CVE Intelligence
Skip to main content

Month report

July 2018

Rolled up 2026-08-09 20:45 from 370,662 CVE records

2,167 CVEs published, +70.9% on the same month last year. 14 rated critical, 0 listed by CISA as exploited. oracle led with 204; the most common weakness class was CWE-843 (46). redhat climbed 58 places, the largest move. 19 vendors ranked for the first time.

Published

2,167

+21.5%on the previous month

Critical / high

14 / 73

of the 287 scored

Medium / low

179 / 21

the rest of the scored bands

Added to CISA KEV

0

listed as exploited this month

Public exploit

93

exploit code indexed publicly

Scanner template

0

0% of the month

Publication to KEV

How long before CISA listed them

5 published this month and listed since — not the 0 listed during it.

Median days to listing

1414

from publication to CISA's date added

Listed within 7 days

0%

of the 5

Listed within 30 days

0%

of the 5

Weakness × vendor

Where the two overlap

CVEs carrying both. Each row is shaded against its own worst class.
VendorCWE-843CWE-416CWE-20CWE-79CWE-787CWE-22CWE-306CWE-200
oracle
foxit45271
ibm
qualcomm
microsoft1
redhat105
schneider electric se
apache

Vendors

Ranked by distinct CVEs this month

Δ is the move against last month's rank.
Vendors ranked by distinct CVEs published in 2018-07, sorted by CVEs descending
#VendorTop products
1oracle2043mysql server (24) · outside in technology (14) · sun zfs storage appliance kit ak software (11)·
2foxit82foxit reader (80) · foxit activex pro sdk (1) · foxit phantompdf (1)·
3ibm823rational quality manager (47) · rational collaborative lifecycle management (34) · rational rhapsody design manager (10)↑2
4qualcomm591android for msm firefox os for msm qrd android (43) · snapdragon automobile snapdragon mobile snapdragon wear (9) · snapdragon mobile snapdragon wear (5)
5microsoft5516microsoft edge (19) · chakracore (12) · windows 10 (9)↓2
6redhat38ceph (4) · ansible (3) · cloudforms (3)↑58
7schneider electric se241u motion (14) · u motion builder (4) · pelco sarix professional v1 (3)·
8apache203apache kafka (2) · apache spark (2) · apache tomcat native (2)↑5
9f5 networks16big ip ltm aam afm analytics apm asm dns edge gateway fps gtm link controller pem webaccelerator (6) · big ip apm (2) · big ip asm (2)↓1
10intel161intel active management technology (3) · intel processor diagnostic tool (2) · intel converged security management engine intel csme (1)↑27
11juniper networks143junos os (11) · contrail service orchestration (3)·
12huawei technologies co11emily al00a (2) · dp300 ips module ngfw module rp200 secospace usg6300 secospace usg6500 secospace usg6600 te30 te40 te50 te60 (1) · dp300 rp200 te30 te40 te50 te60 (1)↑3
13sap11sap internet graphics server igs (3) · sap businessobjects business intelligence suite (2) · sap businessobjects business intelligence bi launchpad and central management console (1)·
14siemens101siclock tc100 siclock tc400 (6) · firmware variant dnp3 tcp for en100 ethernet module (2) · firmware variant iec104 for en100 ethernet module (2)↓8
15atlassian9jira (3) · atlassian http (1) · confluence (1)↑33
16qemu81qemu (7) · display (1)·
17dell emc71idrac7 (2) · idrac8 (2) · idrac9 (2)↑33
18ieee7standard (7)new
19lenovo group7lenovo xclarity administrator (3) · lenovo help android application (1) · lenovo smart assistant (1)·
20acd systems6canvas draw (6)new
21antenna house6antenna house (6)·
22vmware6vmware esxi workstation and fusion (3) · esxi (1) · fusion (1)↑23
23itrack5easy (5)new
24linux5kernel (4) · util linux (1)·
25mcafee5mcafee web gateway mwg (2) · data loss prevention dlp for windows (1) · drive encryption mde (1)↓15
26netpbm5netpbm (5)new
27php formmail5generator (5)new
28qnap55q center virtual appliance (5)↑15
29synology5carddav server (1) · diskstation manager dsm (1) · nas server ds107 (1)↓18
30the curl project5curl (5)new
31echelon44i lon 100 (4) · i lon 600 (4) · smartserver 1 (4)new
32hughes satellite modem4dw7000 (4) · hn7000s sm (4) · hn7740s (4)new
33medtronic424950 mycarelink monitor (2) · 24952 mycarelink monitor (2) · 2090 carelink programmer (1)·
34nextcloud4nextcloud server (2) · nextcloud calendar application (1) · nextcloud contacts application (1)·
35trackr4bravo mobile application (4)new
36zte4zxcdn sns (1) · zxiptv epg (1) · zxiptv ucm (1)·
37doccms3administration panel (3)new
38jenkins project3active directory jenkins plugin (1) · distfork jenkins plugin (1) · pipeline classpath step jenkins plugin (1)new
39manageengine3applications manager (3)↑2
40martem3telem gw6 (2) · telem gwm (2) · telem gw6 gwm (1)new
41navarino3infinity (3)new
42pivotal3pivotal operations manager (2) · pivotal application service (1)↓11
43rsa31rsa identity governance and lifecycle (2) · certificate manager path traversal vulnerability (1)↓10
44samba3samba (3)·
45schweitzer engineering laboratories31acselerator architect (2) · compass (1)new
46xorg3libice (1) · libxdmcp (1) · xorg x11 server (1)new
47zizai technology3tech nut mobile application (2) · tech nut (1)new
48accellion2ftp server (2)new
49asus2rp ac52 access point (2)new
50aveva software2indusoft web studio (1) · intouch (1) · intouch machine edition (1)new

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2018-07 that are on the CISA KEV catalog today. The 0 in the headline is what CISA listed during the month, whenever those CVEs were published. All 50 ranked vendors are listed; a zero count renders as a dot.

Weaknesses

CWE classes by distinct CVEs

  • 1CWE-843460 critical·
  • 2CWE-416300 critical↑55
  • 3CWE-20270 critical↑1
  • 4CWE-79220 critical↑1
  • 5CWE-787170 critical·
  • 6CWE-22161 critical↓5
  • 7CWE-306151 critical↑41
  • 8CWE-200111 critical↓1
  • 9CWE-121100 critical↑8
  • 10CWE-28490 critical↑14
  • 1CWE-29590 critical↑21
  • 2CWE-7790 critical↑1
  • 3CWE-12280 critical↑9
  • 4CWE-12580 critical↑9
  • 5CWE-28580 critical↑30
  • 6CWE-31070 critical·
  • 7CWE-40070 critical↓11
  • 8CWE-79871 critical↑2
  • 9CWE-35261 critical↓10
  • 10CWE-69360 critical↑48

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.