CVE Intelligence
Skip to main content

Month report

November 2018

Rolled up 2026-08-09 20:45 from 370,745 CVE records

983 CVEs published, -7.8% on the same month last year. 16 rated critical, 0 listed by CISA as exploited. google led with 95; the most common weakness class was CWE-400 (14). tibco software climbed 59 places, the largest move. 18 vendors ranked for the first time.

Published

983

-33%on the previous month

Critical / high

16 / 46

of the 133 scored

Medium / low

68 / 3

the rest of the scored bands

Added to CISA KEV

0

listed as exploited this month

Public exploit

93

exploit code indexed publicly

Scanner template

0

0% of the month

Publication to KEV

How long before CISA listed them

6 published this month and listed since — not the 0 listed during it.

Median days to listing

1302

from publication to CISA's date added

Listed within 7 days

0%

of the 6

Listed within 30 days

0%

of the 6

Weakness × vendor

Where the two overlap

CVEs carrying both. Each row is shaded against its own worst class.
VendorCWE-400CWE-79CWE-20CWE-200CWE-89CWE-120CWE-121CWE-22
google
microsoft1
ibm
cisco22312
lenovo
qualcomm
sap
huawei technologies co

Vendors

Ranked by distinct CVEs this month

Δ is the move against last month's rank.
Vendors ranked by distinct CVEs published in 2018-11, sorted by CVEs descending
#VendorTop products
1google9527android (57) · chrome (38)↑7
2microsoft5924windows 10 (19) · windows 10 servers (17) · windows server 2016 (17)↑4
3ibm41db2 for linux unix and windows (7) · robotic process automation with automation anywhere (4) · websphere application server (4)↑2
4cisco1842cisco amp for endpoints (2) · cisco energy management suite (2) · cisco adaptive security appliance asa software (1)↓2
5lenovo16thinksystem smm (9) · lxci for vmware (3) · chassis management module cmm (2)new
6qualcomm14snapdragon automobile snapdragon mobile snapdragon wear (8) · snapdragon automobile snapdragon mobile (4) · snapdragon mobile (2)↓2
7sap14sap fiori client (5) · knowledge management xmlforms in sap netweaver (1) · sap aba (1)↑9
8huawei technologies co10espace 7950 (3) · emily al00a (2) · alp al00b alp tl00b bla al00b bla l09c bla l29c (1)↑13
9schneider electric se9embedded web servers in all modicon m340 premium quantum plcs and bmxnor0200 (5) · data center expert versions 7 5 0 and earlier (1) · data center operation all versions (1)·
10apache8apache hadoop (2) · apache hive (2) · apache syncope (2)↑3
11brocade communications systems8brocade fabric os (8)·
12neojapan8denbun by neojapan inc denbun pop version v3 3p r4 0 and earlier denbun imap version v3 3i r4 0 and earlier (6) · denbun by neojapan inc denbun pop version v3 3p r3 0 and earlier denbun imap version v3 3i r3 0 and earlier (1) · denbun pop version v3 3p r4 0 and earlier (1)new
13zte822zxhn f670 (5) · zxhn h168n (2) · zxr10 8905e (1)·
14dell emc7integrated data protection appliance (5) · avamar (4) · dell emc recoverpoint (2)↑6
15intel7intel driver support assistant (1) · intel media server studio (1) · intel parallel studio xe 2018 (1)
16nagios72nagios xi (7)new
17tibco software7tibco activespaces community edition (1) · tibco activespaces developer edition (1) · tibco activespaces enterprise edition (1)↑59
18check point software technologies6freerdp (6)·
19qnap5qnap qts (4) · qsync central (1)·
20the node js project5node js (5)·
21npm4cached path relative (1) · knightjs (1) · takeapeek (1)·
22nvidia4geforce experience (3) · gpu graphics driver (1)↑31
23omron4cx supervisor (4)·
24redhat4keycloak (3) · ansible (1)·
25symantec4norton symantec endpoint protection sep symantec endpoint protection small business edition sep sbe symantec endpoint protection cloud sep cloud (2) · symantec endpoint protection sep (1) · symantec security analytics sa (1)↑48
26yi42yi technology (4)new
27adobe3adobe acrobat and reader (1) · adobe photoshop cc (1) · flash player (1)↓24
28life sciences computing3opendolphin (3)new
29atlassian2sourcetree for macos (1) · sourcetree for windows (1)↓3
30cloud foundry21bits service release (1) · uaa (1) · uaa release (1)↓2
31dell22openmanage network manager (2)↑32
32hiroshi yuki2yukiwiki (2)new
33micro focus21micro focus service manager (1) · operation bridge containerized suite (1)↑19
34pivotal cloud foundry21credhub service broker (1) · pivotal operations manager (1)new
35qnap systems2qts (2)new
36rack2rack (2)new
37soliton systems k k2filezen (2)new
38the powerdns project2pdns (2) · pdns recursor (2)new
39vmware2vmware vrealize log insight (1) · vmware workstation and fusion (1)↑6
40access manager1access manager (1)new
41baidu1baidu browser (1)new
42bluestacks1bluestacks app player (1)·
43cybersecurity philippines cert1umbracocms (1)new
44cybozu1cybozu garoon (1)·
45feitian japan co1securecore standard edition (1)new
46fineuploader1fineuploader php traditional server (1)new
47fortinet1fortinet fortios (1)·
48freebsd1freebsd (1)·
49fxc1multiple fxc inc network devices managed ethernet switch fxc5210 5218 5224 firmware prior to version ver1 00 22 managed ethernet switch fxc5426f firmware prior to version ver1 00 06 managed ethernet switch fxc5428 firmware prior to version ver1 00 07 power over ethernet poe switch fxc5210pe 5218pe 5224pe firmware prior to version ver1 00 14 and wireless lan router ae1021 ae1021pe firmware all versions (1)new
50hayageek11jquery upload file (1)new

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2018-11 that are on the CISA KEV catalog today. The 0 in the headline is what CISA listed during the month, whenever those CVEs were published. All 50 ranked vendors are listed; a zero count renders as a dot.

Weaknesses

CWE classes by distinct CVEs

  • 1CWE-400140 critical↑4
  • 2CWE-7970 critical
  • 3CWE-2050 critical↓2
  • 4CWE-20050 critical↑7
  • 5CWE-8941 critical↑29
  • 6CWE-12030 critical↑14
  • 7CWE-12130 critical↑1
  • 8CWE-2230 critical↑4
  • 9CWE-28431 critical↓5
  • 10CWE-47630 critical↑19
  • 1CWE-11520 critical·
  • 2CWE-11920 critical↑23
  • 3CWE-12220 critical↑4
  • 4CWE-19020 critical↑7
  • 5CWE-35220 critical↓5
  • 6CWE-41620 critical↓10
  • 7CWE-61120 critical↓2
  • 8CWE-68020 criticalnew
  • 9CWE-78720 critical↓3
  • 10CWE-12610 critical↑16

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.