month report
January 2018
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
January 2018 closed with 1,715 published CVEs. 170 criticals, oracle led volume, mostly via mysql. Biggest breakout: hp at ×25.0 their 12-month median. Top weakness class — CWE-79 (189 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
1,715
— MoM— YoY
Severity mix
170 / 574
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
5.0%
86 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
2975.3
n=86
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
1431
n=4
Detection gap
KEV pressure, no Nuclei coverage
January 2018 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 2microsoft60 CVE
- KEV 2microsoft corporation60 CVE
- KEV 2microsoft corp35 CVE
Weakness × Vendor
What's spreading where in January 2018
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS20Improper Input Validation200Information Exposure119Memory Buffer Bounds787Out-of-bounds Write22Path Traversal89SQL Injection352CSRF287Improper Authentication78OS Command Injectionoracle111oracle corporation11debian2151106212google719146maven111192413canonical21113microsoft12181microsoft corporation12181ibm16462131redhat131122google inc.51346сообщество свободного программного обеспечения324311
Breakout vendors
CVE count ≥3× their own 12-period median.
- 25.0×hp25 CVE
- 8.0×asus8 CVE
- 7.0×jenkins35 CVE
- 6.3×ао «нтц ит роса»19 CVE
- 6.0×rubygems21 CVE
- 5.4×maven70 CVE
- 5.0×canonical65 CVE
- 5.0×red hat, inc.10 CVE
- 5.0×cmsmadesimple5 CVE
- 4.0×novell inc.14 CVE
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #19k7computing25 CVE
- #22netgain systems23 CVE
- #23netgain-systems23 CVE
- #39talos13 CVE
- #43the x.org foundation11 CVE
- #45malwarebytes10 CVE
- #46red hat, inc.10 CVE
- #47responsive coming soon page project10 CVE
- #49ethereum9 CVE
- #52asus8 CVE
Top vendors
Ranked by distinct CVE count this period.
- 177 CVE8 critCVSS 6.5KEV 1Nuclei 1PoC 7mysql (20) · jdk (20) · jre (20)
- 167 CVE7 critCVSS 6.7PoC 3mysql server (19) · java (18) · vm virtualbox (9)
- 115 CVE26 critCVSS 7.4PoC 21debian linux (115)
- 76 CVE11 critCVSS 7.8PoC 3android (74) · chrome (2)
- 70 CVE8 critCVSS 7.1×5.4KEV 2Nuclei 3PoC 7org.jenkins-ci.main:jenkins-core (16) · org.webjars.npm:jquery (3) · org.apache.geode:geode-core (3)
- 65 CVE3 critCVSS 6.5×5.0PoC 11ubuntu linux (65)
- 60 CVECVSS 7.3KEV 2PoC 18office (20) · edge (18) · chakracore (17)
- 60 CVECVSS 7.3KEV 2PoC 18microsoft edge (16) · equation editor (12) · windows kernel (6)
- 59 CVE3 critCVSS 6.3Nuclei 1PoC 1security key lifecycle manager (10) · engineering requirements management doors (7) · rational doors (7)
- 52 CVE4 critCVSS 6.4PoC 4enterprise linux server (35) · enterprise linux workstation (34) · enterprise linux desktop (34)
- 51 CVE10 critCVSS 8.0PoC 2android (51)
- 48 CVE4 critCVSS 7.0PoC 12debian gnu/linux (32) · linux (12) · retirejs (2)
