month report
January 2020
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
January 2020 closed with 1,984 published CVEs. 247 criticals, oracle led volume, mostly via enterprise manager base platform. Top weakness class — CWE-79 (242 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
1,984
— MoM— YoY
Severity mix
247 / 642
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
5.8%
116 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
2242.2
n=116
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
786
n=7
Weakness × Vendor
What's spreading where in January 2020
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS787Out-of-bounds Write20Improper Input Validation78OS Command Injection200Information Exposure269Improper Privilege Mgmt22Path Traversal352CSRF89SQL Injection125Out-of-bounds Readoracle3411oracle corp.341oracle corporation1сообщество свободного программного обеспечения5216412117ооо «русбитех-астра»518316debian410211124opensuse214219ао «концерн вниинс»517513canonical39113novell inc.314321113redhat693121122red hat inc.513421
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #3oracle corporation203 CVE
- #18gitlab48 CVE
- #22mozilla37 CVE
- #25mozilla corp.34 CVE
- #37jenkins project19 CVE
- #45jetbrains12 CVE
- #46juniper12 CVE
- #47symantec12 CVE
- #49juniper networks11 CVE
- #50juniper networks inc.11 CVE
Top vendors
Ranked by distinct CVE count this period.
- 220 CVE7 critCVSS 6.6KEV 2Nuclei 13PoC 7enterprise manager base platform (40) · vm virtualbox (18) · mysql (16)
- 214 CVE7 critCVSS 6.3KEV 2Nuclei 13PoC 7enterprise manager base platform (28) · vm virtualbox (18) · database server (12)
- 203 CVE5 critCVSS 6.0NEWKEV 2Nuclei 11PoC 4enterprise manager base platform (36) · vm virtualbox (18) · mysql server (15)
- 125 CVE18 critCVSS 7.4KEV 1Nuclei 3PoC 33debian gnu/linux (112) · linux (9) · rconfig (2)
- 81 CVE10 critCVSS 7.3PoC 22astra linux special edition (75) · astra linux special edition для «эльбрус» (23) · astra linux common edition (21)
- 80 CVE14 critCVSS 7.1KEV 1Nuclei 3PoC 15debian linux (80)
- 76 CVE5 critCVSS 6.8Nuclei 2PoC 20leap (59) · backports sle (19) · factory (7)
- 75 CVE8 critCVSS 7.3PoC 22ос он «стрелец» (75)
- 73 CVE8 critCVSS 6.8KEV 1Nuclei 2PoC 16ubuntu linux (73)
- 64 CVE6 critCVSS 6.7Nuclei 1PoC 18opensuse leap (56) · suse linux enterprise server for sap applications (11) · suse linux enterprise server (11)
- 64 CVE8 critCVSS 6.7Nuclei 1PoC 8enterprise linux (23) · enterprise linux workstation (20) · enterprise linux desktop (20)
- 63 CVE7 critCVSS 7.5Nuclei 2PoC 14red hat enterprise linux (53) · red hat software collections (4) · openshift container platform (3)
- 60 CVE2 critCVSS 6.8PoC 16ubuntu (60)
- 59 CVE4 critCVSS 7.7KEV 3Nuclei 1PoC 3windows server (36) · windows server 2016 (36) · windows server 2019 (35)
- 59 CVE2 critCVSS 7.4PoC 18альт 8 сп (59) · альт сп 10 (1)
- 58 CVE4 critCVSS 7.3KEV 3Nuclei 1PoC 3windows server 2019 (34) · windows server 2016 (31) · windows 10 1803 (31)
- 56 CVE8 critCVSS 7.1Nuclei 7PoC 7org.jenkins-ci.main:jenkins-core (9) · org.opencastproject:opencast-kernel (3) · org.apache.cxf:cxf (2)
- 48 CVE4 critCVSS 6.5NEWNuclei 2PoC 2gitlab (48) · gitlab ce/ee (7) · gitlab ee (4)
