June 2022
2,302 CVEs published, +4% on May 2022 and +16% on June 2021. CISA added 48 to KEV.
2022 month by month
- Critical
- 33115% of the 2,184 with a CVSS score
- Added to CISA KEV
- 482 of this month's CVEs are in KEV, listed a median 276 days after publication
- Vendors
- 1,0304,147 products
- Top weakness
- XSSCWE-79 · 336 CVEs
Who drove it
Vendors by distinct CVEs this month, with how many of those CVEs are now in CISA KEV and how far each moved in the ranking.
- 1UnknownNote Press, HTML2WP, Five Minute Webshop1458nonenew
- 2GoogleAndroid, Kctf, Protobuf-c12113nonenew
- 3MavenOrg.jenkins-ci.main:jenkins-core, Org.jenkins-ci.plugins:ec2-deployment-dashboard, Com.geteasyqa:easyqa1127nonenew
- 4UnspecifiedFfmpeg, Hindu Matrimonial Script, Phplist990nonenew
- 5JenkinsJenkins, Deployment Dashboard, Jenkins Deployment Dashboard Plugin861nonenew
- 6Сообщество Свободного Программного ОбеспеченияDebian Gnu/linux, Linux, Vim826nonenew
- 7Ооо «русбитех-астра»Astra Linux Special Edition, Astra Linux Special Edition Для «эльбрус», Astra Linux Common Edition693nonenew
- 8QualcommWSA8830 Firmware, WSA8835 Firmware, WCD9370 Firmware68101new
- 9Qualcomm, Inc.Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Iot, Snapdragon Industrial Iot, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial Iot, Snapdragon Mobile, Snapdragon Connectivity, Snapdragon Mobile68101new
- 10Ао "нппкт"Осон Основа Оnyx682nonenew
- 11MicrosoftWindows Server 2019 (Server Core Installation), Windows Server 2019, Windows 106311new
- 12Crates.ioArrow, Rulex, Crossbeam611nonenew
- 13PackagistElefant/cms, Typo3/cms-core, Typo3/cms606nonenew
- 14npmParse-url, Nocodb, Parse-server558nonenew
- 15FedoraprojectFedora, Extra Packages For Enterprise Linux524nonenew
- 16Ооо «ред Софт»Ред Ос483nonenew
- 17AdobeAdobe Bridge, Bridge, Indesign470nonenew
- 18DebianDebian Linux451nonenew
- 19Red HatRed Hat Enterprise Linux, Jboss Core Services, Red Hat Software Collections446nonenew
- 20IBMJazz Team Server, Spectrum Copy Data Management, Robotic Process Automation438nonenew
- 21Samsung MobileSamsung Mobile Devices, Samsung Account, Smart Things410nonenew
- 22Fedora ProjectFedora, 389 Directory Server403nonenew
- 23PyPIInventree, Oauthenticator, Perdido3716nonenew
- 24Ао «ивк»Альт 8 Сп, Альт Сп 10372nonenew
- 25SiemensSinema Remote Connect Server, Sicam Gridedge (Classic), Sicam Gridedge Essential303nonenew
Severity
How this month's CVEs score on CVSS; 118 have no score yet. Severity is not exploitation.
- Critical331
- High815
- Medium944
- Low94
New in the top 100
Not in the top 100 in any of the 24 months before.
What kind of weakness
Weakness classes (CWE) by distinct CVEs, with how far each moved in the ranking.
- CWE-79XSS336
- CWE-89SQL Injection268
- CWE-787Out-of-bounds Write137
- CWE-352CSRF110
- CWE-269Improper Privilege Mgmt63
- CWE-125Out-of-bounds Read61
- CWE-20Improper Input Validation60
- CWE-200Information Exposure60
- CWE-78OS Command Injection55
- CWE-862Missing Authorization49
- CWE-22Path Traversal47
- CWE-8043
- CWE-522Insufficiently Protected Credentials37
- CWE-416Use After Free34
- CWE-287Improper Authentication33
- CWE-434Unrestricted File Upload28
- CWE-119Memory Buffer Bounds27
- CWE-918SSRF25
- CWE-306Missing Auth for Critical Function23
- CWE-863Incorrect Authorization23
Where it landed
The month's CVEs by the sector of the software they affect. A CVE that touches several sectors counts in each.
- OSS Libraries54017% of sector-tagged CVEs
- Web & CMS Plugins38813% of sector-tagged CVEs
- Enterprise Software34511% of sector-tagged CVEs
- Operating Systems33511% of sector-tagged CVEs
- Consumer Software2057% of sector-tagged CVEs
- Mobile Apps1736% of sector-tagged CVEs
- ICS / OT / IoT1625% of sector-tagged CVEs
- Hardware Firmware1475% of sector-tagged CVEs
- Networking Infrastructure1334% of sector-tagged CVEs
- DevTools & CI1264% of sector-tagged CVEs
- Not yet classified241
Which weakness, where
The top weakness classes against the vendors and the sectors that carried them.
The lighter the cell, the more CVEs. Point at one to read it.
| By vendor | 79XSS | 89SQL Injection | 787Out-of-bounds Write | 352CSRF | 269Improper Privilege Mgmt | 125Out-of-bounds Read | 20Improper Input Validation | 200Information Exposure | 78OS Command Injection | 862Missing Authorization |
|---|---|---|---|---|---|---|---|---|---|---|
| 17 | 14 | 14 | 11 | |||||||
| Maven | 36 | 1 | 13 | 1 | 1 | 15 | ||||
| Unspecified | 22 | 14 | 22 | 4 | 20 | 1 | 2 | 2 | ||
| Jenkins | 33 | 13 | 15 | |||||||
| Jenkins Project | 33 | 13 | 15 | |||||||
| Сообщество Свободного Программного Обеспечения | 3 | 1 | 9 | 2 | 7 | 4 | 1 | |||
| Ооо «русбитех-астра» | 9 | 1 | 7 | 2 | 1 | |||||
| Qualcomm | 4 | 10 | 4 | 2 | ||||||
| Qualcomm, Inc. | 4 | 10 | 4 | 2 | ||||||
| Ао «нппкт» | 1 | 5 | 1 | 4 | 5 | 1 | ||||
| Microsoft Corp | 1 | |||||||||
| Crates.io | 1 |