- 40 CVE1 critCVSS 6.9×3.6PoC 11astra linux special edition (32) · astra linux common edition (11) · astra linux special edition для «эльбрус» (7)
- 35 CVE1 critCVSS 6.9×7.0KEV 1Nuclei 1PoC 1jenkins (16) · translation assistance (1) · warnings (1)
- 35 CVECVSS 8.2KEV 2PoC 9microsoft office 2016 (18) · microsoft office 2016 click-to-run (c2r) (17) · microsoft office compatibility pack service pack 3 (16)
- 31 CVE2 critCVSS 6.3Nuclei 1PoC 2webex meetings server (6) · nx-os (3) · sg300-10mpp firmware (2)
- 30 CVE1 critCVSS 6.6Nuclei 7PoC 12wpglobus/wpglobus (7) · moodle/moodle (4) · mautic/core (3)
- 25 CVE2 critCVSS 8.2×25.0PoC 1xp p9000 command view (16) · xp command view (16) · xp7 command view (16)
- 25 CVECVSS 7.2NEWPoC 14antivirus (24) · total security (11) · internet security (10)
- 25 CVECVSS 7.2PoC 25er5110g firmware (25) · er5120g firmware (25) · er5510g firmware (25)
- 24 CVE11 critCVSS 8.4android (23) · libvpx (1)
- 23 CVE5 critCVSS 7.8NEWnetgain systems enterprise manager (23)
- 23 CVE5 critCVSS 7.8NEWenterprise manager (23)
- 21 CVECVSS 7.0×6.0PoC 15jquery-rails (3) · vladtheenterprising (2) · cap-strap (1)
- 20 CVE1 critCVSS 7.7android for msm, firefox os for msm, qrd android (20)
- 19 CVE2 critCVSS 6.9PoC 1linux kernel (18) · linux kernel ixgbe (1) · linux kernel i40e\/i40evf (1)
- 19 CVECVSS 5.6Nuclei 1struxureware data center expert (16) · pelco videoxpert (3)
- 19 CVE2 critCVSS 6.8×6.3PoC 5роса кобальт (15) · роса хром (4) · rels (3)
- 18 CVE4 critCVSS 7.2PoC 1nifi (3) · geode (3) · hadoop (2)
- 17 CVE3 critCVSS 7.3PoC 1apache nifi (3) · apache geode (3) · apache hadoop (2)
- 17 CVE1 critCVSS 6.9PoC 3oncommand insight (12) · active iq unified manager (9) · oncommand workflow automation (9)
- 17 CVE2 critCVSS 6.8KEV 1Nuclei 1PoC 5mysql server (4) · mysql (4) · solaris (3)
- 16 CVE1 critCVSS 6.8×3.2PoC 4ubuntu (16)
- 16 CVE1 critCVSS 6.6PoC 2opencv-python (4) · plone (4) · opencv-contrib-python (4)
- 14 CVE2 critCVSS 6.9PoC 11junos (9) · junos space (4) · screenos (1)
- 14 CVE1 critCVSS 6.2×4.0PoC 6opensuse leap (13) · suse linux enterprise module for server applications (2) · suse linux enterprise module for public cloud (1)
- 13 CVECVSS 6.7PoC 3imagemagick (13)
- 13 CVECVSS 6.8Nuclei 1PoC 7jquery (3) · electron (2) · marked (1)
- 13 CVECVSS 7.8NEWPoC 3cpp-ethereum (9) · tinysvcmdns (1) · delayed_job_web rails gem (1)
- 12 CVE1 critCVSS 6.7PoC 11junos os (8) · junos space (3) · screenos (1)
- 12 CVE2 critCVSS 7.8PoC 2red hat enterprise linux (8) · openshift container platform (2) · jboss fuse (2)
- 12 CVE12 critCVSS 9.8x server (12)
- 11 CVE11 critCVSS 9.8NEWxorg-x11-server (11)
- 10 CVECVSS 6.4×3.3jira (6) · sourcetree (2) · crowd (1)
- 10 CVECVSS 7.3NEWPoC 10malwarebytes (10)
- 10 CVECVSS 7.2NEW×5.0rhel shipped xdg-user-dirs and gnome-session (1) · 389-ds-base (1) · hibernate-validator (1)
- 10 CVECVSS 5.2NEWNuclei 10PoC 5responsive coming soon page (10)
- 9 CVE3 critCVSS 7.7PoC 2webaccess (7) · webaccess\/scada (2)
