October 2019
1,799 CVEs published, +15% on September 2019 and +21% on October 2018. CISA added 0 to KEV.
2019 month by month
| Year | Jan | Feb | Mar | Apr | May | Jun | Jul | Aug | Sep | Oct | Nov | Dec | Year total |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2019 | January 2019: no snapshot | February 2019: 908 CVEs | March 2019: no snapshot | April 2019: no snapshot | May 2019: 1,366 CVEs | June 2019: no snapshot | July 2019: 1,752 CVEs | August 2019: 2,064 CVEs | September 2019: 1,568 CVEs | October 2019: 1,799 CVEs | November 2019: 1,802 CVEs | December 2019: 1,881 CVEs | 13,1408 of 12 months8/12 |
- Critical
- 24915% of the 1,627 with a CVSS score
- Added to CISA KEV
- 07 of this month's CVEs are in KEV, listed a median 887 days after publication
- Vendors
- 6302,613 products
- Top weakness
- XSSCWE-79 · 258 CVEs
Who drove it
Vendors by distinct CVEs this month, with how many of those CVEs are now in CISA KEV and how far each moved in the ranking.
- 1OracleMySQL Server, MySQL, Java Se151101new
- 2Ооо «русбитех-астра»Astra Linux Special Edition, Astra Linux Special Edition Для «эльбрус», Astra Linux Common Edition147221new
- 3Сообщество Свободного Программного ОбеспеченияDebian Gnu/linux, Linux, Tightvnc140271new
- 4DebianDebian Linux, BIND9, Overkill115202new
- 5CanonicalUbuntu Linux, Ubuntu106122new
- 6CiscoSPA122 Firmware, Cisco Firepower Management Center, Cisco SPA112 2-port Phone Adapter892nonenew
- 7AdobeAcrobat Dc, Acrobat Reader Dc, Adobe Acrobat and Reader8622nonenew
- 8Red HatRed Hat Enterprise Linux, Enterprise Linux, Enterprise Linux Server86121new
- 9MavenCom.fasterxml.jackson.core:jackson-databind, Org.jenkins-ci.plugins:dynatrace-dashboard, Org.jenkins-ci.plugins:icescrum7313nonenew
- 10Ао «концерн Вниинс»Ос Он «стрелец»71131new
- 11FedoraprojectFedora6781new
- 12Novell Inc.Opensuse Leap, Suse Linux Enterprise Module For Basesystem, Suse Linux Enterprise Server6591new
- 13OpensuseLeap, Backports Sle616nonenew
- 14MicrosoftWindows, Windows Server, Windows 10 18096022new
- 15NetappOncommand Workflow Automation, Active Iq Unified Manager, Snapcenter6051new
- 16Fedora ProjectFedora5181new
- 17JenkinsJenkins Dynatrace Application Monitoring Plugin, Kubernetes Ci, Jenkins Crx Content Package Deployer Plugin462nonenew
- 18IBMCloud Orchestrator, Security Guardium Big Data Intelligence, Security Directory Server410nonenew
- 19JetbrainsTeamcity, Youtrack, Upsource344nonenew
- 20AwesomemotiveEasy Digital Downloads320nonenew
- 21EasydigitaldownloadsAmazon S3, Attach Accounts To Orders, Commissions310nonenew
- 22TcpdumpTcpdump, Libpcap302nonenew
- 23FoxitsoftwareReader, Phantompdf, Foxit Studio Photo290nonenew
- 24SugarcrmSugarcrm291nonenew
- 25FusionpbxFusionpbx260nonenew
Severity
How this month's CVEs score on CVSS; 172 have no score yet. Severity is not exploitation.
- Critical249
- High656
- Medium658
- Low64
New in the top 100
Not in the top 100 in any of the 24 months before.
What kind of weakness
Weakness classes (CWE) by distinct CVEs, with how far each moved in the ranking.
- CWE-79XSS258
- CWE-89SQL Injection78
- CWE-125Out-of-bounds Read70
- CWE-787Out-of-bounds Write65
- CWE-20Improper Input Validation58
- CWE-22Path Traversal55
- CWE-416Use After Free54
- CWE-78OS Command Injection43
- CWE-200Information Exposure42
- CWE-352CSRF41
- CWE-119Memory Buffer Bounds37
- CWE-276Incorrect Default Permissions33
- CWE-306Missing Auth for Critical Function26
- CWE-120Buffer Overflow22
- CWE-434Unrestricted File Upload22
- CWE-94Code Injection22
- CWE-284Improper Access Control19
- CWE-319Cleartext Transmission18
- CWE-75518
- CWE-862Missing Authorization17
Where it landed
The month's CVEs by the sector of the software they affect. A CVE that touches several sectors counts in each.
- Operating Systems35616% of sector-tagged CVEs
- OSS Libraries26212% of sector-tagged CVEs
- Networking Infrastructure22910% of sector-tagged CVEs
- Enterprise Software22810% of sector-tagged CVEs
- Web & CMS Plugins21610% of sector-tagged CVEs
- Consumer Software1678% of sector-tagged CVEs
- Databases1617% of sector-tagged CVEs
- Security Products1125% of sector-tagged CVEs
- DevTools & CI984% of sector-tagged CVEs
- 6 smaller sectors290
- Not yet classified101
Which weakness, where
The top weakness classes against the vendors and the sectors that carried them.
The lighter the cell, the more CVEs. Point at one to read it.
| By vendor | 79XSS | 89SQL Injection | 125Out-of-bounds Read | 787Out-of-bounds Write | 20Improper Input Validation | 22Path Traversal | 416Use After Free | 78OS Command Injection | 200Information Exposure | 352CSRF |
|---|---|---|---|---|---|---|---|---|---|---|
| Oracle | 1 | 1 | 1 | |||||||
| Ооо «русбитех-астра» | 3 | 1 | 21 | 9 | 11 | 4 | 1 | |||
| Сообщество Свободного Программного Обеспечения | 6 | 2 | 23 | 8 | 7 | 3 | 1 | 1 | 2 | |
| Oracle Corp. | 1 | 1 | ||||||||
| Oracle Corporation | ||||||||||
| Debian | 7 | 21 | 5 | 9 | 3 | 2 | 1 | 1 | ||
| Cisco Systems Inc. | 18 | 9 | 16 | 2 | 5 | 4 | 2 | |||
| Adobe | 8 | 22 | 9 | 1 | 26 | 1 | ||||
| Cisco | 18 | 9 | 15 | 3 | 5 | 3 | 2 | |||
| Adobe Systems Inc. | 8 | 17 | 9 | 1 | 26 | |||||
| Maven | 3 | 1 | 1 | 9 | ||||||
| Ао «концерн Вниинс» | 2 | 1 | 5 | 4 | 1 | 1 |