CVE Intelligence
Skip to main content

Month report

July 2017

Rolled up 2026-08-09 20:45 from 370,778 CVE records

1,268 CVEs published, +78.8% on the same month last year. 8 rated critical, 0 listed by CISA as exploited. ibm led with 78; the most common weakness class was CWE-119 (12). mcafee climbed 48 places, the largest move. 22 vendors ranked for the first time.

Published

1,268

+22.7%on the previous month

Critical / high

8 / 27

of the 39 scored

Medium / low

4 / 0

the rest of the scored bands

Added to CISA KEV

0

listed as exploited this month

Public exploit

83

exploit code indexed publicly

Scanner template

0

0% of the month

Publication to KEV

How long before CISA listed them

13 published this month and listed since — not the 0 listed during it.

Median days to listing

1690

from publication to CISA's date added

Listed within 7 days

0%

of the 13

Listed within 30 days

0%

of the 13

Weakness × vendor

Where the two overlap

CVEs carrying both. Each row is shaded against its own worst class.
VendorCWE-119CWE-287CWE-78CWE-190CWE-200CWE-121CWE-184CWE-20
ibm
microsoft
google
apache1
juniper networks
nvidia
cisco8
intellishield7

Vendors

Ranked by distinct CVEs this month

Δ is the move against last month's rank.
Vendors ranked by distinct CVEs published in 2017-07, sorted by CVEs descending
#VendorTop products
1ibm781security guardium (8) · infosphere master data management (7) · jazz reporting service (7)↑2
2microsoft5715windows 10 gold 1511 1607 and 1703 and windows server 2016 (8) · microsoft windows server 2008 sp2 and r2 sp1 windows 7 sp1 windows 8 1 windows server 2012 gold and r2 windows rt 8 1 windows 10 gold 1511 1607 and 1703 and windows server 2016 (7) · microsoft windows 7 sp1 windows server 2008 sp2 and r2 sp1 windows 8 1 and windows rt 8 1 windows server 2012 and r2 windows 10 gold 1511 1607 1703 and windows server 2016 (5)↓1
3google46android (46)↑3
4apache26114apache openmeetings (11) · apache http server (6) · apache struts (3)↑4
5juniper networks205junos os (15) · screenos (5)·
6nvidia11nvidia windows gpu display driver (6) · android (3) · nvidia gpu display driver (2)·
7cisco872ios (6) · universal product (6) · cisco ios xe software (3)·
8intellishield762universal product (7) · ios (4) · cisco ios xe software (2)new
9tomoki fuke6encrypted files in self decryption format created by filecapsule deluxe portable (3) · filecapsule deluxe portable (3)new
10mcafee5advanced threat defense atd (5)↑48
11toshiba lighting technology5toshiba home gateway hem gw16a (5) · toshiba home gateway hem gw26a (5)new
12chitora soft4installer of lhaz (2) · self extracting archive files created by lhaz (2)new
13cybozu4cybozu garoon (3) · cybozu kunai for android (1)↓3
14kddi4home spot cube2 (4)new
15buffalo3wmr 433 (2) · wmr 433w (2) · wapm 1166d (1)↓4
16poppler3poppler (3)·
17redhat3cygwin (1) · rkhunter (1) · rubygem safemode (1)↑11
18sony3wg c10 (3)↑46
19biscom2secure file transfer (2)↑16
20hammock2assetview for macos (2)new
21hibara software2self extracting encrypted files created by attachecase (2)·
22information technology promotion agency japan ipa2installer of casl ii simulator self extract format (1) · source code security studying tool icodechecker (1)↓6
23inmarsat2amosconnect (2)new
24lenovo group2lenovo connect2 (1) · lenovo notebook bios (1)↓15
25national institute for land and infrastructure management2douro kouji kanseizutou check program (1) · douroshisetu kihon data sakusei system (1)new
26national tax agency2installer of setup file of advance preparation jizen setup exe (1) · setup file of advance preparation for e tax software web version (1)·
27puppet2puppet enterprise (1) · puppet server (1)↓1
28the ministry of justice2installer of pdf digital signature plugin (1) · installer of shinseiyo sogo soft (1)new
29vmware2vmware tools (1) · vmware vcenter server (1)↓25
30w3 eden2wordpress download manager (2)new
31acquisition technology logistics agency1installer of electronic tendering and bid opening system (1)↑1
32android1android (1)new
33apple1installer of quicktime for windows (1)·
34brother industries1mfc j960dwn (1)new
35chad butler1wp members (1)new
36charamin steering committee1the installer of charamin omp (1)new
37dfactory1responsive lightbox (1)new
38dotnetnuke111dotnetnuke cms fixed in 9 1 1 (1)new
39elastic1elasticsearch x pack security (1)↓32
40fortinet1fortinet fortiwlm (1)↑2
41i o data device1ts ptcam (1) · ts ptcam poe (1) · ts wlc2 (1)↓29
42iceni1infix (1)·
43intel16th and 7th generation intel core processor families intel xeon e3 1500m v5 and v6 processor families and intel xeon e3 1200 v5 and v6 product families (1)↑4
44ministry of agreculture foresty and fishery1installer of denshinouhin check system for ministry of agriculture forestry and fisheries nouson seibi jigyou 2014 march edition (1)new
45ministry of education culture sports science and technology mext1ebidsettingchecker exe (1)new
46ministry of land infrastructure transport and tourism japan1the installer of mlit denshiseikabutsusakuseishienkensa system (1) · the self extracting archive including the installer of mlit denshiseikabutsusakuseishienkensa system (1)new
47nancyfx1nancyfx framework up to 2 0 0 (1)new
48nginx11nginx (1)new
49sourcenext1self extracting archive files created by file compact (1)·
50the spice project1spice (1)new

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2017-07 that are on the CISA KEV catalog today. The 0 in the headline is what CISA listed during the month, whenever those CVEs were published. All 50 ranked vendors are listed; a zero count renders as a dot.

Weaknesses

CWE classes by distinct CVEs

  • 1CWE-119120 critical↑20
  • 2CWE-28730 critical↑11
  • 3CWE-7830 critical·
  • 4CWE-19020 critical·
  • 5CWE-20020 critical↓1
  • 6CWE-12110 critical↑16
  • 7CWE-18410 criticalnew
  • 8CWE-2011 critical↓5
  • 9CWE-26410 critical↑1
  • 10CWE-30010 critical·
  • 1CWE-39210 criticalnew
  • 2CWE-40010 critical↓5
  • 3CWE-40210 criticalnew
  • 4CWE-47610 critical↑23
  • 5CWE-52211 critical↓13
  • 6CWE-78710 critical·
  • 7CWE-7910 critical↓16
  • 8CWE-79810 critical·
  • 9CWE-82310 criticalnew
  • 10CWE-8910 critical

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.