CVE Intelligence
Skip to main content

Month report

June 2018

Rolled up 2026-08-09 20:45 from 371,001 CVE records

1,783 CVEs published, +72.6% on the same month last year. 10 rated critical, 0 listed by CISA as exploited. hackerone led with 340; the most common weakness class was CWE-22 (132). ca technologies climbed 41 places, the largest move. 9 vendors ranked for the first time.

Published

1,783

+53.4%on the previous month

Critical / high

10 / 41

of the 117 scored

Medium / low

57 / 9

the rest of the scored bands

Added to CISA KEV

0

listed as exploited this month

Public exploit

124

exploit code indexed publicly

Scanner template

0

0% of the month

Publication to KEV

How long before CISA listed them

3 published this month and listed since — not the 0 listed during it.

Median days to listing

1383

from publication to CISA's date added

Listed within 7 days

0%

of the 3

Listed within 30 days

0%

of the 3

Weakness × vendor

Where the two overlap

CVEs carrying both. Each row is shaded against its own worst class.
VendorCWE-22CWE-311CWE-506CWE-20CWE-79CWE-400CWE-200CWE-264
hackerone12710441214202
mozilla
microsoft
qualcomm
ibm
siemens12
ca technologies
f5 networks

Vendors

Ranked by distinct CVEs this month

Δ is the move against last month's rank.
Vendors ranked by distinct CVEs published in 2018-06, sorted by CVEs descending
#VendorTop products
1hackerone3404coffeescript node module (3) · html janitor node module (2) · nodemailer js node module (2)
2mozilla315112firefox (300) · firefox esr (151) · thunderbird (150)·
3microsoft574windows 10 (29) · windows 10 servers (27) · windows server 2016 (23)
4qualcomm32android for msm firefox os for msm qrd android (32)↑17
5ibm23infosphere information server (3) · security access manager (3) · mq (2)↓1
6siemens11scalance m875 (6) · scalance x 200irt switch family incl siplus net variants (3) · scalance x 200rna switch family (3)↑37
7ca technologies103ca privileged access manager (10)↑41
8f5 networks10big ip ltm aam afm analytics apm asm dns edge gateway fps gtm link controller pem webaccelerator (4) · big ip ltm aam afm analytics apm asm dns edge gateway gtm link controller pem webaccelerator websafe (3) · big ip apm (1)↑4
9ics cert102intellivue patient monitors avalon fetal maternal monitors (3) · abb ip gateway (2) · beckhoff twincat (2)↓1
10mcafee1011epolicy orchestrator epo (3) · network security management nsm (3) · common ui cui (1)↑18
11synology10diskstation manager dsm (2) · drive (2) · photo station (2)↑9
12talos10natus (3) · pixar renderman (2) · allen bradley (1)↓7
13apache91apache storm (2) · apache cassandra (1) · apache geode (1)↓4
14cybozu9cybozu office (6) · cybozu mailwise (3)·
15huawei technologies co91288h v5 2288h v5 2488 v5 ch121 v3 ch121l v3 ch121l v5 ch121 v5 ch140 v3 ch140l v3 ch220 v3 ch222 v3 ch242 v3 ch242 v5 rh1288 v3 rh2288 v3 rh2288h v3 xh310 v3 xh321 v3 xh321 v5 xh620 v3 (4) · espace desktop (1) · hg255s 10 (1)↓5
16micro focus922solutions business manager 11 4 (5) · secure messaging gateway (2) · cms server (1)↑2
17basercms users community7basercms (7)·
18the eclipse foundation7eclipse jetty (5) · eclipse mosquitto (2)·
19tibco software71tibco spotfire analytics platform for aws marketplace (3) · tibco administrator enterprise edition (2) · tibco administrator enterprise edition for z linux (2)↑26
20trend micro71trend micro officescan (7)↓14
21suse6open build service (2) · crowbar (1) · kdump (1)·
22opensuse5open build service (4) · obs service set version (1)·
23puppet5puppet agent (2) · pe client tools (1) · puppet enterprise 2018 1 x prior to 2018 1 1 razor server and pe razor server prior to 1 9 0 0 (1)↑18
24cloud foundry4loggregator (2) · cloud foundry uaa (1) · diego (1)↑2
25the node js project4node js (4)↑8
26delta electronics3delta industrial automation dopsoft (3)↑26
27exadel3flamingo amf serializer (3)new
28fortinet3fortinet fortimanager fortianalyzer (2) · fortinet fortimanager (1)↓11
29ge3mds pulsenet and mds pulsenet enterprise (3)·
30nvidia3gpu display driver (3)↓11
31pivotal3spring framework (2) · operations manager (1)↓20
32pixelpost org3pixelpost (3)new
33rsa3authentication manager (1) · rsa authentication manager (1) · web threat detection (1)new
34sap se31sap ui (2) · sap ui for sap netweaver 7 00 (2) · sap business one (1)↓21
35symantec3symantec endpoint protection (2) · norton app lock (1)↓3
36graniteds2framework (2)new
37intel2integrated performance primitives cryptography library (1) · intel core based microprocessors (1)↓22
38libfsntfs project2libfsntfs (2)new
39linux foundation2linux kernel (2)new
40lutron22homeworks qs firmware (1) · radiora 2 firmware (1) · stanza (1)new
41manageengine21applications manager (2)new
42netapp2oncommand unified manager for 7 mode core package (1) · santricity products (1)↓2
43qnap2app center in qts (1) · ldap server in qts (1)·
44tenable2burp suite community edition (1) · libjpeg turbo (1)
45vmware211airwatch agent (1) · nsx sd wan by velocloud (1)↓22
46all nippon airways co1ana app for ios (1)new
47apple11icloud (1) · iphone os (1) · itunes (1)·
48atlassian1fisheye and crucible (1)↓23
49canonical11icloud (1) · iphone os (1) · itunes (1)·
50dell emc1idrac service module (1)↓36

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2018-06 that are on the CISA KEV catalog today. The 0 in the headline is what CISA listed during the month, whenever those CVEs were published. All 50 ranked vendors are listed; a zero count renders as a dot.

Weaknesses

CWE classes by distinct CVEs

  • 1CWE-221320 critical↑6
  • 2CWE-3111040 critical↓1
  • 3CWE-506410 critical↑22
  • 4CWE-20290 critical
  • 5CWE-79260 critical↑1
  • 6CWE-400210 critical↓1
  • 7CWE-20090 critical↑5
  • 8CWE-26470 critical↑26
  • 9CWE-35260 critical↑12
  • 10CWE-39960 critical↑12
  • 1CWE-28750 critical↑3
  • 2CWE-47150 critical·
  • 3CWE-7751 critical↑28
  • 4CWE-8951 critical↓3
  • 5CWE-9450 critical↑13
  • 6CWE-11940 critical↑2
  • 7CWE-12140 critical↓4
  • 8CWE-50240 critical↑6
  • 9CWE-7840 critical↑8
  • 10CWE-79842 critical↑22

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.