CVE Intelligence
Skip to main content

Month report

January 2019

Rolled up 2026-08-09 20:45 from 370,700 CVE records

1,212 CVEs published, -4.8% on the same month last year. 8 rated critical, 0 listed by CISA as exploited. oracle led with 155; the most common weakness class was CWE-416 (76). cisco climbed 33 places, the largest move. 14 vendors ranked for the first time.

Published

1,212

+4.2%on the previous month

Critical / high

8 / 64

of the 173 scored

Medium / low

96 / 5

the rest of the scored bands

Added to CISA KEV

0

listed as exploited this month

Public exploit

86

exploit code indexed publicly

Scanner template

0

0% of the month

Publication to KEV

How long before CISA listed them

6 published this month and listed since — not the 0 listed during it.

Median days to listing

1129

from publication to CISA's date added

Listed within 7 days

0%

of the 6

Listed within 30 days

0%

of the 6

Weakness × vendor

Where the two overlap

CVEs carrying both. Each row is shaded against its own worst class.
VendorCWE-416CWE-79CWE-125CWE-200CWE-119CWE-20CWE-284CWE-77
oracle
google
foxit725
microsoft31
cisco125655
qualcomm
juniper networks
nec

Vendors

Ranked by distinct CVEs this month

Δ is the move against last month's rank.
Vendors ranked by distinct CVEs published in 2019-01, sorted by CVEs descending
#VendorTop products
1oracle1551vm virtualbox (27) · mysql server (25) · outside in technology (24)·
2google846chrome (84)↓1
3foxit80reader (68) · phantompdf (11) · foxit (1)·
4microsoft48111windows 10 (23) · windows 10 servers (23) · windows server 2019 (22)↓1
5cisco45123cisco identity services engine software (6) · cisco sd wan solution (5) · cisco webex wrf player (5)↑33
6qualcomm31snapdragon automobile snapdragon mobile snapdragon wear (14) · snapdragon mobile snapdragon wear (13) · snapdragon automobile snapdragon mobile (2)↓1
7juniper networks264juniper atp (12) · junos os (12) · junos space (2)·
8nec21hc100rc (8) · aterm w300p (5) · aterm wf1200cr and aterm wg1200cr (4)·
9ibm1811security identity manager (5) · api connect (3) · rational publishing engine (2)↓7
10isc183bind 9 (15) · isc dhcp (2) · kea dhcp (1)·
11apache122apache airflow (4) · apache http server (3) · apache thrift (2)↑1
12sap se12sap cloud connector (2) · sap crm webclient ui s4fnd (2) · sap crm webclient ui sapscore (2)·
13cybozu9cybozu remote service (4) · cybozu office (2) · cybozu dezie (1)·
14ics cert8cx supervisor (5) · dr 195 164 ger infinity delta (3)·
15drupal71drupal core (6) · 3rd party module search autocomplete (1)·
16intel7intel r optane tm ssd dc p4800x (2) · intel r nuc (1) · intel r proset wireless wifi software (1)↓2
17jenkins project53jenkins (2) · pipeline declarative plugin (1) · pipeline groovy plugin (1)·
18micronet5inplc rt (4) · installer of inplc sdk express 3 08 and earlier and installer of inplc sdk pro 3 08 and earlier (1)new
19ricoh company5ricoh interactive whiteboard (5)new
20the systemd project5systemd (5)new
21toshiba lighting technology5toshiba home gateway hem gw16a and toshiba home gateway hem gw26a (5)·
22adobe4adobe experience manager (2) · adobe acrobat and reader (1) · adobe experience manager forms (1)·
23jpcert coordination center41logontracer (4)new
24linux4kernel (4)·
25mcafee4total protection mtp (2) · mcafee web gateway (1) · mvision endpoint (1)↓15
26panasonic4bn sdwbp3 (3) · some pre installed applications on panasonic pc (1)new
27brocade communications systems31brocade network advisor (3)↑1
28dell3dell networking os10 (1) · rsa archer (1) · rsa authentication manager (1)↑11
29facebook3hhvm (2) · wangle (1)↓23
30imperva3securesphere (3)new
31nippon telegraph and telephone west3biz box router n58i and n500 (2) · biz box router n58i n500 nvr500 and rtx810 (2) · yamaha broadband voip router nvr500 (2)·
32spring3spring batch (1) · spring integration (1) · spring web services (1)new
33tenable3labkey server community edition (3)·
34thimpress3learnpress (3)new
35tibco software3tibco spotfire analytics platform for aws marketplace (3) · tibco spotfire server (2) · tibco spotfire server versions (1)↑19
36abb2cms 770 (1) · m2m ethernet (1)·
37ca technologies2ca service desk manager (2)·
38digital arts2i filter (2)·
39netapp2clustered data ontap (1) · oncommand unified manager for 7 mode core package (1)↑6
40nippon telegraph and telephone east2biz box router n58i and n500 (2) · biz box router n58i n500 nvr500 and rtx810 (2) · yamaha broadband voip router nvr500 (2)·
41palo alto networks2palo alto networks pan os (2)↑6
42power dns2pdns recursor (2)new
43seiko epson2seiko epson printers and scanners (2)new
44symantec2norton app lock (1) · symantec reporter (1)↑9
45weseek2growi (2)·
46yamaha2biz box router n58i and n500 (2) · biz box router n58i n500 nvr500 and rtx810 (2) · yamaha broadband voip router nvr500 (2)new
47yokogawa electric2multiple yokogawa products that contain vnet ip open communication driver (1) · the license management function of yokogawa products (1)new
483s smart13s smart software solutions gmbh codesys control v3 products prior to version 3 5 14 0 (1)new
49apple11iphone os (1) · macos (1)·
50arne brachhold1google xml sitemaps (1)new

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2019-01 that are on the CISA KEV catalog today. The 0 in the headline is what CISA listed during the month, whenever those CVEs were published. All 50 ranked vendors are listed; a zero count renders as a dot.

Weaknesses

CWE classes by distinct CVEs

  • 1CWE-416760 critical↑13
  • 2CWE-79200 critical↓1
  • 3CWE-125110 critical↑4
  • 4CWE-200100 critical↑4
  • 5CWE-11971 critical↑20
  • 6CWE-2070 critical↓4
  • 7CWE-28470 critical↑11
  • 8CWE-7760 critical·
  • 9CWE-79853 critical↑42
  • 10CWE-28740 critical↑1
  • 1CWE-53240 critical·
  • 2CWE-40030 critical↓8
  • 3CWE-61130 critical↑33
  • 4CWE-77030 critical·
  • 5CWE-84330 critical·
  • 6CWE-9430 critical·
  • 7CWE-12220 critical↓2
  • 8CWE-25020 critical·
  • 9CWE-26420 critical↓2
  • 10CWE-26920 critical·

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.