- 9 CVECVSS 7.9NEWPoC 2cpp-ethereum (7) · aleth (1) · ethereum virtual machine (1)
- 9 CVE2 critCVSS 7.4PoC 1hp jetadvantage security manager (2) · hp support assistant (1) · hp thinpro (1)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | oracle | 177 | 8 | 1 | 1 | KEV 1Nuclei 1PoC 7 | mysql (20) · jdk (20) · jre (20) | — | |
| 2 | oracle corporation | 167 | 7 | · | · | PoC 3 | mysql server (19) · java (18) · vm virtualbox (9) | — | |
| 3 | debian | 115 | 26 | · | · | PoC 21 | debian linux (115) | — | |
| 4 | 76 | 11 | · | · | PoC 3 | android (74) · chrome (2) | — | ||
| 5 | maven | 70 | 8 | 2 | 3 | ×5.4KEV 2Nuclei 3PoC 7 | org.jenkins-ci.main:jenkins-core (16) · org.webjars.npm:jquery (3) · org.apache.geode:geode-core (3) | — | |
| 6 | canonical | 65 | 3 | · | · | ×5.0PoC 11 | ubuntu linux (65) | — | |
| 7 | microsoft | 60 | · | 2 | · | KEV 2PoC 18 | office (20) · edge (18) · chakracore (17) | — | |
| 8 | microsoft corporation | 60 | · | 2 | · | KEV 2PoC 18 | microsoft edge (16) · equation editor (12) · windows kernel (6) | — | |
| 9 | ibm | 59 | 3 | · | 1 | Nuclei 1PoC 1 | security key lifecycle manager (10) · engineering requirements management doors (7) · rational doors (7) | — | |
| 10 | redhat | 52 | 4 | · | · | PoC 4 | enterprise linux server (35) · enterprise linux workstation (34) · enterprise linux desktop (34) | — | |
| 11 | google inc. | 51 | 10 | · | · | PoC 2 | android (51) | — | |
| 12 | сообщество свободного программного обеспечения | 48 | 4 | · | · | PoC 12 | debian gnu/linux (32) · linux (12) · retirejs (2) | — | |
| 13 | ооо «русбитех-астра» | 40 | 1 | · | · | ×3.6PoC 11 | astra linux special edition (32) · astra linux common edition (11) · astra linux special edition для «эльбрус» (7) | — | |
| 14 | jenkins | 35 | 1 | 1 | 1 | ×7.0KEV 1Nuclei 1PoC 1 | jenkins (16) · translation assistance (1) · warnings (1) | — | |
| 15 | microsoft corp | 35 | · | 2 | · | KEV 2PoC 9 | microsoft office 2016 (18) · microsoft office 2016 click-to-run (c2r) (17) · microsoft office compatibility pack service pack 3 (16) | — | |
| 16 | cisco | 31 | 2 | · | 1 | Nuclei 1PoC 2 | webex meetings server (6) · nx-os (3) · sg300-10mpp firmware (2) | — | |
| 17 | packagist | 30 | 1 | · | 7 | Nuclei 7PoC 12 | wpglobus/wpglobus (7) · moodle/moodle (4) · mautic/core (3) | — | |
| 18 | hp | 25 | 2 | · | · | ×25.0PoC 1 | xp p9000 command view (16) · xp command view (16) · xp7 command view (16) | — | |
| 19 | k7computing | 25 | · | · | · | NEWPoC 14 | antivirus (24) · total security (11) · internet security (10) | — | |
| 20 | tp-link | 25 | · | · | · | PoC 25 | er5110g firmware (25) · er5120g firmware (25) · er5510g firmware (25) | — | |
| 21 | google inc | 24 | 11 | · | · | android (23) · libvpx (1) | — | ||
| 22 | netgain systems | 23 | 5 | · | · | NEW | netgain systems enterprise manager (23) | — | |
| 23 | netgain-systems | 23 | 5 | · | · | NEW | enterprise manager (23) | — | |
