month report
May 2018
Data as of Jun 4, 2026, 13:28 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
May 2018 closed with 1,191 published CVEs — -71.3% YoY . 153 criticals, npm led volume, mostly via sequelize. Biggest breakout: hackerone at ×33.3 their 12-month median. Top weakness class — CWE-79 (133 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
1,191
-29.2% MoM-71.3% YoY
Severity mix
153 / 521
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
3.4%
40 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
2851.3
n=40
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
1406
n=7
Detection gap
KEV pressure, no Nuclei coverage
May 2018 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 3microsoft71 CVE
- KEV 2microsoft corp35 CVE
- KEV 1adobe37 CVE
Weakness × Vendor
What's spreading where in May 2018
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS20Improper Input Validation125Out-of-bounds Read119Memory Buffer Bounds200Information Exposure787Out-of-bounds Write416Use After Free311Missing Encryption89SQL Injection310CWE-310npm81212740641hackerone71212740641foxitsoftware22894929foxit22564828microsoft64116181debian676292canonical153493ibm5413112redhat1233431сообщество свободного программного обеспечения136174maven45adobe5282162
Breakout vendors
CVE count ≥3× their own 12-period median.
- 33.3×hackerone100 CVE
- 20.0×foxitsoftware90 CVE
- 17.0×npm102 CVE
- 8.9×foxit80 CVE
- 5.7×moxa17 CVE
- 4.5×pivotal9 CVE
- 4.3×d-link corp.13 CVE
- 4.0×advantech12 CVE
- 3.3×d-link10 CVE
- 3.0×joomla9 CVE
Top vendors
Ranked by distinct CVE count this period.
- 102 CVE12 critCVSS 7.6×17.0Nuclei 2PoC 9sequelize (4) · hapi (3) · ws (2)
- 100 CVE12 critCVSS 7.6NEW×33.3Nuclei 1PoC 9sequelize node module (4) · hapi node module (3) · ws node module (2)
- 90 CVECVSS 8.1×20.0PoC 2phantompdf (88) · foxit reader (81) · reader (9)
- 80 CVECVSS 8.0×8.9PoC 2foxit reader (80)
- 71 CVE1 critCVSS 7.0KEV 3PoC 10windows server 2016 (20) · edge (20) · windows 10 (19)
- 64 CVE8 critCVSS 7.0PoC 17debian linux (64)
- 50 CVE6 critCVSS 7.0PoC 19ubuntu linux (50)
- 42 CVE1 critCVSS 6.4storwize v9000 firmware (9) · storwize v7000 firmware (9) · storwize v5000 firmware (9)
- 41 CVE4 critCVSS 6.8PoC 13enterprise linux server (24) · enterprise linux workstation (24) · enterprise linux desktop (23)
- 39 CVE6 critCVSS 6.9PoC 12debian gnu/linux (28) · linux (5) · props-ng (3)
- 38 CVE4 critCVSS 6.2PoC 1org.jenkins-ci.main:jenkins-core (14) · org.springframework:spring-core (2) · org.jenkins-ci.plugins:google-login (2)
- 37 CVE13 critCVSS 8.7KEV 1PoC 4flash player (9) · acrobat dc (8) · acrobat reader dc (8)
- 35 CVE6 critCVSS 7.4aironet access point software (4) · wireless lan controller software (4) · digital network architecture center (3)
- 35 CVE1 critCVSS 7.7KEV 2PoC 8microsoft edge (17) · chakracore (14) · internet explorer (7)
- 29 CVE5 critCVSS 7.2PoC 10astra linux special edition (25) · astra linux common edition (12) · astra linux special edition для «эльбрус» (8)
