month report
November 2018
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
November 2018 closed with 990 published CVEs. 143 criticals, google led volume, mostly via android. Top weakness class — CWE-79 (134 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
990
— MoM— YoY
Severity mix
143 / 453
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
2.1%
21 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
2666.3
n=21
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
1302
n=6
Detection gap
KEV pressure, no Nuclei coverage
November 2018 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 3redhat74 CVE
- KEV 2google132 CVE
- KEV 2microsoft63 CVE
- KEV 2microsoft corp42 CVE
- KEV 2google inc24 CVE
- KEV 1[unknown]21 CVE
- KEV 1maven15 CVE
Weakness × Vendor
What's spreading where in November 2018
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS125Out-of-bounds Read787Out-of-bounds Write200Information Exposure119Memory Buffer Bounds352CSRF78OS Command Injection89SQL Injection20Improper Input Validation22Path Traversalgoogle3212896382debian617168361сообщество свободного программного обеспечения216125111redhat4109914microsoft9932ооо «русбитех-астра»11172121google inc.14213132canonical9921microsoft corp5331ibm617112canonical ltd.481google inc27121
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #13terra-master24 CVE
- #15[unknown]21 CVE
- #17opticam20 CVE
- #24qualcomm14 CVE
- #27unknown13 CVE
- #29yitechnology12 CVE
- #30laobancms11 CVE
- #33totolink11 CVE
- #37nuget10 CVE
- #42schneider electric se9 CVE
Top vendors
Ranked by distinct CVE count this period.
- 132 CVE7 critCVSS 7.4KEV 2PoC 8android (87) · chrome (40) · monorail (3)
- 108 CVE10 critCVSS 7.2KEV 2Nuclei 2PoC 28debian linux (108)
- 80 CVE9 critCVSS 7.2KEV 1Nuclei 2PoC 28debian gnu/linux (71) · linux (5) · keepalived (4)
- 74 CVE10 critCVSS 7.3KEV 3PoC 11enterprise linux server (44) · enterprise linux workstation (43) · enterprise linux desktop (42)
- 63 CVE2 critCVSS 7.2KEV 2PoC 4windows 10 (22) · windows server 2016 (21) · windows server 2019 (20)
- 61 CVE6 critCVSS 7.0KEV 1Nuclei 2PoC 17astra linux special edition (55) · astra linux common edition (16) · astra linux special edition для «эльбрус» (14)
- 57 CVE4 critCVSS 7.7PoC 2android (57)
- 43 CVE9 critCVSS 7.6Nuclei 1PoC 10ubuntu linux (43)
- 42 CVE2 critCVSS 7.5KEV 2PoC 2windows server 2016 (14) · windows 10 1709 (13) · windows 10 1607 (13)
- 41 CVECVSS 5.6db2 (7) · db2 for linux, unix and windows (7) · rational engineering lifecycle manager (4)
- 26 CVE8 critCVSS 7.5PoC 3ubuntu (26)
- 24 CVE1 critCVSS 7.1KEV 2PoC 3google chrome (15) · android (9)
- 24 CVE4 critCVSS 7.3NEWPoC 14terramaster operating system (24)
- 22 CVE4 critCVSS 6.8PoC 7red hat enterprise linux (19) · openshift container platform (1) · red hat enterprise virtualization (1)
- 21 CVE1 critCVSS 6.7NEWKEV 1PoC 1samba (7) · nginx (3) · pdns (2)
- 20 CVE8 critCVSS 8.0PoC 8c2 application firmware (20) · c2 system firmware (20)
- 20 CVE8 critCVSS 8.0NEWPoC 8i5 application firmware (20) · i5 system firmware (20)
- 20 CVE2 critCVSS 7.2Nuclei 1PoC 13centreon/centreon (5) · showdoc/showdoc (3) · baserproject/basercms (2)
