Month report
October 2019
Rolled up 2026-08-09 20:45 from 370,690 CVE records
1,566 CVEs published, +6.7% on the same month last year. 23 rated critical, 0 listed by CISA as exploited. oracle led with 137; the most common weakness class was CWE-79 (22). trend micro climbed 47 places, the largest move. 21 vendors ranked for the first time.
Published
1,566
Critical / high
23 / 140
Medium / low
118 / 13
Added to CISA KEV
0
Public exploit
89
Scanner template
0
Publication to KEV
How long before CISA listed them
Median days to listing
887
Listed within 7 days
0%
Listed within 30 days
0%
Weakness × vendor
Where the two overlap
| Vendor | CWE-79 | CWE-89 | CWE-416 | CWE-119 | CWE-125 | CWE-20 | CWE-200 | CWE-400 |
|---|---|---|---|---|---|---|---|---|
| oracle | ||||||||
| cisco | 18 | 9 | 16 | 11 | 3 | 4 | ||
| adobe | ||||||||
| microsoft | ||||||||
| jenkins project | ||||||||
| ibm | ||||||||
| foxit | 16 | 4 | ||||||
| juniper networks | 1 | 1 |
Vendors
Ranked by distinct CVEs this month
| # | Vendor | Top products | ||||||
|---|---|---|---|---|---|---|---|---|
| 1 | oracle | 137 | 1 | 1 | 4 | mysql server (28) · java (19) · vm virtualbox (10) | · | |
| 2 | cisco | 85 | 1 | cisco firepower management center (19) · cisco spa112 2 port phone adapter (18) · cisco adaptive security appliance asa software (8) | ↑1 | |||
| 3 | adobe | 84 | 3 | adobe acrobat and reader (69) · adobe experience manager (12) · adobe download manager (1) | ↑10 | |||
| 4 | microsoft | 60 | 2 | 8 | windows (37) · windows server (37) · windows 10 version 1903 for 32 bit systems (31) | ↓3 | ||
| 5 | jenkins project | 46 | 1 | jenkins crx content package deployer plugin (3) · jenkins dynatrace application monitoring plugin (3) · jenkins elasticbox jenkins kubernetes ci cd plugin (3) | ↓3 | |||
| 6 | ibm | 41 | cloud orchestrator (9) · security guardium big data intelligence (8) · security directory server (5) | ↓2 | ||||
| 7 | foxit | 27 | reader (13) · phantompdf (10) · studio photo (4) | · | ||||
| 8 | juniper networks | 25 | junos os (24) · sbr carrier (1) | · | ||||
| 9 | isc | 14 | 1 | bind 9 (8) · kea (3) · bind 9 supported preview edition (2) | · | |||
| 10 | sap se | 12 | sap businessobjects business intelligence platform web intelligence html interface (5) · sap financial consolidation (2) · sap customer relationship management email management bbpcrm (1) | — | ||||
| 11 | redhat | 10 | ansible (2) · bind9 (1) · bootstrap3 typeahead js (1) | ↑45 | ||||
| 12 | chicken | 6 | chicken (6) | new | ||||
| 13 | clipsoft | 6 | rexpert (6) | new | ||||
| 14 | cobham | 6 | explorer 710 (6) | new | ||||
| 15 | kaspersky | 6 | tightvnc (4) · libvnc (1) · turbovnc (1) | · | ||||
| 16 | trend micro | 6 | 1 | 2 | deep security agent (1) · deep security manager (1) · trend micro anti threat toolkit attk (1) | ↑47 | ||
| 17 | abcprintf | 5 | online store (5) | new | ||||
| 18 | hinet | 5 | 4 | gpon (5) | new | |||
| 19 | milesight | 5 | ip security cameras (5) | new | ||||
