Top 50 vendors and products by “distinct” security vulnerabilities

With the help of CVE Details security vulnerability database, we’ve tracked the number of distinct vulnerabilities across the top 50 vendors and products from 1999 to 2019.

More than 64,000 vulnerabilities have been logged across the top 50 vendors and over 73,000 across the top 50 products.

Which brands and products have had the most distinct vulnerabilities?

We take a look below.

Top 50 vendors for security vulnerabilities

Microsoft has had the most security vulnerabilities since 1999, with just over 6,700, followed by Oracle with 5,500 and IBM with 4,600.

The biggest spike in vulnerabilities can from Debian in 2018 with 1,200 logged. In fact, 2018 saw the biggest number of vulnerabilities across the top 50 vendors with a 19.3 percent increase on 2017. Figures reduced again in 2019 with a 34 percent drop year on year.

Top 50 products for security vulnerabilities

Debian Linux has had the most security vulnerabilities since 1999, with nearly 3,000 followed by Google Android with 2,500 and Linux Kernel with 2,300.

In 2018, Debian Linux saw the biggest spike in security vulnerabilities with 1,197.

Top 50 vendors with security vulnerabilities - year by year figures

Vendor199920002001200220032004200520062007200820092010201120122013201420152016201720182019Total
Microsoft1721431732431041481662672592372363172531723453745684916987126686746
Oracle41134551830791581311201572072243805054728018767564895507
IBM22165943335481911331471722021691753904563163816836193644606
Google4515429428019115831870010017906094540
Apple7122347661481382092132183032553111993087083285931882294503
Cisco2116556527365469111901091551671604333684903534914434404153
Adobe716313564952072021461481384835483533854413299
Redhat4048492337481013937174035572002242412671808232572763
Debian27163381224602324681917249213224733612003602722
Linux1952215195113390627610212486116189131862184541781702346
Mozilla1030135993122881001431211162041601201891433601182189
Canonical1421431115921502662881677361972000
HP1736475742293639656978119143841431101061142311291694
SUN54265757645575861161572189011411217530151501
Opensuse48138154293327109821481299
Apache891632252424174424354344617491571022151581081211
Opera17342839563221605832
Fedoraproject317114312510071187728
GNU4141219153948221720131826234528221978055717
Novell8892216203445274124448131456190606
Qualcomm6886376171575
PHP14111843116212235372213332810644563
Wireshark14252325153146822933955879555
D-link1545654525
SAP1211131715268354545011575525
Huawei13100181193487
Imagemagick3577157485
Foxitsoftware67247162476
Jenkins1919161254453
Symantec58622928194145312814175023293337445
Suse181821933821839439243416
Cpanel13321334
EMC213049627773312
Juniper27473221865534302
Moodle111716119542482537302
Siemens42383336375362301
Joomla5159962510162513295
Wordpress16485514123220292043289
Netapp44119112275
McAfee51712453224584434271
Ffmpeg1113547719292047270
Drupal373570528143419269
Vmware25312024183418153645266
Freebsd1827363114151727151181013242
Qemu36916538230
F523528863226
XEN3542412862208
Phpmyadmin211317111017172076202
Mysql1021151416584222198
Trend Micro617721206659196

Top 50 products with security vulnerabilities - year by year figures

VendorProduct Name199920002001200220032004200520062007200820092010201120122013201420152016201720182019Total
DebianDebian Linux27163110174721198510824133544811973602962
GoogleAndroid1255258436134142520
LinLinux Kernel1952215195113390627110212383115189130862174541771702333
AppleMac Os X202554961061109581977437721504442173001172095
UbuntuUbuntu Linux45132143921472652861647361902002
GoogleChrome391502662491741271871721531611771855
MozillaFirefox227510177931261061011631491081791333331766
AppleIphone OS273237112961223871643871561520
MicrosoftWindows 7641024499351491342291622501268
MicrosoftWindows Server 200822799210550103381511332432481264
AdobeAcrobat Dc1042272092993421181
AdobeAcrobat Reader Dc1042272092993421181
MicrosoftWindows 10571722682573571111
MicrosoftWindows Server 201252381551562351632461045
AdobeFlash Player21206063665676329266711028
RedhatEnterprise Linux Desktop20557414186484121981
RedhatEnterprise Linux Server297714188511125971
MicrosoftWindows 8.136150154225164242971
RedhatEnterprise Linux Workstation7414176493123907
OpensuseOpensuse4813715026923661901
MicrosoftInternet Explorer383212824323112979880
AdobeAcrobat456559286443137224210875
AppleSafari1742377312149907213556179871
MicrosoftWindows Server 2016251242357850
MicrosoftWindows Vista353776869542953313712764827
MozillaThunderbird1365165039616814811364175812
MicrosoftMicrosoft Xp103422446656394089981014387729
MicrosoftWindows Rt 8.129138140159235701
MozillaSeamonkey70367055826714710455686
SUNSolaris3472733423030444363216516476679
MicrosoftIE3919345425593792752627594823617
MozillaFirefox Esr116100579572176616
FedoraprojectFedora6813912494184609
AppleMac OS X Server144272555283831046731603
AdobeAcrobat Reader17456860306641137116580
RedhatEnterprise Linux930752578365262174541
OracleJRE591801158069503
MicrosoftEdge135202161498
OpensuseLeap26586146497
MicrosoftWindows 2000173143423141684230307745497
OracleJDK481801158069492
OracleMysql6566647710185458
SUNSunos458333540272021211743624129442
AppleItunes7811136101104430
PHPPHP131117331142022353522106428
WiresharkWireshark14252325314682299558428
SUNJRE205144545747130403
MicrosoftWindows 2003 Server113558453120387285395
SUNJDK175034545836131380
QualcommSd 625 Firmware235145380