Month report
January 2013
Rolled up 2026-08-09 20:45 from 370,700 CVE records
439 CVEs published, +39.8% on the same month last year. 6 rated critical, 0 listed by CISA as exploited. rockwell automation led with 8; the most common weakness class was CWE-284 (5). redhat climbed 2 places, the largest move. 4 vendors ranked for the first time.
Published
439
Critical / high
6 / 8
Medium / low
5 / 1
Added to CISA KEV
0
Public exploit
72
Scanner template
0
Publication to KEV
How long before CISA listed them
Median days to listing
3344
Listed within 7 days
0%
Listed within 30 days
0%
Weakness × vendor
Where the two overlap
| Vendor | CWE-284 | CWE-287 | CWE-119 | CWE-23 | CWE-200 | CWE-266 | CWE-276 | CWE-280 |
|---|---|---|---|---|---|---|---|---|
| rockwell automation | 3 | 2 | 2 | 1 | ||||
| 3s smart software solutions | 1 | 1 | ||||||
| festo | 1 | 1 | ||||||
| redhat | 1 | 1 | ||||||
| specview | 1 |
Vendors
Ranked by distinct CVEs this month
| # | Vendor | Top products | ||||||
|---|---|---|---|---|---|---|---|---|
| 1 | rockwell automation | 8 | 1 | 1756 enbt 1756 eweb 1768 enbt 1768 eweb communication modules (8) · 1788 enbt flexlogix adapter (8) · 1794 aentr flex i o ethernet ip adapter (8) | new | |||
| 2 | 3s smart software solutions | 2 | 2 | cecx x c1 modular master controller with codesys (2) · cecx x m1 modular controller with codesys and softmotion (2) · codesys (2) | new | |||
| 3 | festo | 2 | 2 | cecx x c1 modular master controller with codesys (2) · cecx x m1 modular controller with codesys and softmotion (2) · codesys (2) | new | |||
| 4 | redhat | 2 | red hat jboss enterprise application platform 6 0 (2) · red hat jboss enterprise application platform 6 for rhel 5 (2) · red hat jboss enterprise application platform 6 for rhel 6 (2) | ↑2 | ||||
| 5 | specview | 1 | 1 | specview (1) | new |
One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2013-01 that are on the CISA KEV catalog today. The 0 in the headline is what CISA listed during the month, whenever those CVEs were published. All 5 ranked vendors are listed; a zero count renders as a dot.
Weaknesses
CWE classes by distinct CVEs
- 1CWE-28452 critical·
- 2CWE-28732 critical·
- 3CWE-11920 critical·
- 4CWE-2321 criticalnew
- 5CWE-20010 critical·
- 6CWE-26610 criticalnew
- 7CWE-27611 critical·
- 8CWE-28010 criticalnew
- 9CWE-69310 criticalnew
One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.