| 20 | intel | 4 | nuc advisory (2) · active system console advisory (1) · smart connect technology for intel nuc advisory (1) | · | ||||
| 21 | mantisbt | 4 | mantisbt (4) | new | ||||
| 22 | postgresql | 4 | postgresql (4) | · | ||||
| 23 | siemens | 4 | simatic winac rtx f 2010 (3) · development evaluation kits for profinet io dk standard ethernet controller (2) · development evaluation kits for profinet io ek ertec 200 (2) | ↓8 | ||||
| 24 | apache | 3 | apache thrift (2) · apache mina (1) | ↓13 | ||||
| 25 | dell | 3 | avamar (1) · dell encryption enterprise (1) · dell endpoint security suite enterprise (1) | ↓19 | ||||
| 26 | elastic | 3 | elastic code (1) · elasticsearch (1) · logstash (1) | · | ||||
| 27 | pivotal | 3 | apps manager (1) · rabbitmq (1) · rabbitmq for pcf (1) | ↑28 | ||||
| 28 | tiki wiki | 3 | cms groupware (3) | new | ||||
| 29 | activesoft | 2 | mybuilder (2) | new | ||||
| 30 | ca technologies a broadcom | 2 | 2 | ca network flow analysis (1) · ca performance management (1) | · | |||
| 31 | cloud foundry | 2 | cf deployment (2) · smb volume (1) · uaa release (1) | ↓8 | ||||
| 32 | 2 | 1 | hhvm (1) · whatsapp for android (1) | ↓5 | ||||
| 33 | fortinet | 2 | fortiextender (1) · fortinet fortios (1) | · | ||||
| 34 | icedtea | 2 | icedtea6 (2) | · | ||||
| 35 | mcafee | 2 | mcafee endpoint security ens (2) | ↓15 | ||||
| 36 | palo alto networks | 2 | globalprotect agent for linux and osx (1) · globalprotect agent for windows (1) | · | ||||
| 37 | rpcbind | 2 | rpcbind (2) | new | ||||
| 38 | snyk | 2 | 1 | safer eval (2) | new | |||
| 39 | topoo technology | 2 | topmeeting (2) | new | ||||
| 40 | transmission | 2 | transmission (2) | new | ||||
| 41 | zte | 2 | zx297520v3 (1) · zxmp m721 dx (1) | ↑26 | ||||
| 42 | asterisk | 1 | asterisk (1) | new | ||||
| 43 | autojump | 1 | autojump (1) | new | ||||
| 44 | bitlbee | 1 | bitlbee (1) | new | ||||
| 45 | chromium browser | 1 | chromium browser (1) | new | ||||
| 46 | debian | 1 | bind9 (1) | · | ||||
| 47 | dogtag | 1 | jss (1) | new | ||||
| 48 | drbd8 | 1 | drbd8 (1) | new | ||||
| 49 | fon wireless | 1 | fon2601e se fon2601e re fon2601e fsw s and fon2601e fsw b (1) | new | ||||
| 50 | gmer | 1 | gmer (1) | new |
One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2019-10 that are on the CISA KEV catalog today. The 0 in the headline is what CISA listed during the month, whenever those CVEs were published. All 50 ranked vendors are listed; a zero count renders as a dot.
Weaknesses
CWE classes by distinct CVEs
- 1CWE-79220 critical↑1
- 2CWE-89221 critical↑72
- 3CWE-416200 critical↑7
- 4CWE-119190 critical↑4
- 5CWE-125175 critical↑13
- 6CWE-20150 critical↓5
- 7CWE-200110 critical↑7
- 8CWE-40090 critical↑44
- 9CWE-75590 critical·
- 10CWE-12270 critical↑3
- 1CWE-2271 critical↓2
- 2CWE-28471 critical↓8
- 3CWE-7873 critical↓10
- 4CWE-26450 critical↑23
- 5CWE-30650 critical·
- 6CWE-78750 critical↓4
- 7CWE-12040 critical↑7
- 8CWE-53240 critical↑43
- 9CWE-31930 critical·
- 10CWE-35230 critical↑27
One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.