- 45 CVE9 critCVSS 7.2KEV 1Nuclei 2PoC 11fedora (44) · extra packages for enterprise linux (1) · 389 directory server (1)
- 43 CVE4 critCVSS 6.8PoC 33cisco data center network manager (12) · data center network manager (12) · ios xr (5)
- 42 CVE5 critCVSS 7.2PoC 33cisco data center network manager (12) · cisco ios xr (5) · cisco sd-wan (3)
- 37 CVE1 critCVSS 7.7NEWPoC 11firefox (37) · firefox esr (22) · thunderbird (15)
- 37 CVE5 critCVSS 7.4Nuclei 1PoC 1plone (7) · pillow (5) · ansible (2)
- 35 CVE1 critCVSS 5.6Nuclei 1PoC 3active iq unified manager (26) · oncommand insight (22) · oncommand workflow automation (22)
- 34 CVE1 critCVSS 7.7NEWPoC 11firefox (34) · firefox esr (22) · thunderbird (18)
- 34 CVE6 critCVSS 6.9Nuclei 1PoC 12magento/community-edition (6) · magento/core (3) · dolibarr/dolibarr (3)
- 28 CVE1 critCVSS 6.8PoC 3android (19) · chrome (8) · tensorflow (1)
- 28 CVE11 critCVSS 8.7sm8150 firmware (25) · sxr2130 firmware (23) · sdm845 firmware (23)
- 28 CVE11 critCVSS 8.4snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon iot, snapdragon mobile, snapdragon voice & music, snapdragon wearables (10) · snapdragon auto, snapdragon consumer iot, snapdragon industrial iot, snapdragon mobile, snapdragon voice & music (2) · snapdragon auto, snapdragon consumer iot, snapdragon industrial iot, snapdragon mobile, snapdragon voice & music, snapdragon wearables (2)
- 25 CVE5 critCVSS 7.2Nuclei 1PoC 6осон основа оnyx (25)
- 23 CVE5 critCVSS 7.2Nuclei 1PoC 1jboss portal (2) · quay (2) · jboss eap (2)
- 21 CVE2 critCVSS 6.3Nuclei 1security secret server (8) · mq appliance (3) · qradar security information and event manager (2)
- 21 CVECVSS 6.6Nuclei 2PoC 1jenkins (7) · cloudbees (2) · amazon ec2 (2)
- 21 CVE8 critCVSS 8.1hashbrown-cms (2) · angular-expressions (1) · aws-lambda (1)
- 21 CVECVSS 6.4Nuclei 1PoC 5linux enterprise server (5) · suse linux enterprise server 15 (4) · suse linux enterprise server (3)
- 19 CVE4 critCVSS 7.8PoC 4fedora (19)
- 19 CVECVSS 6.5NEWNuclei 2PoC 1jenkins (7) · jenkins sounds plugin (2) · jenkins amazon ec2 plugin (2)
- 17 CVE4 critCVSS 7.9Nuclei 1magento (6) · illustrator cc (5) · adobe illustrator cc (5)
- 17 CVE5 critCVSS 7.7nifi (2) · cxf (2) · spamassassin (2)
- 16 CVE5 critCVSS 7.9Nuclei 1PoC 2netty (3) · cxf (2) · apache spamassassin (2)
- 16 CVE2 critCVSS 6.3PoC 3sgi tempo (3) · simplivity 380 gen10 g firmware (2) · simplivity 380 gen9 firmware (2)
- 15 CVE1 critCVSS 6.9Nuclei 1dp300 firmware (2) · mate 20 firmware (2) · rp200 firmware (2)
- 15 CVECVSS 6.8PoC 4linux kernel (8) · tizen (7) · kernel (1)
- 13 CVE2 critCVSS 7.8PoC 5libredwg (7) · coreutils (2) · cpio (1)
- 12 CVECVSS 6.5NEWteamcity (4) · intellij idea (3) · youtrack (2)
- 12 CVECVSS 7.2NEWPoC 9junos (11) · junos space (1)
- 12 CVECVSS 7.0NEWPoC 1norton mobile security for android (3) · it management suite (3) · norton mobile security (3)
- 11 CVE5 critCVSS 7.2PoC 7dcs-2102 firmware (5) · dcs-2121 firmware (5) · dir-859 firmware (4)
- 11 CVECVSS 7.4NEWPoC 9junos os (10) · junos os evolved (3) · junos space (1)
