CVE Intelligence
Skip to main content

Month report

January 2017

Rolled up 2026-08-09 20:45 from 370,697 CVE records

1,083 CVEs published, +61.9% on the same month last year. 5 rated critical, 0 listed by CISA as exploited. oracle led with 224; the most common weakness class was CWE-119 (2). intel climbed -16 places, the largest move. 20 vendors ranked for the first time.

Published

1,083

+109.5%on the previous month

Critical / high

5 / 11

of the 20 scored

Medium / low

4 / 0

the rest of the scored bands

Added to CISA KEV

0

listed as exploited this month

Public exploit

69

exploit code indexed publicly

Scanner template

0

0% of the month

Publication to KEV

How long before CISA listed them

3 published this month and listed since — not the 0 listed during it.

Median days to listing

1966

from publication to CISA's date added

Listed within 7 days

0%

of the 3

Listed within 30 days

0%

of the 3

Weakness × vendor

Where the two overlap

CVEs carrying both. Each row is shaded against its own worst class.
VendorCWE-119CWE-120CWE-122CWE-1241CWE-1333CWE-269CWE-330CWE-335
oracle
google
pidgin
hancom
kaspersky
ntp project
ntpsec project
lenovo group

Vendors

Ranked by distinct CVEs this month

Δ is the move against last month's rank.
Vendors ranked by distinct CVEs published in 2017-01, sorted by CVEs descending
#VendorTop products
1oracle2243advanced outbound telephony (38) · marketing (20) · one to one fulfillment (19)new
2google1303android (130)·
3pidgin16pidgin (16)new
4hancom6hancom office (6)new
5kaspersky5internet security (3) · total security (2)new
6ntp project5ntp (5) · ntpsec (5)new
7ntpsec project5ntp (5) · ntpsec (5)new
8lenovo group4edge and slim usb keyboard driver (1) · system x m5 m6 and x6 bios (1) · transition application (1)·
9f5 networks3f5 big ip ltm aam afm analytics apm asm dns link controller pem websafe (2) · f5 big ip ltm aam afm analytics apm asm dns gtm link controller pem (1)new
10lexmark3perceptive document filters (3)new
11memcached32memcached (3)new
12ruby3ruby (3) · tcl tk (1)new
13aerospike21database server (2)new
14trane2comfortlink ii scc firmware (2)new
15bluestacks1app player (1)new
16dlink1dwr 932b firmware (1)·
17foxit software1foxit reader (1)new
18freeimage1freeimage (1)new
19intel1intel ethernet controller x710 family and intel ethernet controller xl710 family (1)↓16
20joyent1smartos (1)↓18
21libbpg1libbpg (1)new
22libtiff1libtiff (1)new
23micro focus international1open enterprise server (1)new
24tcl1ruby (1) · tcl tk (1)new
25vercel1ms (1)new

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2017-01 that are on the CISA KEV catalog today. The 0 in the headline is what CISA listed during the month, whenever those CVEs were published. All 25 ranked vendors are listed; a zero count renders as a dot.

Weaknesses

CWE classes by distinct CVEs

  • 1CWE-11920 critical·
  • 2CWE-12011 critical↑1
  • 3CWE-12210 critical·
  • 4CWE-124110 criticalnew
  • 5CWE-133310 criticalnew
  • 6CWE-26910 critical·
  • 7CWE-33010 critical·
  • 8CWE-33510 criticalnew
  • 9CWE-41610 critical↑1
  • 10CWE-42610 critical·
  • 1CWE-78710 critical·

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.