapi functional testing plugin (2)
- 31 CVE3 critCVSS 7.1NEWPoC 15wegia (31)
- 31 CVE3 critCVSS 7.1NEWPoC 15wegia (31)
- 30 CVECVSS 5.9applitools eyes (3) · sensedia api platform tools (2) · statistics gatherer (2)
- 30 CVE3 critCVSS 6.4NEWPoC 1mediawiki - checkuser extension (3) · mediawiki - securepoll extension (3) · mediawiki - abusefilter extension (3)
- 29 CVE5 critCVSS 6.1sapcar (4) · sap netweaver (4) · sap business warehouse (4)
- 28 CVE5 critCVSS 6.1sapcar (4) · sap netweaver application server for abap (2) · sap businessobjects content administrator workbench (1)
- 27 CVE2 critCVSS 7.3PoC 23dir-513 (7) · di-8100 (6) · di-8200 (3)
- 27 CVECVSS 6.5red hat enterprise linux 9 (19) · red hat enterprise linux 8 (19) · red hat enterprise linux 10 (18)
- 26 CVE3 critCVSS 7.4PoC 22dir-513 firmware (6) · di-8100 firmware (6) · di-8200 firmware (3)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | сообщество свободного программного обеспечения | 536 | 18 | 1 | 2 | KEV 1Nuclei 2PoC 26 | linux (406) · debian gnu/linux (140) · gpac (22) | — | |
| 2 | linux | 401 | · | 1 | · | KEV 1PoC 1 | linux (401) · linux kernel (401) | — | |
| 3 | ооо «ред софт» | 395 | 6 | 3 | 2 | KEV 3Nuclei 2PoC 15 | ред ос (395) | — | |
| 4 | ооо «русбитех-астра» | 372 | 8 | 3 | · | KEV 3PoC 11 | astra linux special edition (372) · astra linux common edition (47) | — | |
| 5 | red hat inc. | 282 | 2 | · | · | PoC 7 | red hat enterprise linux (275) · red hat openshift container platform (7) · red hat jboss core services (6) | — | |
| 6 | ао "нппкт" | 236 | 6 | 3 | · | KEV 3PoC 7 | осон основа оnyx (236) | — | |
| 7 | ао «сбертех» | 228 | 3 | 2 | · | KEV 2PoC 5 | platform v sberlinux os server (228) | — | |
| 8 | debian | 201 | · | 3 | · | ×40.2KEV 3PoC 1 | debian linux (200) · dpkg (1) | — | |
| 9 | ао «ивк» | 178 | 8 | 2 | · | KEV 2PoC 7 | альт 8 сп (131) · альт сп 10 (53) | — | |
| 10 | code-projects | 154 | · | · | · | ×14.7PoC 154 | exam form submission (20) · online appointment booking system (14) · church donation system (14) | — | |
| 11 | microsoft corp | 145 | 3 | 4 | 3 | KEV 4Nuclei 3PoC 4 | windows server 2025 (server core installation) (97) · windows server 2025 (97) · windows server 2022, 23h2 edition (server core installation) (94) | — | |
| 12 | microsoft | 141 | 5 | 3 | 3 | KEV 3Nuclei 3PoC 3 | windows server 2025 (97) · windows server 2025 (server core installation) (97) · windows server 2022 23h2 (94) | — | |
| 13 | canonical ltd. | 113 | 2 | · | · | PoC 5 | ubuntu (112) · maas (1) | — | |
| 14 | cadsofttools | 91 | · | · | · | NEW | cadimage (91) | — | |
| 15 | irfanview | 91 | · | · | · | NEW×18.2 | irfanview (91) | — | |
| 16 | phpgurukul | 86 | · | · | 1 | Nuclei 1PoC 84 | vehicle parking management system (13) · apartment visitors management system (9) · online fire reporting system (9) | — | |
| 17 | oracle corp. | 85 | 1 | · | · | mysql server (20) · mysql (9) · e-business suite (9) | — | ||
| 18 | apple | 84 | 25 | 3 | · | KEV 3 | macos (78) · ipados (29) · ios and ipados (25) | — | |
| 19 | oracle | 77 | 1 | · | · | mysql (28) · jdk (7) · vm virtualbox (7) | — | ||
| 20 | oracle corporation | 77 | 1 | · | · | mysql server (29) · oracle vm virtualbox (7) · oracle java se (7) | — | ||
| 21 | adobe systems inc. | 73 | 3 | · | 1 | Nuclei 1 | adobe framemaker (15) · coldfusion (13) · illustrator 2025 (10) | — | |
| 22 | adobe | 71 | 3 | · | 1 | Nuclei 1 | framemaker (15) · adobe framemaker (15) · coldfusion (13) | — | |