- 26 CVE8 critCVSS 8.5PoC 14moxa (17) · mysql mmm (8) · open fire user import export plugin (1)
- 25 CVE3 critCVSS 6.9PoC 8ubuntu (25)
- 20 CVECVSS 5.4NEWPoC 3jenkins (11) · procps-ng, procps (4) · undertow (1)
- 19 CVECVSS 5.1jenkins (14) · google login (2) · html publisher (1)
- 17 CVECVSS 7.9×5.7PoC 9edr-810 firmware (17)
- 15 CVE1 critCVSS 6.6PoC 6red hat enterprise linux (12) · red hat enterprise mrg (3) · red hat virtualization (2)
- 14 CVECVSS 7.8trend micro email encryption gateway (6) · trend micro maximum security (5) · trend micro smart protection server (standalone) (2)
- 14 CVECVSS 7.5email encryption gateway (6) · premium security (5) · antivirus\+ (5)
- 13 CVE4 critCVSS 9.1×4.3PoC 5dsl-3782 (7) · dir-550a (2) · dir-604m (2)
- 13 CVE3 critCVSS 7.3Nuclei 2PoC 2moodle/moodle (5) · dolibarr/dolibarr (4) · opencart/opencart (2)
- 12 CVE5 critCVSS 8.4×4.0webaccess (12) · webaccess dashboard (11) · webaccess\/nms (11)
- 12 CVECVSS 6.0PoC 2linux kernel (12)
- 12 CVE1 critCVSS 7.1PoC 6opensuse leap (12) · suse linux enterprise server for sap applications (3) · suse linux enterprise server (3)
- 12 CVECVSS 7.5PoC 4microsoft.chakracore (11) · system.security.cryptography.xml (1)
- 11 CVECVSS 6.7PoC 1android (9) · gmail (1) · chrome (1)
- 11 CVE4 critCVSS 8.2Nuclei 1PoC 2weblogic server (3) · insurance calculation engine (3) · communications diameter signaling router (3)
- 11 CVE4 critCVSS 8.4KEV 1Nuclei 2PoC 6kace system management appliance (11)
- 10 CVECVSS 7.1PoC 92345 security guard (10)
- 10 CVE3 critCVSS 7.5PoC 2nifi (2) · batik (1) · solr (1)
- 10 CVE3 critCVSS 7.7PoC 2apache nifi (2) · derby (1) · openoffice (1)
- 10 CVE3 critCVSS 9.1×3.3PoC 2dsl-3782 firmware (6) · dir-550a firmware (2) · dir-604m firmware (2)
- 10 CVECVSS 7.6PoC 11288h v5; 2288h v5 (3) · berlin-l21hn; prague-al00a; prague-al00b; prague-al00c; prague-l31; prague-tl00a; prague-tl10a (1) · dp300; rp200; te30; te40; te50; te60 (1)
- 10 CVE2 critCVSS 8.2delta electronics wplsoft (3) · vgo robot (2) · advantech webaccess versions 8.1 and prior. (1)
- 10 CVE4 critCVSS 8.6Nuclei 1PoC 2weblogic server (3) · communications diameter signaling router (2) · oracle utilities network management system (2)
- 10 CVECVSS 5.7radare2 (10)
- 10 CVECVSS 5.0PoC 1internet graphics server (4) · identity management (2) · sapscore (1)
- 9 CVE3 critCVSS 8.3PoC 2xenmobile server (7) · application delivery controller firmware (1) · netscaler gateway firmware (1)
- 9 CVECVSS 6.1NEWPoC 3espruino (9)
- 9 CVECVSS 7.52288h v5 firmware (5) · 1288h v5 firmware (5) · 2488 v5 firmware (2)
- 9 CVE1 critCVSS 6.5×3.0joomla\! (9)
- 9 CVE1 critCVSS 7.1×4.5spring framework (2) · spring integration zip (2) · spring data commons (1)
- 9 CVECVSS 6.7fusion (2) · spring framework (2) · spring integration zip (2)
- 9 CVECVSS 7.5wireshark (9)
- 9 CVE1 critCVSS 6.9PoC 1ос он «стрелец» (9)