- 19 CVE3 critCVSS 7.0Nuclei 1PoC 9opensuse leap (19) · suse linux enterprise desktop (8) · suse linux enterprise module for open buildservice development tools (7)
- 18 CVE4 critCVSS 8.9PoC 18cisco amp for endpoints (2) · energy management suite software (2) · cisco energy management suite (2)
- 18 CVE4 critCVSS 7.7PoC 17energy management suite (2) · advanced malware protection for endpoints (1) · cisco 250 series smart switches (1)
- 16 CVECVSS 6.7system management module firmware (9) · thinksystem smm (9) · xclarity integrator (3)
- 15 CVE3 critCVSS 7.6KEV 1PoC 1org.apache.hadoop:hadoop-main (2) · org.apache.syncope:syncope-core (2) · org.keycloak:keycloak-core (2)
- 14 CVE1 critCVSS 7.7NEWsd 820a firmware (12) · msm8996au firmware (12) · sd 820 firmware (12)
- 14 CVE1 critCVSS 7.8snapdragon automobile, snapdragon mobile, snapdragon wear (8) · snapdragon automobile, snapdragon mobile (4) · snapdragon mobile (2)
- 14 CVECVSS 7.2sap fiori client (5) · fiori client (5) · businessobjects business intelligence (2)
- 13 CVE5 critCVSS 8.1NEWPoC 3yi technology (8) · circontrol circarlife all versions prior to 4.3.1 (2) · indusoft web studio, and intouch edge hmi (formerly intouch machine edition) (2)
- 12 CVE1 critCVSS 7.1PoC 2foxit reader (12) · u3d (9)
- 12 CVE1 critCVSS 7.7NEWPoC 4yi home camera firmware (12) · yi home (4)
- 11 CVE4 critCVSS 7.6NEWPoC 5laobancms (11)
- 11 CVE1 critCVSS 6.8PoC 3ckeditor (1) · cached-path-relative (1) · editor.md (1)
- 11 CVECVSS 7.7Nuclei 1PoC 6linux enterprise desktop (5) · linux enterprise server (5) · suse linux enterprise server (5)
- 11 CVE6 critCVSS 8.1NEWNuclei 1PoC 3a3002ru firmware (11)
- 11 CVECVSS 6.8Nuclei 1PoC 6ос он «стрелец» (11)
- 10 CVECVSS 6.1espace 7950 firmware (3) · emily-al00a firmware (2) · fusionsphere openstack (1)
- 10 CVECVSS 6.2espace 7950 (3) · emily-al00a (2) · huawei honor 7a, huawei honor 9 lite (1)
- 10 CVECVSS 7.1NEWmicrosoft.chakracore (8) · umbraco (1) · microsoft.netcore.app (1)
- 9 CVE2 critCVSS 7.7PoC 1hadoop (2) · hive (2) · syncope (2)
- 9 CVE1 critCVSS 7.5PoC 2emc integrated data protection appliance (5) · emc avamar (4) · openmanage network manager (2)
- 9 CVECVSS 7.0Nuclei 1PoC 4leap (9) · backports sle (1)
- 9 CVE2 critCVSS 8.4PoC 1modicom m340 firmware (5) · modicom premium firmware (5) · modicom quantum firmware (5)
- 9 CVE2 critCVSS 8.4NEWPoC 1embedded web servers in all modicon m340, premium, quantum plcs and bmxnor0200 (5) · data center expert versions 7.5.0 and earlier (1) · data center operation all versions (1)
- 8 CVE1 critCVSS 7.9apache syncope (2) · hadoop (2) · apache hive (2)
- 8 CVECVSS 7.6fabric operating system (8)
- 8 CVECVSS 7.6NEWbrocade fabric os (8)
- 8 CVE5 critCVSS 9.1NEWdebun pop (8) · debun imap (7)
- 8 CVE5 critCVSS 9.1NEWdenbun by neojapan inc. (denbun pop version v3.3p r4.0 and earlier, denbun imap version v3.3i r4.0 and earlier) (6) · denbun by neojapan inc. (denbun pop version v3.3p r3.0 and earlier, denbun imap version v3.3i r3.0 and earlier) (1) · denbun pop version v3.3p r4.0 and earlier (1)
- 8 CVE2 critCVSS 6.9NEWPoC 2zxhn f670 (5) · zxhn f670 firmware (5) · zxhn h168n (2)
- 7 CVE1 critCVSS 7.6NEWPoC 1ts5600d1206 firmware (7)