| 23 | maven | 69 | 6 | · | 1 | Nuclei 1PoC 1 | org.glassfish.main.admingui:console-common (5) · org.keycloak:keycloak-services (4) · org.jenkins-ci.plugins:applitools-eyes (3) | — | |
| 24 | novell inc. | 68 | 2 | · | · | PoC 8 | opensuse leap (61) · suse linux enterprise server (60) · suse linux enterprise server for sap applications (59) | — | |
| 25 | campcodes | 65 | · | · | · | ×10.8PoC 63 | employee management system (10) · payroll management system (9) · courier management system (8) | — | |
| 26 | tenda | 63 | · | · | · | PoC 54 | fh451 firmware (15) · fh451 (15) · o3v2 (10) | — | |
| 27 | npm | 59 | 4 | 1 | 2 | KEV 1Nuclei 2PoC 7 | @haxtheweb/haxcms-nodejs (6) · directus (4) · @finos/git-proxy (4) | — | |
| 28 | shenzhen tenda technology co., ltd. | 57 | · | · | · | PoC 49 | tenda fh451 (14) · tenda o3 (10) · tenda fh1201 (8) | — | |
| 29 | ibm | 54 | · | · | · | db2 (8) · openpages with watson (6) · smartcloud analytics log analysis (4) | — | ||
| 30 | pypi | 51 | 5 | · | 1 | Nuclei 1PoC 18 | transformers (5) · pyload-ng (5) · openexr (3) | — | |
| 31 | apple inc. | 44 | 14 | · | · | macos (39) · ipados (21) · ios (17) | — | ||
| 32 | irfan skiljan | 42 | · | · | · | NEW | irfanview (42) | — | |
| 33 | samsung | 41 | 12 | · | · | magicinfo 9 server (18) · android (12) · data management server firmware (6) | — | ||
| 34 | anisha | 37 | · | · | · | NEWPoC 37 | online appointment booking system (14) · job diary (5) · jonnys liquor (3) | — | |
| 35 | crates.io | 36 | · | · | · | sequoia-openpgp (4) · cosmwasm-std (2) · curve25519-dalek (2) | — | ||
| 36 | fabian | 36 | · | · | · | ×4.5PoC 36 | voting system (7) · online ordering system (7) · chat system (5) | — | |
| 37 | go | 34 | 7 | · | 2 | Nuclei 2PoC 4 | github.com/mattermost/mattermost/server/v8 (3) · github.com/lf-edge/ekuiper/v2 (3) · github.com/mattermost/mattermost-server (3) | — | |
| 38 | totolink | 33 | 3 | · | · | PoC 30 | t6 firmware (13) · t6 (13) · a702r firmware (6) | — | |
| 39 | jenkins | 32 | · | · | · | applitools eyes (3) · xooa (2) · apica loadtest (2) | — | ||
| 40 | ibm corp. | 31 | · | · | · | ibm db2 connect server (8) · ibm db2 (8) · ibm openpages (5) | — | ||
| 41 | jenkins project | 31 | · | · | · | jenkins applitools eyes plugin (3) · jenkins qmetry test management plugin (2) · jenkins readyapi functional testing plugin (2) | — | ||
| 42 | labredescefetrj | 31 | 3 | · | · | NEWPoC 15 | wegia (31) | — | |
| 43 | wegia | 31 | 3 | · | · | NEWPoC 15 | wegia (31) | — | |
| 44 | cd foundation | 30 | · | · | · | applitools eyes (3) · sensedia api platform tools (2) · statistics gatherer (2) | — | ||
| 45 | wikimedia foundation | 30 | 3 | · | · | NEWPoC 1 | mediawiki - checkuser extension (3) · mediawiki - securepoll extension (3) · mediawiki - abusefilter extension (3) | — | |
| 46 | sap | 29 | 5 | · | · | sapcar (4) · sap netweaver (4) · sap business warehouse (4) | — | ||
| 47 | sap_se | 28 | 5 | · | · | sapcar (4) · sap netweaver application server for abap (2) · sap businessobjects content administrator workbench (1) | — | ||
| 48 | d-link corp. | 27 | 2 | · | · | PoC 23 | dir-513 (7) · di-8100 (6) · di-8200 (3) | — | |
| 49 | red hat | 27 | · | · | · | red hat enterprise linux 9 (19) · red hat enterprise linux 8 (19) · red hat enterprise linux 10 (18) | — | ||
| 50 | dlink | 26 | 3 | · | · | PoC 22 | dir-513 firmware (6) · di-8100 firmware (6) · di-8200 firmware (3) | — |