CVE Intelligence
Skip to main content

Month report

January 2018

Rolled up 2026-08-09 20:45 from 381,136 CVE records

1,273 CVEs published, +17.5% on the same month last year. 5 rated critical, 0 listed by CISA as exploited. oracle led with 167; the most common weakness class was CWE-22 (18). redhat climbed 44 places, the largest move. 12 vendors ranked for the first time.

Published

1,273

+15.2%on the previous month

Critical / high

5 / 16

of the 43 scored

Medium / low

21 / 1

the rest of the scored bands

Added to CISA KEV

0

listed as exploited this month

Public exploit

163

exploit code indexed publicly

Scanner template

0

0% of the month

Publication to KEV

How long before CISA listed them

4 published this month and listed since — not the 0 listed during it.

Median days to listing

1430.5

from publication to CISA's date added

Listed within 7 days

0%

of the 4

Listed within 30 days

0%

of the 4

Weakness × vendor

Where the two overlap

CVEs carrying both. Each row is shaded against its own worst class.
VendorCWE-22CWE-391CWE-20CWE-200CWE-78CWE-79CWE-264CWE-287
oracle
microsoft
google
ibm
netgain systems1513
qualcomm
apache
talos

Vendors

Ranked by distinct CVEs this month

Δ is the move against last month's rank.
Vendors ranked by distinct CVEs published in 2018-01, sorted by CVEs descending
#VendorTop products
1oracle1673mysql server (19) · java (18) · vm virtualbox (9)·
2microsoft60219microsoft edge (16) · equation editor (12) · windows kernel (6)↑3
3google513android (51)↑1
4ibm461security key lifecycle manager (10) · rational doors (7) · security access manager (4)↓3
5netgain systems23netgain systems enterprise manager (23)new
6qualcomm20android for msm firefox os for msm qrd android (20)↓3
7apache17apache geode (3) · apache nifi (3) · apache hadoop (2)↑4
8talos13cpp ethereum (9) · delayed job web rails gem (1) · parity (1)·
9juniper networks121junos os (8) · junos space (3) · screenos (1)·
10the x org foundation11xorg x11 server (11)new
11atlassian10jira (5) · activity streams (1) · atlassian jira (1)↑4
12redhat101389 ds base (1) · hibernate validator (1) · libpam4j (1)↑44
13hp91hp jetadvantage security manager (2) · hp designjet printers hp latex printers (1) · hp enterprise laserjet printers and mfps hp officejet enterprise color printers and mfp hp pagewide color printers and mps (1)·
14vmware7fusion (3) · workstation (2) · workstation pro player (2)—
15intel63most modern operating systems (2) · intel driver and support assistant (1) · intel graphics driver (1)↑26
16trend micro65trend micro smart protection server standalone (5) · trend micro mobile security enterprise (1)↑1
17powerdns5powerdns recursor (3) · powerdns (1) · powerdns authoritative (1)new
18flexera software4linux kernel (4)·
19sap se4sap hana (1) · sap netweaver (1) · sap solution manager (1)new
20siemens41telecontrol server basic (3) · desigo pxc001 e d v4 10 (1) · desigo pxc001 e d v5 00 (1)↑11
21lenovo group3enterprise network operating system affecting lenovo and ibm rackswitch and bladecenter products (1) · integrated management module 2 imm2 (1) · lenovo fingerprint manager pro (1)·
22schneider electric se3pelco videoxpert enterprise (3)·
23symantec3proxysg (2) · asg (1) · reporter (1)↑3
24yandex n v3yandex browser (1) · yandex browser for android (1) · yandex browser for desktop (1)·
25jdennis2keycloak httpd client install (2)new
26malwarebytes2malwarebytes (2)new
27micro focus2netiq access manager (1) · netiq access manager administrative console (1)↓4
28f5 networks1big ip afm (1)↓21
29fortinet1fortios (1)↓7
30freeipa1ipa (1)·
31hancom1hancom office hword neo (1)·
32japan total system co1groupsession (1)·
33miek gieben1miekg dns (1)new
34nippon telegraph and telephone east1flet s virus clear easy setup application tool (1) · flet s virus clear v6 easy setup application tool (1)↑15
35nlnet labs1unbound (1)new
36pivotal11pivotal spring data rest and spring boot (1)·
37qemu1qemu (1)·
38schezo1lhaplus (1)new
39seelook1nootka (1)new
40simon kelley1dnsmasq (1)new
41the dovecot project1dovecot (1)new

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2018-01 that are on the CISA KEV catalog today. The 0 in the headline is what CISA listed during the month, whenever those CVEs were published. All 41 ranked vendors are listed; a zero count renders as a dot.

Weaknesses

CWE classes by distinct CVEs

  • 1CWE-22180 critical↑7
  • 2CWE-391120 critical·
  • 3CWE-20100 critical↑3
  • 4CWE-20090 critical↑3
  • 5CWE-7870 critical↑5
  • 6CWE-7960 critical↓2
  • 7CWE-26440 critical·
  • 8CWE-28740 critical↑15
  • 9CWE-40040 critical↑18
  • 10CWE-11930 critical↓5
  • 1CWE-50232 critical·
  • 2CWE-86330 critical·
  • 3CWE-8930 critical↑25
  • 4CWE-12120 critical↓3
  • 5CWE-20320 critical↓2
  • 6CWE-28420 critical↓7
  • 7CWE-28520 critical·
  • 8CWE-34720 critical·
  • 9CWE-35820 critical·
  • 10CWE-36220 critical·

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.