BlackTreeCVE IntelligenceStructured vendor attributionCISA KEV is confirmed exploitationCVSS is technical severity
CVEs by vendor
Compare the scale and character of disclosures without treating a high CVE count as proof that a vendor is less secure. Product identity comes from retained structured source evidence.
2026 catalogue
Vendor comparison
50 vendors with at least five attributed CVEs. 30,152 records in this comparison.
| Vendor | CVEs | Critical | High | CISA KEV | Avg CVSS |
|---|---|---|---|---|---|
| Linux | 7,155 | 537 | 2,798 | 3 | 7.3 (4,851 scored) |
| 3,326 | 374 | 1,392 | 8 | 7.0 (3,218 scored) | |
| Oracle Corporation | 3,074 | 589 | 1,699 | 0 | 7.6 (3,074 scored) |
| Microsoft | 3,007 | 204 | 2,048 | 26 | 7.4 (3,007 scored) |
| IBM | 1,233 | 144 | 518 | 1 | 7.0 (1,233 scored) |
| Red Hat | 931 | 42 | 348 | 0 | 6.4 (931 scored) |
| Apache Software Foundation | 863 | 183 | 362 | 0 | 7.4 (860 scored) |
| Adobe | 833 | 82 | 363 | 4 | 6.9 (830 scored) |
| Apple | 804 | 70 | 259 | 2 | 6.5 (804 scored) |
| OpenClaw | 663 | 28 | 285 | 0 | 6.6 (663 scored) |
| Mozilla | 513 | 183 | 221 | 0 | 8.1 (513 scored) |
| Dell | 485 | 24 | 200 | 1 | 6.6 (485 scored) |
| SourceCodester | 387 | 0 | 0 | 0 | 6.0 (387 scored) |
| code-projects | 350 | 0 | 1 | 0 | 6.2 (350 scored) |
| Cisco | 320 | 58 | 106 | 15 | 7.1 (320 scored) |
| Tenda | 291 | 24 | 229 | 0 | 8.4 (291 scored) |
| WWBN | 277 | 36 | 100 | 0 | 7.0 (277 scored) |
| itsourcecode | 275 | 0 | 0 | 0 | 5.9 (275 scored) |
| Canonical | 270 | 18 | 17 | 0 | 7.0 (63 scored) |
| NVIDIA | 248 | 11 | 181 | 0 | 7.4 (248 scored) |
| BSI | 233 | 0 | 0 | 0 | Not scored |
| Hewlett Packard Enterprise (HPE) | 220 | 19 | 129 | 0 | 7.1 (220 scored) |
| GitLab | 212 | 6 | 66 | 1 | 5.9 (212 scored) |
| Spring | 206 | 10 | 71 | 0 | 6.3 (206 scored) |
| D-Link | 200 | 41 | 84 | 0 | 7.7 (200 scored) |
| siyuan-note | 199 | 59 | 80 | 0 | 7.9 (199 scored) |
| TOTOLINK | 193 | 106 | 32 | 0 | 8.2 (193 scored) |
| ThemeREX | 179 | 23 | 155 | 0 | 8.3 (179 scored) |
| SAP SE | 174 | 23 | 28 | 0 | 6.1 (174 scored) |
| Elastic | 163 | 0 | 30 | 0 | 6.2 (163 scored) |
| ImageMagick | 161 | 1 | 20 | 0 | 5.4 (161 scored) |
| Mattermost | 161 | 0 | 16 | 0 | 5.2 (161 scored) |
| MervinPraison | 157 | 44 | 84 | 0 | 8.2 (157 scored) |
| MongoDB | 157 | 4 | 94 | 0 | 6.9 (157 scored) |
| TP-Link Systems Inc. | 154 | 1 | 101 | 0 | 7.3 (154 scored) |
| Drupal | 149 | 12 | 16 | 1 | 5.9 (149 scored) |
| n8n-io | 146 | 20 | 68 | 0 | 7.2 (146 scored) |
| Samsung Mobile | 146 | 3 | 29 | 0 | 6.3 (146 scored) |
| MediaTek, Inc. | 143 | 2 | 31 | 0 | 6.4 (143 scored) |
| Splunk | 143 | 6 | 50 | 1 | 6.4 (143 scored) |
| getgrav | 142 | 19 | 80 | 0 | 7.6 (142 scored) |
| open-webui | 139 | 2 | 61 | 0 | 6.4 (139 scored) |
| Jenkins Project | 138 | 2 | 44 | 0 | 5.9 (138 scored) |
| misp | 138 | 9 | 44 | 0 | 6.6 (138 scored) |
| Qualcomm, Inc. | 136 | 3 | 92 | 0 | 7.4 (136 scored) |
| zephyrproject | 136 | 1 | 34 | 0 | 5.9 (136 scored) |
| discourse | 133 | 1 | 16 | 0 | 5.2 (133 scored) |
| Huawei | 132 | 2 | 18 | 0 | 5.8 (132 scored) |
| FreeRDP | 131 | 10 | 70 | 0 | 7.1 (131 scored) |
| craftcms | 126 | 5 | 57 | 0 | 6.7 (126 scored) |
Each CVE is counted once using its structured product-source vendor. Unattributed records and groups with fewer than five CVEs are omitted. CISA KEV counts confirmed exploitation; CVSS averages include only scored records. Disclosure volume is not a vendor safety rating.