- 11 CVECVSS 7.3NEWPoC 9junos (10) · junos os evolved (1) · junos space (1)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | oracle | 220 | 7 | 2 | 13 | KEV 2Nuclei 13PoC 7 | enterprise manager base platform (40) · vm virtualbox (18) · mysql (16) | — | |
| 2 | oracle corp. | 214 | 7 | 2 | 13 | KEV 2Nuclei 13PoC 7 | enterprise manager base platform (28) · vm virtualbox (18) · database server (12) | — | |
| 3 | oracle corporation | 203 | 5 | 2 | 11 | NEWKEV 2Nuclei 11PoC 4 | enterprise manager base platform (36) · vm virtualbox (18) · mysql server (15) | — | |
| 4 | сообщество свободного программного обеспечения | 125 | 18 | 1 | 3 | KEV 1Nuclei 3PoC 33 | debian gnu/linux (112) · linux (9) · rconfig (2) | — | |
| 5 | ооо «русбитех-астра» | 81 | 10 | · | · | PoC 22 | astra linux special edition (75) · astra linux special edition для «эльбрус» (23) · astra linux common edition (21) | — | |
| 6 | debian | 80 | 14 | 1 | 3 | KEV 1Nuclei 3PoC 15 | debian linux (80) | — | |
| 7 | opensuse | 76 | 5 | · | 2 | Nuclei 2PoC 20 | leap (59) · backports sle (19) · factory (7) | — | |
| 8 | ао «концерн вниинс» | 75 | 8 | · | · | PoC 22 | ос он «стрелец» (75) | — | |
| 9 | canonical | 73 | 8 | 1 | 2 | KEV 1Nuclei 2PoC 16 | ubuntu linux (73) | — | |
| 10 | novell inc. | 64 | 6 | · | 1 | Nuclei 1PoC 18 | opensuse leap (56) · suse linux enterprise server for sap applications (11) · suse linux enterprise server (11) | — | |
| 11 | redhat | 64 | 8 | · | 1 | Nuclei 1PoC 8 | enterprise linux (23) · enterprise linux workstation (20) · enterprise linux desktop (20) | — | |
| 12 | red hat inc. | 63 | 7 | · | 2 | Nuclei 2PoC 14 | red hat enterprise linux (53) · red hat software collections (4) · openshift container platform (3) | — | |
| 13 | canonical ltd. | 60 | 2 | · | · | PoC 16 | ubuntu (60) | — | |
| 14 | microsoft | 59 | 4 | 3 | 1 | KEV 3Nuclei 1PoC 3 | windows server (36) · windows server 2016 (36) · windows server 2019 (35) | — | |
| 15 | ао «ивк» | 59 | 2 | · | · | PoC 18 | альт 8 сп (59) · альт сп 10 (1) | — | |
| 16 | microsoft corp | 58 | 4 | 3 | 1 | KEV 3Nuclei 1PoC 3 | windows server 2019 (34) · windows server 2016 (31) · windows 10 1803 (31) | — | |
| 17 | maven | 56 | 8 | · | 7 | Nuclei 7PoC 7 | org.jenkins-ci.main:jenkins-core (9) · org.opencastproject:opencast-kernel (3) · org.apache.cxf:cxf (2) | — | |
| 18 | gitlab | 48 | 4 | · | 2 | NEWNuclei 2PoC 2 | gitlab (48) · gitlab ce/ee (7) · gitlab ee (4) | — | |
| 19 | fedoraproject | 45 | 9 | 1 | 2 | KEV 1Nuclei 2PoC 11 | fedora (44) · extra packages for enterprise linux (1) · 389 directory server (1) | — | |
| 20 | cisco | 43 | 4 | · | · | PoC 33 | cisco data center network manager (12) · data center network manager (12) · ios xr (5) | — | |
| 21 | cisco systems inc. | 42 | 5 | · | · | PoC 33 | cisco data center network manager (12) · cisco ios xr (5) · cisco sd-wan (3) | — | |
| 22 | mozilla | 37 | 1 | · | · | NEWPoC 11 | firefox (37) · firefox esr (22) · thunderbird (15) | — | |
| 23 | pypi | 37 | 5 | · | 1 | Nuclei 1PoC 1 | plone (7) · pillow (5) · ansible (2) | — | |
| 24 | netapp | 35 | 1 | · | 1 | Nuclei 1PoC 3 | active iq unified manager (26) · oncommand insight (22) · oncommand workflow automation (22) | — | |
| 25 | mozilla corp. | 34 | 1 | · | · | NEWPoC 11 | firefox (34) · firefox esr (22) · thunderbird (18) | — | |
