CVE Intelligence
Skip to main content

Month report

October 2017

Rolled up 2026-08-09 20:45 from 370,700 CVE records

1,398 CVEs published, +103.5% on the same month last year. 5 rated critical, 0 listed by CISA as exploited. oracle led with 179; the most common weakness class was CWE-119 (10). f5 networks climbed 29 places, the largest move. 14 vendors ranked for the first time.

Published

1,398

+13.8%on the previous month

Critical / high

5 / 31

of the 51 scored

Medium / low

15 / 0

the rest of the scored bands

Added to CISA KEV

0

listed as exploited this month

Public exploit

173

exploit code indexed publicly

Scanner template

0

0% of the month

Publication to KEV

How long before CISA listed them

8 published this month and listed since — not the 0 listed during it.

Median days to listing

1598

from publication to CISA's date added

Listed within 7 days

0%

of the 8

Listed within 30 days

0%

of the 8

Weakness × vendor

Where the two overlap

CVEs carrying both. Each row is shaded against its own worst class.
VendorCWE-119CWE-79CWE-323CWE-20CWE-200CWE-416CWE-121CWE-287
oracle
microsoft2
ibm
juniper networks
google
apache
f5 networks
foxit5

Vendors

Ranked by distinct CVEs this month

Δ is the move against last month's rank.
Vendors ranked by distinct CVEs published in 2017-10, sorted by CVEs descending
#VendorTop products
1oracle17916java (20) · mysql server (18) · peoplesoft enterprise pt peopletools (14)·
2microsoft61210chakracore microsoft edge (12) · internet explorer (5) · windows kernel (5)↓1
3ibm28rational engineering lifecycle manager (7) · daeja viewone (4) · rational collaborative lifecycle management (3)
4juniper networks2531junos os (18) · junos space (4) · contrail (2)·
5google222android (22)↓3
6apache1813apache nifi (4) · apache portable runtime (2) · apache wicket (2)↓2
7f5 networks11big ip ltm aam afm analytics apm asm dns gtm link controller pem websafe (2) · big ip aam pem (1) · big ip ltm aam afm analytics apm asm dns edge gateway gtm link controller pem webaccelerator (1)↑29
8foxit9foxit reader (9)new
9wi fi alliance9wi fi protected access wpa and wpa2 (9)new
10trend micro76trend micro officescan (7)↑1
11redhat6122keycloak (3) · centos (1) · enterprise linux (1)↓1
12gemalto5gemalto s hasp srm sentinel hasp and sentinel ldk products prior to sentinel ldk rte (5)new
13lenovo group5service framework application (4) · e95 thinkcentre m710s m710t (1)↑12
14talos5computerinsel photoline (3) · simple direct media (2)new
15intel41nuc kits (4)↑27
16micro focus4hp arcsight esm (3) · hp arcsight esm express (3) · hpe operations orchestration (1)↑1
17atlassian3atlassian fisheye and crucible (2) · bamboo (1)·
18hitachi solutions3hibun confidential file decryption program (2) · installer of hibun confidential file viewer (1)new
19mcafee3network data loss prevention (3)↑8
20blackberry2workspaces server (2)·
21brocade communications systems2zone director controller and unleashed ap firmware (1) · zone director controller firmware (1)·
22fortinet2fortinet fortios (2)↓13
23gnu21wget (2)new
24n a2idm 4 5 bidirectional edir driver version (2)new
25nvidia2geforce experience (1) · jetson (1)↓19
26symantec2symantec encryption desktop (1) · symantec endpoint encryption (1)↓8
27akeo consulting1rufus (1)new
28bitdefender1bitdefender internet security (1)new
29centos111centos (1) · enterprise linux (1) · linux kernel (1)new
30cybozu1cybozu office (1)·
31dell emc1data protection advisor (1) · dell emc data protection advisor (1)·
32emc1data protection advisor (1) · dell emc data protection advisor (1)new
33hackerone1rubygems (1)↑7
34joyent1joyent smart data center (1)·
35koji project1koji (1)new
36linux111centos (1) · enterprise linux (1) · linux kernel (1)new
37qnap11qnap helpdesk app (1)↑18
38reallyl io1jwt scala (1)new
39siemens1cadra (1)·
40synology1synology audio station (1)↓21
41tibco software1tibco managed file transfer command center (1) · tibco managed file transfer internet server (1)·
42zte1zxdt22 sf01 (1)↓21

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2017-10 that are on the CISA KEV catalog today. The 0 in the headline is what CISA listed during the month, whenever those CVEs were published. All 42 ranked vendors are listed; a zero count renders as a dot.

Weaknesses

CWE classes by distinct CVEs

  • 1CWE-119101 critical↑9
  • 2CWE-7990 critical↑2
  • 3CWE-32380 critical·
  • 4CWE-2060 critical↓2
  • 5CWE-20050 critical↑2
  • 6CWE-41650 critical·
  • 7CWE-12140 critical·
  • 8CWE-28740 critical↓3
  • 9CWE-39940 critical↓6
  • 10CWE-12530 critical↓9
  • 1CWE-26430 critical↓5
  • 2CWE-42830 critical·
  • 3CWE-19020 critical↑2
  • 4CWE-2220 critical↑2
  • 5CWE-30620 critical↑5
  • 6CWE-35220 critical↑9
  • 7CWE-50221 critical↑13
  • 8CWE-61320 critical·
  • 9CWE-7820 critical↓11
  • 10CWE-84320 critical·

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.