| 24 | rubygems | 21 | · | · | · | ×6.0PoC 15 | jquery-rails (3) · vladtheenterprising (2) · cap-strap (1) | — | |
| 25 | qualcomm, inc. | 20 | 1 | · | · | android for msm, firefox os for msm, qrd android (20) | — | ||
| 26 | linux | 19 | 2 | · | · | PoC 1 | linux kernel (18) · linux kernel ixgbe (1) · linux kernel i40e\/i40evf (1) | — | |
| 27 | schneider-electric | 19 | · | · | 1 | Nuclei 1 | struxureware data center expert (16) · pelco videoxpert (3) | — | |
| 28 | ао «нтц ит роса» | 19 | 2 | · | · | ×6.3PoC 5 | роса кобальт (15) · роса хром (4) · rels (3) | — | |
| 29 | apache | 18 | 4 | · | · | PoC 1 | nifi (3) · geode (3) · hadoop (2) | — | |
| 30 | apache software foundation | 17 | 3 | · | · | PoC 1 | apache nifi (3) · apache geode (3) · apache hadoop (2) | — | |
| 31 | netapp | 17 | 1 | · | · | PoC 3 | oncommand insight (12) · active iq unified manager (9) · oncommand workflow automation (9) | — | |
| 32 | oracle corp. | 17 | 2 | 1 | 1 | KEV 1Nuclei 1PoC 5 | mysql server (4) · mysql (4) · solaris (3) | — | |
| 33 | canonical ltd. | 16 | 1 | · | · | ×3.2PoC 4 | ubuntu (16) | — | |
| 34 | pypi | 16 | 1 | · | · | PoC 2 | opencv-python (4) · plone (4) · opencv-contrib-python (4) | — | |
| 35 | juniper | 14 | 2 | · | · | PoC 11 | junos (9) · junos space (4) · screenos (1) | — | |
| 36 | novell inc. | 14 | 1 | · | · | ×4.0PoC 6 | opensuse leap (13) · suse linux enterprise module for server applications (2) · suse linux enterprise module for public cloud (1) | — | |
| 37 | imagemagick | 13 | · | · | · | PoC 3 | imagemagick (13) | — | |
| 38 | npm | 13 | · | · | 1 | Nuclei 1PoC 7 | jquery (3) · electron (2) · marked (1) | — | |
| 39 | talos | 13 | · | · | · | NEWPoC 3 | cpp-ethereum (9) · tinysvcmdns (1) · delayed_job_web rails gem (1) | — | |
| 40 | juniper networks | 12 | 1 | · | · | PoC 11 | junos os (8) · junos space (3) · screenos (1) | — | |
| 41 | red hat inc. | 12 | 2 | · | · | PoC 2 | red hat enterprise linux (8) · openshift container platform (2) · jboss fuse (2) | — | |
| 42 | x.org | 12 | 12 | · | · | x server (12) | — | ||
| 43 | the x.org foundation | 11 | 11 | · | · | NEW | xorg-x11-server (11) | — | |
| 44 | atlassian | 10 | · | · | · | ×3.3 | jira (6) · sourcetree (2) · crowd (1) | — | |
| 45 | malwarebytes | 10 | · | · | · | NEWPoC 10 | malwarebytes (10) | — | |
| 46 | red hat, inc. | 10 | · | · | · | NEW×5.0 | rhel shipped xdg-user-dirs and gnome-session (1) · 389-ds-base (1) · hibernate-validator (1) | — | |
| 47 | responsive coming soon page project | 10 | · | · | 10 | NEWNuclei 10PoC 5 | responsive coming soon page (10) | — | |
| 48 | advantech | 9 | 3 | · | · | PoC 2 | webaccess (7) · webaccess\/scada (2) | — | |
| 49 | ethereum | 9 | · | · | · | NEWPoC 2 | cpp-ethereum (7) · aleth (1) · ethereum virtual machine (1) | — | |
| 50 | hp inc. | 9 | 2 | · | · | PoC 1 | hp jetadvantage security manager (2) · hp support assistant (1) · hp thinpro (1) | — |