- 7 CVE1 critCVSS 7.1NEWintegrated data protection appliance (5) · avamar (4) · dell emc recoverpoint virtual machine (vm) (2)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | 132 | 7 | 2 | · | KEV 2PoC 8 | android (87) · chrome (40) · monorail (3) | — | ||
| 2 | debian | 108 | 10 | 2 | 2 | KEV 2Nuclei 2PoC 28 | debian linux (108) | — | |
| 3 | сообщество свободного программного обеспечения | 80 | 9 | 1 | 2 | KEV 1Nuclei 2PoC 28 | debian gnu/linux (71) · linux (5) · keepalived (4) | — | |
| 4 | redhat | 74 | 10 | 3 | · | KEV 3PoC 11 | enterprise linux server (44) · enterprise linux workstation (43) · enterprise linux desktop (42) | — | |
| 5 | microsoft | 63 | 2 | 2 | · | KEV 2PoC 4 | windows 10 (22) · windows server 2016 (21) · windows server 2019 (20) | — | |
| 6 | ооо «русбитех-астра» | 61 | 6 | 1 | 2 | KEV 1Nuclei 2PoC 17 | astra linux special edition (55) · astra linux common edition (16) · astra linux special edition для «эльбрус» (14) | — | |
| 7 | google inc. | 57 | 4 | · | · | PoC 2 | android (57) | — | |
| 8 | canonical | 43 | 9 | · | 1 | Nuclei 1PoC 10 | ubuntu linux (43) | — | |
| 9 | microsoft corp | 42 | 2 | 2 | · | KEV 2PoC 2 | windows server 2016 (14) · windows 10 1709 (13) · windows 10 1607 (13) | — | |
| 10 | ibm | 41 | · | · | · | db2 (7) · db2 for linux, unix and windows (7) · rational engineering lifecycle manager (4) | — | ||
| 11 | canonical ltd. | 26 | 8 | · | · | PoC 3 | ubuntu (26) | — | |
| 12 | google inc | 24 | 1 | 2 | · | KEV 2PoC 3 | google chrome (15) · android (9) | — | |
| 13 | terra-master | 24 | 4 | · | · | NEWPoC 14 | terramaster operating system (24) | — | |
| 14 | red hat inc. | 22 | 4 | · | · | PoC 7 | red hat enterprise linux (19) · openshift container platform (1) · red hat enterprise virtualization (1) | — | |
| 15 | [unknown] | 21 | 1 | 1 | · | NEWKEV 1PoC 1 | samba (7) · nginx (3) · pdns (2) | — | |
| 16 | foscam | 20 | 8 | · | · | PoC 8 | c2 application firmware (20) · c2 system firmware (20) | — | |
| 17 | opticam | 20 | 8 | · | · | NEWPoC 8 | i5 application firmware (20) · i5 system firmware (20) | — | |
| 18 | packagist | 20 | 2 | · | 1 | Nuclei 1PoC 13 | centreon/centreon (5) · showdoc/showdoc (3) · baserproject/basercms (2) | — | |
| 19 | novell inc. | 19 | 3 | · | 1 | Nuclei 1PoC 9 | opensuse leap (19) · suse linux enterprise desktop (8) · suse linux enterprise module for open buildservice development tools (7) | — | |
| 20 | cisco | 18 | 4 | · | · | PoC 18 | cisco amp for endpoints (2) · energy management suite software (2) · cisco energy management suite (2) | — | |
| 21 | cisco systems inc. | 18 | 4 | · | · | PoC 17 | energy management suite (2) · advanced malware protection for endpoints (1) · cisco 250 series smart switches (1) | — | |
| 22 | lenovo | 16 | · | · | · | system management module firmware (9) · thinksystem smm (9) · xclarity integrator (3) | — | ||
| 23 | maven | 15 | 3 | 1 | · | KEV 1PoC 1 | org.apache.hadoop:hadoop-main (2) · org.apache.syncope:syncope-core (2) · org.keycloak:keycloak-core (2) | — | |
| 24 | qualcomm | 14 | 1 | · | · | NEW | sd 820a firmware (12) · msm8996au firmware (12) · sd 820 firmware (12) | — | |
| 25 | qualcomm, inc. | 14 | 1 | · | · | snapdragon automobile, snapdragon mobile, snapdragon wear (8) · snapdragon automobile, snapdragon mobile (4) · snapdragon mobile (2) | — | ||