| 26 | packagist | 34 | 6 | · | 1 | Nuclei 1PoC 12 | magento/community-edition (6) · magento/core (3) · dolibarr/dolibarr (3) | — | |
| 27 | 28 | 1 | · | · | PoC 3 | android (19) · chrome (8) · tensorflow (1) | — | ||
| 28 | qualcomm | 28 | 11 | · | · | sm8150 firmware (25) · sxr2130 firmware (23) · sdm845 firmware (23) | — | ||
| 29 | qualcomm, inc. | 28 | 11 | · | · | snapdragon auto, snapdragon compute, snapdragon connectivity, snapdragon consumer iot, snapdragon industrial iot, snapdragon iot, snapdragon mobile, snapdragon voice & music, snapdragon wearables (10) · snapdragon auto, snapdragon consumer iot, snapdragon industrial iot, snapdragon mobile, snapdragon voice & music (2) · snapdragon auto, snapdragon consumer iot, snapdragon industrial iot, snapdragon mobile, snapdragon voice & music, snapdragon wearables (2) | — | ||
| 30 | ао "нппкт" | 25 | 5 | · | 1 | Nuclei 1PoC 6 | осон основа оnyx (25) | — | |
| 31 | red hat | 23 | 5 | · | 1 | Nuclei 1PoC 1 | jboss portal (2) · quay (2) · jboss eap (2) | — | |
| 32 | ibm | 21 | 2 | · | 1 | Nuclei 1 | security secret server (8) · mq appliance (3) · qradar security information and event manager (2) | — | |
| 33 | jenkins | 21 | · | · | 2 | Nuclei 2PoC 1 | jenkins (7) · cloudbees (2) · amazon ec2 (2) | — | |
| 34 | npm | 21 | 8 | · | · | hashbrown-cms (2) · angular-expressions (1) · aws-lambda (1) | — | ||
| 35 | suse | 21 | · | · | 1 | Nuclei 1PoC 5 | linux enterprise server (5) · suse linux enterprise server 15 (4) · suse linux enterprise server (3) | — | |
| 36 | fedora project | 19 | 4 | · | · | PoC 4 | fedora (19) | — | |
| 37 | jenkins project | 19 | · | · | 2 | NEWNuclei 2PoC 1 | jenkins (7) · jenkins sounds plugin (2) · jenkins amazon ec2 plugin (2) | — | |
| 38 | adobe | 17 | 4 | · | 1 | Nuclei 1 | magento (6) · illustrator cc (5) · adobe illustrator cc (5) | — | |
| 39 | apache | 17 | 5 | · | · | nifi (2) · cxf (2) · spamassassin (2) | — | ||
| 40 | apache software foundation | 16 | 5 | · | 1 | Nuclei 1PoC 2 | netty (3) · cxf (2) · apache spamassassin (2) | — | |
| 41 | hp | 16 | 2 | · | · | PoC 3 | sgi tempo (3) · simplivity 380 gen10 g firmware (2) · simplivity 380 gen9 firmware (2) | — | |
| 42 | huawei | 15 | 1 | · | 1 | Nuclei 1 | dp300 firmware (2) · mate 20 firmware (2) · rp200 firmware (2) | — | |
| 43 | linux | 15 | · | · | · | PoC 4 | linux kernel (8) · tizen (7) · kernel (1) | — | |
| 44 | gnu | 13 | 2 | · | · | PoC 5 | libredwg (7) · coreutils (2) · cpio (1) | — | |
| 45 | jetbrains | 12 | · | · | · | NEW | teamcity (4) · intellij idea (3) · youtrack (2) | — | |
| 46 | juniper | 12 | · | · | · | NEWPoC 9 | junos (11) · junos space (1) | — | |
| 47 | symantec | 12 | · | · | · | NEWPoC 1 | norton mobile security for android (3) · it management suite (3) · norton mobile security (3) | — | |
| 48 | dlink | 11 | 5 | · | · | PoC 7 | dcs-2102 firmware (5) · dcs-2121 firmware (5) · dir-859 firmware (4) | — | |
| 49 | juniper networks | 11 | · | · | · | NEWPoC 9 | junos os (10) · junos os evolved (3) · junos space (1) | — | |
| 50 | juniper networks inc. | 11 | · | · | · | NEWPoC 9 | junos (10) · junos os evolved (1) · junos space (1) | — |