- 8 CVECVSS 5.7big-ip link controller (8) · big-ip local traffic manager (8) · big-ip policy enforcement manager (8)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | npm | 102 | 12 | · | 2 | ×17.0Nuclei 2PoC 9 | sequelize (4) · hapi (3) · ws (2) | ↑154 | |
| 2 | hackerone | 100 | 12 | · | 1 | NEW×33.3Nuclei 1PoC 9 | sequelize node module (4) · hapi node module (3) · ws node module (2) | — | |
| 3 | foxitsoftware | 90 | · | · | · | ×20.0PoC 2 | phantompdf (88) · foxit reader (81) · reader (9) | ↑86 | |
| 4 | foxit | 80 | · | · | · | ×8.9PoC 2 | foxit reader (80) | ↑189 | |
| 5 | microsoft | 71 | 1 | 3 | · | KEV 3PoC 10 | windows server 2016 (20) · edge (20) · windows 10 (19) | ↑6 | |
| 6 | debian | 64 | 8 | · | · | PoC 17 | debian linux (64) | ↓3 | |
| 7 | canonical | 50 | 6 | · | · | PoC 19 | ubuntu linux (50) | ↑1 | |
| 8 | ibm | 42 | 1 | · | · | storwize v9000 firmware (9) · storwize v7000 firmware (9) · storwize v5000 firmware (9) | ↑7 | ||
| 9 | redhat | 41 | 4 | · | · | PoC 13 | enterprise linux server (24) · enterprise linux workstation (24) · enterprise linux desktop (23) | ↑5 | |
| 10 | сообщество свободного программного обеспечения | 39 | 6 | · | · | PoC 12 | debian gnu/linux (28) · linux (5) · props-ng (3) | ↑3 | |
| 11 | maven | 38 | 4 | · | · | PoC 1 | org.jenkins-ci.main:jenkins-core (14) · org.springframework:spring-core (2) · org.jenkins-ci.plugins:google-login (2) | ↑5 | |
| 12 | adobe | 37 | 13 | 1 | · | KEV 1PoC 4 | flash player (9) · acrobat dc (8) · acrobat reader dc (8) | — | |
| 13 | cisco | 35 | 6 | · | · | aironet access point software (4) · wireless lan controller software (4) · digital network architecture center (3) | ↑7 | ||
| 14 | microsoft corp | 35 | 1 | 2 | · | KEV 2PoC 8 | microsoft edge (17) · chakracore (14) · internet explorer (7) | ↑3 | |
| 15 | ооо «русбитех-астра» | 29 | 5 | · | · | PoC 10 | astra linux special edition (25) · astra linux common edition (12) · astra linux special edition для «эльбрус» (8) | ↓3 | |
| 16 | talos | 26 | 8 | · | · | PoC 14 | moxa (17) · mysql mmm (8) · open fire user import export plugin (1) | ↑2 | |
| 17 | canonical ltd. | 25 | 3 | · | · | PoC 8 | ubuntu (25) | ↑2 | |
| 18 | [unknown] | 20 | · | · | · | NEWPoC 3 | jenkins (11) · procps-ng, procps (4) · undertow (1) | — | |
| 19 | jenkins | 19 | · | · | · | jenkins (14) · google login (2) · html publisher (1) | ↑21 | ||
| 20 | moxa | 17 | · | · | · | ×5.7PoC 9 | edr-810 firmware (17) | ↑132 | |
| 21 | red hat inc. | 15 | 1 | · | · | PoC 6 | red hat enterprise linux (12) · red hat enterprise mrg (3) · red hat virtualization (2) | ↑1 | |
| 22 | trend micro | 14 | · | · | · | trend micro email encryption gateway (6) · trend micro maximum security (5) · trend micro smart protection server (standalone) (2) | — | ||
| 23 | trendmicro | 14 | · | · | · | email encryption gateway (6) · premium security (5) · antivirus\+ (5) | — | ||
| 24 | d-link corp. | 13 | 4 | · | · | ×4.3PoC 5 | dsl-3782 (7) · dir-550a (2) · dir-604m (2) | ↑53 | |
