CVE Intelligence
Skip to main content

Month report

April 2019

Rolled up 2026-08-09 20:45 from 370,662 CVE records

1,531 CVEs published, -8.2% on the same month last year. 20 rated critical, 0 listed by CISA as exploited. oracle led with 160; the most common weakness class was CWE-284 (20). linux climbed 48 places, the largest move. 9 vendors ranked for the first time.

Published

1,531

+28.2%on the previous month

Critical / high

20 / 104

of the 280 scored

Medium / low

138 / 18

the rest of the scored bands

Added to CISA KEV

0

listed as exploited this month

Public exploit

129

exploit code indexed publicly

Scanner template

0

0% of the month

Publication to KEV

How long before CISA listed them

16 published this month and listed since — not the 0 listed during it.

Median days to listing

1016.5

from publication to CISA's date added

Listed within 7 days

0%

of the 16

Listed within 30 days

0%

of the 16

Weakness × vendor

Where the two overlap

CVEs carrying both. Each row is shaded against its own worst class.
VendorCWE-284CWE-20CWE-79CWE-200CWE-287CWE-22CWE-400CWE-78
oracle
microsoft2
jenkins project
ibm
cisco2145111
mozilla
synology2812
juniper networks213

Vendors

Ranked by distinct CVEs this month

Δ is the move against last month's rank.
Vendors ranked by distinct CVEs published in 2019-04, sorted by CVEs descending
#VendorTop products
1oracle16029mysql server (40) · vm virtualbox (12) · weblogic server (10)·
2microsoft139716windows (72) · windows server (72) · microsoft edge (23)↓1
3jenkins project93jenkins ansible tower plugin (3) · jenkins audit to database plugin (3) · jenkins ftp publisher plugin (3)↑3
4ibm5831sterling b2b integrator (10) · security privileged identity manager (7) · api connect (6)↓1
5cisco382cisco wireless lan controller wlc (8) · cisco aironet access point software (5) · clamav (5)↓3
6mozilla354firefox (31) · thunderbird (14) · firefox esr (11)·
7synology20diskstation manager dsm (5) · synology router manager srm (5) · application service (2)·
8juniper networks161junos os (14) · juniper identity management service (1) · service insight (1)·
9android15android (15)·
10crestron15111crestron airmedia (13) · crestron airmedia barco wepresent extron sharelink teq av it wips710 sharp pn l703wa optoma wps pro blackbox hd wps infocus liteshow3 and infocus liteshow4 (2)·
11ubuntu151maas (4) · unity8 (2) · apport (1)·
12apache1315apache http server (3) · apache zeppelin (3) · apache archiva (2)↓4
13siemens11cp 1604 (3) · cp 1616 (3) · simatic cp 443 1 opc ua (2)↑27
14the eclipse foundation9eclipse jetty (3) · eclipse kura (3) · eclipse hawkbit (1)↑12
15vmware9esxi (3) · fusion (3) · workstation (3)·
16dell emc81idrac (3) · dell emc isilonsd management server (2) · open manage system administrator (2)↑39
17redhat7389 ds base (1) · bind (1) · candlepin (1)↑22
18tibco software72tibco activematrix bpm (6) · tibco activematrix bpm distribution for tibco silver fabric (6) · tibco silver fabric enabler for activematrix bpm (6)↓2
19linux6kernel (4) · linux (2)↑48
20qualcomm6snapdragon auto snapdragon compute snapdragon consumer electronics connectivity snapdragon consumer iot snapdragon industrial iot snapdragon mobile (2) · snapdragon auto snapdragon compute snapdragon consumer iot snapdragon industrial iot snapdragon mobile snapdragon wearables (1) · snapdragon auto snapdragon consumer electronics connectivity snapdragon consumer iot snapdragon industrial iot snapdragon mobile snapdragon voice music (1)·
21sap se61sap basis (1) · sap crystal reports for visual studio (1) · sap hana (1)↓7
22symantec6norton security (2) · sep cloud (1) · sep sbe (1)·
23wi fi alliance6hostapd with sae support (5) · wpa supplicant with sae support (5) · hostapd with eap pwd support (4)·
24advantech5webaccess scada (3) · webaccess (2)·
25cloud foundry5uaa release oss (2) · bosh backup and restore (1) · capi release (1)↓7
26fortinet5forticlientmac (1) · fortinet fortimanager (1) · fortinet fortios (1)↑17
27gog com52gog galaxy (5)new
28humantalk co5daviewindy (5)new
29autodesk4autodesk advance steel (4) · autodesk autocad (4) · autodesk autocad architecture (4)new
30kubernetes41kubernetes (4)·
31nvidia4jetson tx2 (2) · jetson tegra tx2 (1) · jetson tx1 and tx2 (1)↑42
32pivotal4uaa release oss (2) · apps manager (1) · cf deployment (1)↑16
33sonicwall4sonicos (3) · sonicosv (3) · global management system gms (1)·
34atlassian311atlassian application links (1) · confluence (1) · jira (1)↓25
35clusterlabs3pacemaker (3)·
36facebook3fizz (1) · hhvm (1) · wangle (1)·
37honeywell3experion pks (3)↑7
38lenovo3bios (1) · lenovo bootable generator (1) · system x (1)·
39odoo3odoo enterprise (3) · odoo community (2)new
40ubiquiti networks3edgemax (3)·
41verizon3fios quantum gateway g1100 (3)new
42canonical22snapd (2)·
43check point2check point endpoint security client for windows (1) · check point ipsec vpn (1)new
44dell21supportassist client (2)↓15
45detcon2sitewatch gateway (2)new
46f52big ip apm (1) · big ip ltm aam afm analytics apm asm dns edge gateway fps gtm link controller pem webaccelerator (1)new
47forcepoint2forcepoint email security (2)↑13
48freedesktop org22systemd (2)·
49fujifilm2fujifilm fcr capsula x carbon x (2)new
50micro focus2micro focus content manager (1) · micro focus network automation and micro focus network operations management nom (1)↓19

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2019-04 that are on the CISA KEV catalog today. The 0 in the headline is what CISA listed during the month, whenever those CVEs were published. All 50 ranked vendors are listed; a zero count renders as a dot.

Weaknesses

CWE classes by distinct CVEs

  • 1CWE-284200 critical↑3
  • 2CWE-20162 critical↓1
  • 3CWE-79161 critical
  • 4CWE-200100 critical↑18
  • 5CWE-287100 critical↑44
  • 6CWE-2280 critical↑2
  • 7CWE-40070 critical↑3
  • 8CWE-7861 critical↑7
  • 9CWE-12151 critical↓3
  • 10CWE-40450 critical·
  • 1CWE-12540 critical↓9
  • 2CWE-19040 critical↓1
  • 3CWE-35240 critical↑13
  • 4CWE-39940 critical↑19
  • 5CWE-12230 critical↓8
  • 6CWE-27630 critical·
  • 7CWE-41630 critical↓3
  • 8CWE-49430 critical·
  • 9CWE-52430 criticalnew
  • 10CWE-6530 criticalnew

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.