Vulnerabilities by Vendor
CVE records grouped by vendor, ranked by count. Each vendor page lists affected products, confirmed exploitation from the CISA KEV catalog, and links to the vendor's security advisories.
Vendors
30 totalWindows, Internet Explorer, Office
IOS and IOS XE Software, Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD), IOS software
Multiple Products, iOS, iPadOS, and macOS, iOS
Flash Player, ColdFusion, Acrobat and Reader
Chromium V8, Chromium, Chrome
DNS-120, DIR-823X, DIR-615
WebLogic Server, Java SE, Fusion Middleware
Struts, Tomcat, HTTP Server
Pulse Connect Secure, Endpoint Manager Mobile (EPMM), Endpoint Manager (EPM)
vCenter Server, ESXi, Multiple Products
Kernel
FortiOS, Multiple Products, FortiOS and FortiProxy
NetScaler, NetScaler ADC and NetScaler Gateway, Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
Zimbra Collaboration Suite (ZCS), Zimbra Collaboration Suite (ZCS), Zimbra Collaborate Suite (ZCS)
SMA1000 Appliances, SonicOS, SonicWall Email Security
NU516U1, WL-NU516U1, WL-WN579A3
Framework, Pixel, Kernel
Mobile Devices, MagicINFO 9 Server
PAN-OS, Expedition
AC6, F453, G103
NetWeaver, Commerce Cloud, Customer Relationship Management (CRM)
Multiple Firewalls, DSL CPE Devices, Multiple Network-Attached Storage (NAS) Devices
Firefox and Thunderbird, Firefox, Firefox, Firefox ESR, and Thunderbird
Confluence Data Center and Server, Confluence Server and Data Center, Jira Server and Data Center
Apex One, Apex One and OfficeScan, Apex One, Apex One as a Service, and Worry-Free Business Security
Multiple Chipsets, Multiple Chipsets , Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Network Attached Storage (NAS), Photo Station, Helpdesk
Web Help Desk, Serv-U, Orion
Webmail, Roundcube Webmail
TEW-657BRM, TEW-432BRP, TEW-713RE
Frequently Asked Questions
Which vendors have the most actively exploited vulnerabilities?→
By count of CISA KEV entries in this database, the top vendors are Microsoft (389), Cisco (100), Apple (95). The count measures confirmed exploitation only. It is not a rating of overall product security.
How are vendors assigned to vulnerabilities?→
For CVEs in the CISA KEV catalog, the vendor and product come from the vendorProject and product fields CISA publishes. For other CVEs, the vendor comes from the affected-product data in the CVE record.
Why is a vendor missing from this list?→
A vendor gets its own page once at least 10 CVE records in this database belong to it. Vendors with fewer records are still listed on the individual CVE pages.
Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). CVE record data © The MITRE Corporation, used under the CVE Terms of Use. This site is not endorsed or certified by MITRE or CISA.