| 25 | packagist | 13 | 3 | · | 2 | Nuclei 2PoC 2 | moodle/moodle (5) · dolibarr/dolibarr (4) · opencart/opencart (2) | ↑7 | |
| 26 | advantech | 12 | 5 | · | · | ×4.0 | webaccess (12) · webaccess dashboard (11) · webaccess\/nms (11) | ↑93 | |
| 27 | linux | 12 | · | · | · | PoC 2 | linux kernel (12) | ↑15 | |
| 28 | novell inc. | 12 | 1 | · | · | PoC 6 | opensuse leap (12) · suse linux enterprise server for sap applications (3) · suse linux enterprise server (3) | ↓7 | |
| 29 | nuget | 12 | · | · | · | PoC 4 | microsoft.chakracore (11) · system.security.cryptography.xml (1) | ↑42 | |
| 30 | 11 | · | · | · | PoC 1 | android (9) · gmail (1) · chrome (1) | ↓24 | ||
| 31 | oracle | 11 | 4 | · | 1 | Nuclei 1PoC 2 | weblogic server (3) · insurance calculation engine (3) · communications diameter signaling router (3) | ↓27 | |
| 32 | quest | 11 | 4 | 1 | 2 | KEV 1Nuclei 2PoC 6 | kace system management appliance (11) | — | |
| 33 | 2345 security guard project | 10 | · | · | · | PoC 9 | 2345 security guard (10) | — | |
| 34 | apache | 10 | 3 | · | · | PoC 2 | nifi (2) · batik (1) · solr (1) | ↑3 | |
| 35 | apache software foundation | 10 | 3 | · | · | PoC 2 | apache nifi (2) · derby (1) · openoffice (1) | ↑3 | |
| 36 | d-link | 10 | 3 | · | · | ×3.3PoC 2 | dsl-3782 firmware (6) · dir-550a firmware (2) · dir-604m firmware (2) | ↑99 | |
| 37 | huawei technologies co., ltd. | 10 | · | · | · | PoC 1 | 1288h v5; 2288h v5 (3) · berlin-l21hn; prague-al00a; prague-al00b; prague-al00c; prague-l31; prague-tl00a; prague-tl10a (1) · dp300; rp200; te30; te40; te50; te60 (1) | ↓7 | |
| 38 | ics-cert | 10 | 2 | · | · | delta electronics wplsoft (3) · vgo robot (2) · advantech webaccess versions 8.1 and prior. (1) | ↑17 | ||
| 39 | oracle corp. | 10 | 4 | · | 1 | Nuclei 1PoC 2 | weblogic server (3) · communications diameter signaling router (2) · oracle utilities network management system (2) | ↓10 | |
| 40 | radare | 10 | · | · | · | radare2 (10) | — | ||
| 41 | sap | 10 | · | · | · | PoC 1 | internet graphics server (4) · identity management (2) · sapscore (1) | ↑21 | |
| 42 | citrix | 9 | 3 | · | · | PoC 2 | xenmobile server (7) · application delivery controller firmware (1) · netscaler gateway firmware (1) | — | |
| 43 | espruino | 9 | · | · | · | NEWPoC 3 | espruino (9) | — | |
| 44 | huawei | 9 | · | · | · | 2288h v5 firmware (5) · 1288h v5 firmware (5) · 2488 v5 firmware (2) | ↓16 | ||
| 45 | joomla | 9 | 1 | · | · | ×3.0 | joomla\! (9) | — | |
| 46 | pivotal | 9 | 1 | · | · | ×4.5 | spring framework (2) · spring integration zip (2) · spring data commons (1) | — | |
| 47 | vmware | 9 | · | · | · | fusion (2) · spring framework (2) · spring integration zip (2) | ↑21 | ||
| 48 | wireshark | 9 | · | · | · | wireshark (9) | ↓17 | ||
| 49 | ао «концерн вниинс» | 9 | 1 | · | · | PoC 1 | ос он «стрелец» (9) | ↓2 | |
| 50 | f5 | 8 | · | · | · | big-ip link controller (8) · big-ip local traffic manager (8) · big-ip policy enforcement manager (8) | ↓2 |