CVE Intelligence
Skip to main content

Month report

March 2019

Rolled up 2026-08-09 20:45 from 370,662 CVE records

1,194 CVEs published, -10.7% on the same month last year. 18 rated critical, 0 listed by CISA as exploited. microsoft led with 77; the most common weakness class was CWE-20 (26). kaspersky lab climbed 20 places, the largest move. 11 vendors ranked for the first time.

Published

1,194

+42.5%on the previous month

Critical / high

18 / 119

of the 261 scored

Medium / low

113 / 11

the rest of the scored bands

Added to CISA KEV

0

listed as exploited this month

Public exploit

124

exploit code indexed publicly

Scanner template

0

0% of the month

Publication to KEV

How long before CISA listed them

12 published this month and listed since — not the 0 listed during it.

Median days to listing

1058.5

from publication to CISA's date added

Listed within 7 days

0%

of the 12

Listed within 30 days

0%

of the 12

Weakness × vendor

Where the two overlap

CVEs carrying both. Each row is shaded against its own worst class.
VendorCWE-20CWE-125CWE-79CWE-284CWE-77CWE-121CWE-122CWE-22
microsoft1
cisco232491
ibm
intel
apple
jenkins project
kaspersky lab233
apache

Vendors

Ranked by distinct CVEs this month

Δ is the move against last month's rank.
Vendors ranked by distinct CVEs published in 2019-03, sorted by CVEs descending
#VendorTop products
1microsoft77123windows (32) · windows server (32) · microsoft edge (21)·
2cisco6412nexus 3000 series switches (21) · nexus 3500 platform switches (20) · nexus 9000 series switches in standalone nx os mode (17)
3ibm51db2 for linux unix and windows (7) · rational quality manager (7) · rational collaborative lifecycle management (4)↑2
4intel39intel r graphics driver for windows (19) · intel r csme server platform services trusted execution engine and intel r active management technology (12) · intel platform sample silicon reference firmware (5)·
5apple3019ios (29) · tvos (21) · macos (19)·
6jenkins project20222jenkins azure vm agents plugin (3) · jenkins fortify on demand uploader plugin (2) · jenkins pipeline groovy plugin (2)↑1
7kaspersky lab18ultravnc (16) · invision power board (1) · vanilla forums (1)↑20
8apache124apache jspwiki (2) · apache mesos (2) · apache solr (2)↑7
9atlassian11111crowd (5) · confluence server (2) · sourcetree for windows (2)↑4
10ics cert11moxa iks eds (9) · gpsd and microjson open source project (1) · psi gridconnect gmbh formerly known as psi nentec gmbh telecontrol gateway and smart telecontrol unit family iec104 security proxy (1)↓2
11foxit9reader (5) · phantompdf (4)·
12the libssh2 project91libssh2 (9)new
13extensible firmware interface development kit edk ii8extensible firmware interface development kit edk ii (8)new
14sap se8abap platform server kernel (1) · abap platform server krnl32nuc (1) · abap platform server krnl32uc (1)↓3
15suse8supportutils (5) · yast2 multipath (1) · yast2 printer (1)·
16tibco software821tibco jasperreports server (5) · tibco jasperreports server for activematrix bpm (5) · tibco jasperreports server community edition (4)·
17big ip7big ip ltm aam afm analytics apm asm dns edge gateway fps gtm link controller pem webaccelerator (6) · big ip asm (1)new
18cloud foundry71cloud foundry container runtime cfcr (2) · stratos (2) · capi (1)↑18
19hospira71symbiq infusion system (5) · plum a 3 infusion system (4) · plum a infusion system (4)·
20jolly technologies7lobby track desktop (7)new
21elastic6111kibana (3) · logstash (2) · elasticsearch (1)·
22f5 networks6big ip aam (1) · big ip apm (1) · big ip apm enterprise manager (1)↓8
23tenable61alcatel lucent i 240w q gpon ont (6)↑8
24ultravnc6ultravnc (6)new
25talos52pixar renderman (3) · coturn (2)↓5
26the eclipse foundation5eclipse mosquitto (4) · eclipse jetty (1)↑6
27visitorpass5evisitorpass (5)new
28baxter4sigma spectrum infusion system (4)new
29dell4rsa archer (2) · rsa authentication manager (1) · wyse device agent (1)↓4
30hid global4easylobby solo (4)new
31micro focus4solutions business manager sbm (4)↓3
32rockwell automation4rslinx enterprise software (3) · plc5 (1) · rslogix (1)·
33flexera software3flexnet publisher (3)↓14
34hp3hp laserjet enterprise hp pagewide enterprise hp laserjet managed and hp officejet enterprise printers (1) · hp remote graphics software (1) · hp support assistant (1)·
35moxa3softcms (2) · oncell g3100v2 series (1) · oncell g3111 g3151 g3211 g3251 series (1)·
36netapp3snapcenter server (2) · netapp service processor (1)↓13
37palo alto3palo alto networks expedition migration tool (3)·
38rails312https github com rails rails (3)·
39redhat3ansible (1) · tower (1) · wildfly core (1)↑12
40siemens3firmware variant dnp3 tcp for en100 ethernet module (1) · firmware variant iec104 for en100 ethernet module (1) · firmware variant iec 61850 for en100 ethernet module (1)·
41article2pdf2article2pdf wordpress plug in (2)new
42envoy2envoy passport for android (2) · envoy passport for iphone (2)new
43fortinet2fortinet fortiportal (2)↓2
44honeywell2experion pks (2)·
45mcafee2mcafee network security manager nsm (2)↓29
46medtronic21amplia crt d (2) · brava crt d (2) · carelink 2090 programmer (2)·
47node js21node js (2)·
48pivotal2apps manager (1) · pivotal application service (1) · pivotal ops manager (1)·
49puppet2chloride (1) · puppet discovery (1)·
50the ghostscript project2ghostscript (2)new

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2019-03 that are on the CISA KEV catalog today. The 0 in the headline is what CISA listed during the month, whenever those CVEs were published. All 50 ranked vendors are listed; a zero count renders as a dot.

Weaknesses

CWE classes by distinct CVEs

  • 1CWE-20261 critical↑2
  • 2CWE-125191 critical↑2
  • 3CWE-79140 critical↓2
  • 4CWE-284111 critical↑4
  • 5CWE-77110 critical·
  • 6CWE-12190 critical↑10
  • 7CWE-12280 critical↓1
  • 8CWE-2272 critical↓1
  • 9CWE-26471 critical↑17
  • 10CWE-40070 critical↓8
  • 1CWE-19060 critical·
  • 2CWE-28550 critical↑5
  • 3CWE-29550 critical↑6
  • 4CWE-41650 critical↑6
  • 5CWE-7850 critical↑7
  • 6CWE-78750 critical↓2
  • 7CWE-37740 critical·
  • 8CWE-78840 criticalnew
  • 9CWE-86340 critical·
  • 10CWE-9442 critical↑22

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.