August 2018
1,057 CVEs published, −52% on July 2018 and −32% on August 2017. CISA added 0 to KEV.
2018 month by month
| Year | Jan | Feb | Mar | Apr | May | Jun | Jul | Aug | Sep | Oct | Nov | Dec | Year total |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2018 | January 2018: 1,715 CVEs | February 2018: 1,350 CVEs | March 2018: 2,306 CVEs | April 2018: no snapshot | May 2018: no snapshot | June 2018: 1,804 CVEs | July 2018: 2,225 CVEs | August 2018: 1,057 CVEs | September 2018: 1,209 CVEs | October 2018: 1,483 CVEs | November 2018: no snapshot | December 2018: 1,212 CVEs | 14,3619 of 12 months9/12 |
- Critical
- 16416% of the 1,014 with a CVSS score
- Added to CISA KEV
- 08 of this month's CVEs are in KEV, listed a median 1319.5 days after publication
- Vendors
- 5052,069 products
- Top weakness
- XSSCWE-79 · 144 CVEs
Who drove it
Vendors by distinct CVEs this month, with how many of those CVEs are now in CISA KEV and how far each moved in the ranking.
- 1DebianDebian Linux, Advanced Package Tool876nonenew
- 2Red HatEnterprise Linux Desktop, Enterprise Linux Workstation, Enterprise Linux Server849nonenew
- 3CanonicalUbuntu Linux, Ubuntu, Cloud-init656nonenew
- 4MicrosoftWindows 10, Windows 10 Servers, Windows Server 1709 (Server Core Installation)6224new
- 5Сообщество Свободного Программного ОбеспеченияDebian Gnu/linux, Linux, Yum548nonenew
- 6HPCentralview Fraud Risk Management, 3par Service Provider, Aruba Clearpass Policy Manager5115nonenew
- 7Ооо «русбитех-астра»Astra Linux Special Edition, Astra Linux Common Edition, Astra Linux Special Edition Для «эльбрус»485nonenew
- 8Hewlett Packard EnterpriseHPE 3par Service Processors, HPE Centralview Fraud Risk Management, Aruba Clearpass4714nonenew
- 9MavenOrg.jenkins-ci.main:jenkins-core, Org.apache.tomcat.embed:tomcat-embed-core, De.tracetronic.jenkins.plugins:ecutest4221new
- 10IBMSecurity Identity Governance and Intelligence, Maximo Asset Management, Urbancode Deploy341nonenew
- 11GoogleChrome, Android, Android Studio324nonenew
- 12SamsungSth-eth-250 Firmware, Samsung, Smartthings Hub Sth-eth-2502814nonenew
- 13InsteonHub Firmware, Insteon, Hub 2245-222 Firmware2414nonenew
- 14PackagistSymfony/symfony, Pimcore/pimcore, Mantisbt/mantisbt2331new
- 15JenkinsJenkins, Tracetronic Ecu-test, Meliora Testlab220nonenew
- 16CiscoCisco Web Security Appliance, Web Security Appliance, SG300-28MP Firmware210nonenew
- 17Open-emrOpenemr203nonenew
- 18Apache Software FoundationApache Traffic Server, Apache Tomcat, Tomcat1911new
- 19OracleDatabase Server, Application Testing Suite, Core Rdbms1911new
- 20ApacheTraffic Server, Tomcat, Cayenne1811new
- 21RubygemsSafemode, Activerecord, Web-console182nonenew
- 22[unknown]Gnutls, Kernel, Ttembed180nonenew
- 23Kaspersky LabKraftway, Eltex Esp-200, Zipato Zipabox Smart Home Controller144nonenew
- 24Novell Inc.Opensuse Leap, Suse Linux Enterprise Server For Sap Applications, Suse Linux Enterprise Server143nonenew
- 25AdobeFlash Player, Creative Cloud, Acrobat Dc136nonenew
Severity
How this month's CVEs score on CVSS; 43 have no score yet. Severity is not exploitation.
- Critical164
- High417
- Medium414
- Low19
New in the top 100
Not in the top 100 in any of the 24 months before.
What kind of weakness
Weakness classes (CWE) by distinct CVEs, with how far each moved in the ranking.
- CWE-79XSS144
- CWE-200Information Exposure69
- CWE-119Memory Buffer Bounds62
- CWE-20Improper Input Validation62
- CWE-787Out-of-bounds Write50
- CWE-352CSRF48
- CWE-22Path Traversal35
- CWE-89SQL Injection34
- CWE-287Improper Authentication28
- CWE-125Out-of-bounds Read21
- CWE-798Hard-coded Credentials21
- CWE-400Resource Consumption20
- CWE-611XXE19
- CWE-78OS Command Injection19
- CWE-476NULL Pointer Dereference18
- CWE-732Incorrect Permissions17
- CWE-120Buffer Overflow16
- CWE-502Deserialization16
- CWE-94Code Injection15
- CWE-190Integer Overflow14
Where it landed
The month's CVEs by the sector of the software they affect. A CVE that touches several sectors counts in each.
- Operating Systems24817% of sector-tagged CVEs
- OSS Libraries21515% of sector-tagged CVEs
- Enterprise Software21314% of sector-tagged CVEs
- Web & CMS Plugins1349% of sector-tagged CVEs
- Networking Infrastructure1198% of sector-tagged CVEs
- ICS / OT / IoT846% of sector-tagged CVEs
- Security Products735% of sector-tagged CVEs
- Mobile Apps654% of sector-tagged CVEs
- Hardware Firmware614% of sector-tagged CVEs
- Not yet classified77
Which weakness, where
The top weakness classes against the vendors and the sectors that carried them.
The lighter the cell, the more CVEs. Point at one to read it.
| By vendor | 79XSS | 200Information Exposure | 119Memory Buffer Bounds | 20Improper Input Validation | 787Out-of-bounds Write | 352CSRF | 22Path Traversal | 89SQL Injection | 287Improper Authentication | 125Out-of-bounds Read |
|---|---|---|---|---|---|---|---|---|---|---|
| Debian | 3 | 6 | 13 | 9 | 4 | 2 | 1 | 5 | ||
| Red Hat | 4 | 4 | 12 | 11 | 2 | 1 | 3 | 1 | 2 | 7 |
| Canonical | 3 | 4 | 5 | 3 | 1 | 5 | ||||
| Microsoft | 8 | 4 | 16 | 1 | ||||||
| Сообщество Свободного Программного Обеспечения | 5 | 3 | 7 | 3 | 3 | 5 | ||||
| Microsoft Corp | 1 | 7 | 2 | 14 | 1 | |||||
| HP | 9 | 3 | 4 | 1 | 1 | 1 | 2 | 2 | ||
| Ооо «русбитех-астра» | 5 | 3 | 8 | 3 | 2 | 1 | 5 | |||
| Hewlett Packard Enterprise | 9 | 3 | 4 | 2 | 2 | 2 | ||||
| Maven | 2 | 8 | 2 | 1 | 3 | |||||
| IBM | 5 | 9 | 2 | 2 | 2 | 1 | ||||
| 2 | 9 | 4 | 1 |