| 26 | sap | 14 | · | · | · | sap fiori client (5) · fiori client (5) · businessobjects business intelligence (2) | — | ||
| 27 | unknown | 13 | 5 | · | · | NEWPoC 3 | yi technology (8) · circontrol circarlife all versions prior to 4.3.1 (2) · indusoft web studio, and intouch edge hmi (formerly intouch machine edition) (2) | — | |
| 28 | foxitsoftware | 12 | 1 | · | · | PoC 2 | foxit reader (12) · u3d (9) | — | |
| 29 | yitechnology | 12 | 1 | · | · | NEWPoC 4 | yi home camera firmware (12) · yi home (4) | — | |
| 30 | laobancms | 11 | 4 | · | · | NEWPoC 5 | laobancms (11) | — | |
| 31 | npm | 11 | 1 | · | · | PoC 3 | ckeditor (1) · cached-path-relative (1) · editor.md (1) | — | |
| 32 | suse | 11 | · | · | 1 | Nuclei 1PoC 6 | linux enterprise desktop (5) · linux enterprise server (5) · suse linux enterprise server (5) | — | |
| 33 | totolink | 11 | 6 | · | 1 | NEWNuclei 1PoC 3 | a3002ru firmware (11) | — | |
| 34 | ао «концерн вниинс» | 11 | · | · | 1 | Nuclei 1PoC 6 | ос он «стрелец» (11) | — | |
| 35 | huawei | 10 | · | · | · | espace 7950 firmware (3) · emily-al00a firmware (2) · fusionsphere openstack (1) | — | ||
| 36 | huawei technologies co., ltd. | 10 | · | · | · | espace 7950 (3) · emily-al00a (2) · huawei honor 7a, huawei honor 9 lite (1) | — | ||
| 37 | nuget | 10 | · | · | · | NEW | microsoft.chakracore (8) · umbraco (1) · microsoft.netcore.app (1) | — | |
| 38 | apache | 9 | 2 | · | · | PoC 1 | hadoop (2) · hive (2) · syncope (2) | — | |
| 39 | dell | 9 | 1 | · | · | PoC 2 | emc integrated data protection appliance (5) · emc avamar (4) · openmanage network manager (2) | — | |
| 40 | opensuse | 9 | · | · | 1 | Nuclei 1PoC 4 | leap (9) · backports sle (1) | — | |
| 41 | schneider-electric | 9 | 2 | · | · | PoC 1 | modicom m340 firmware (5) · modicom premium firmware (5) · modicom quantum firmware (5) | — | |
| 42 | schneider electric se | 9 | 2 | · | · | NEWPoC 1 | embedded web servers in all modicon m340, premium, quantum plcs and bmxnor0200 (5) · data center expert versions 7.5.0 and earlier (1) · data center operation all versions (1) | — | |
| 43 | apache software foundation | 8 | 1 | · | · | apache syncope (2) · hadoop (2) · apache hive (2) | — | ||
| 44 | broadcom | 8 | · | · | · | fabric operating system (8) | — | ||
| 45 | brocade communications systems, inc. | 8 | · | · | · | NEW | brocade fabric os (8) | — | |
| 46 | neo | 8 | 5 | · | · | NEW | debun pop (8) · debun imap (7) | — | |
| 47 | neojapan inc. | 8 | 5 | · | · | NEW | denbun by neojapan inc. (denbun pop version v3.3p r4.0 and earlier, denbun imap version v3.3i r4.0 and earlier) (6) · denbun by neojapan inc. (denbun pop version v3.3p r3.0 and earlier, denbun imap version v3.3i r3.0 and earlier) (1) · denbun pop version v3.3p r4.0 and earlier (1) | — | |
| 48 | zte | 8 | 2 | · | · | NEWPoC 2 | zxhn f670 (5) · zxhn f670 firmware (5) · zxhn h168n (2) | — | |
| 49 | buffalo | 7 | 1 | · | · | NEWPoC 1 | ts5600d1206 firmware (7) | — | |
| 50 | dell emc | 7 | 1 | · | · | NEW | integrated data protection appliance (5) · avamar (4) · dell emc recoverpoint virtual machine (vm) (2) | — |