month report
October 2020
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
October 2020 closed with 1,621 published CVEs. 207 criticals, apple led volume, mostly via macos. Top weakness class — CWE-79 (147 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
1,621
— MoM— YoY
Severity mix
207 / 701
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
4.6%
75 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
1962.3
n=75
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
422
n=14
Detection gap
KEV pressure, no Nuclei coverage
October 2020 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 2apple241 CVE
- KEV 1pulsesecure14 CVE
- KEV 1sonicwall13 CVE
Weakness × Vendor
What's spreading where in October 2020
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS787Out-of-bounds Write20Improper Input Validation125Out-of-bounds Read917Expression Language Injection120Buffer Overflow400Resource Consumption22Path Traversal416Use After Free78OS Command Injectionapple467192613327oracle11111oracle corp.11oracle corporation11microsoft corp66311microsoft66311сообщество свободного программного обеспечения4454215hp1258debian56317netapp4cisco1081124cisco systems inc.1091124
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #21netgear36 CVE
- #24juniper networks30 CVE
- #27netapp inc.28 CVE
- #32nvidia24 CVE
- #41bigbluebutton15 CVE
- #46pulsesecure14 CVE
- #50sonicwall13 CVE
- #62wordpress foundation9 CVE
- #65mitsubishielectric8 CVE
- #66verifone8 CVE
Top vendors
Ranked by distinct CVE count this period.
- 241 CVE21 critCVSS 7.3KEV 2PoC 2macos (166) · mac os x (164) · iphone os (154)
- 173 CVE10 critCVSS 6.1KEV 4Nuclei 12PoC 5mysql (48) · jdk (8) · openjdk (8)
- 164 CVE9 critCVSS 6.0KEV 4Nuclei 12PoC 4mysql server (47) · database (13) · java se (8)
- 160 CVE9 critCVSS 5.9KEV 4Nuclei 12PoC 4mysql server (48) · java se jdk and jre (8) · peoplesoft enterprise pt peopletools (7)
- 91 CVECVSS 7.4Nuclei 2PoC 3windows 10 1909 (51) · windows 10 2004 (51) · windows 10 1903 (50)
- 90 CVECVSS 7.3Nuclei 2PoC 3windows 10 (55) · windows server 2016 (52) · windows 10 version 2004 (51)
- 73 CVE8 critCVSS 6.6Nuclei 10PoC 12debian gnu/linux (66) · linux (7) · cups (4)
- 67 CVE41 critCVSS 9.3Nuclei 1PoC 1intelligent management center (64) · ezmeral container platform (1) · universal cmbd foundation (1)
- 65 CVE8 critCVSS 6.5Nuclei 11PoC 9debian linux (65)
- 58 CVE1 critCVSS 4.8PoC 3oncommand insight (51) · active iq unified manager (49) · oncommand workflow automation (42)
- 56 CVECVSS 7.0KEV 1Nuclei 1PoC 54firepower threat defense (30) · cisco adaptive security appliance (asa) software (20) · adaptive security appliance software (19)
- 56 CVECVSS 6.9KEV 1Nuclei 1PoC 54firepower threat defense (30) · adaptive security appliance (20) · cisco firepower management center (9)
- 55 CVE6 critCVSS 6.6Nuclei 8PoC 7fedora (55)
- 52 CVE2 critCVSS 6.5PoC 1curam spm (9) · curam social program management (9) · security access manager (6)
- 44 CVECVSS 6.0PoC 7осон основа оnyx (44)
- 43 CVE3 critCVSS 6.3PoC 4ос он «стрелец» (43)
- 41 CVE4 critCVSS 6.7Nuclei 2PoC 1org.apache.nifi:nifi (3) · com.barchart.jenkins:maven-release-cascade (2) · org.biouno:uno-choice (2)
- 40 CVE4 critCVSS 7.0Nuclei 2PoC 8electron (2) · npm-user-validate (2) · hermes-engine (2)
- 38 CVE6 critCVSS 6.9PoC 1android (35) · tensorflow (2) · tink java (1)
- 37 CVE3 critCVSS 6.5Nuclei 1PoC 4leap (37) · backports sle (7)
- 36 CVE16 critCVSS 7.5NEWKEV 1Nuclei 1rbr850 firmware (13) · rbs850 firmware (13) · rbk852 firmware (13)
- 34 CVE1 critCVSS 6.5PoC 5альт 8 сп (34)
- 30 CVECVSS 7.0Nuclei 1PoC 27junos (25) · junos os evolved (3) · mist cloud ui (3)
- 30 CVECVSS 7.0NEWNuclei 1PoC 27junos os (25) · junos os evolved (4) · mist cloud ui (3)
- 30 CVE1 critCVSS 6.8PoC 5astra linux special edition (28) · astra linux special edition для «эльбрус» (12) · astra linux common edition (10)
- 28 CVE3 critCVSS 7.3PoC 2firefox (22) · thunderbird (10) · firefox esr (9)
- 28 CVECVSS 5.2NEWsnapcenter (28) · oncommand insight (28) · oncommand workflow automation (28)
- 28 CVE2 critCVSS 6.3PoC 4red hat enterprise linux (23) · openshift container platform (4) · openshift service mesh (1)
- 27 CVE2 critCVSS 6.5PoC 3ubuntu (27)
- 26 CVE6 critCVSS 6.5Nuclei 10PoC 5fedora (26)
- 25 CVE3 critCVSS 8.2Nuclei 1PoC 4opensuse leap (22) · suse linux enterprise server for sap applications (9) · suse linux enterprise server (9)
- 24 CVE2 critCVSS 7.3NEWvirtual gpu manager (11) · nvidia dgx servers (9) · nvidia vgpu software (7)
- 22 CVECVSS 7.3illustrator (7) · animate (4) · after effects (2)
- 21 CVECVSS 7.3illustrator 2020 (7) · animate (4) · adobe after effects (2)
- 21 CVE1 critCVSS 6.3Nuclei 2PoC 7baserproject/basercms (3) · shopware/core (2) · pyrocms/pyrocms (2)
- 21 CVE1 critCVSS 6.1Nuclei 1PoC 23d visual enterprise viewer (6) · commerce cloud (2) · netweaver application server java (2)
- 20 CVE1 critCVSS 6.2Nuclei 1PoC 2sap 3d visual enterprise viewer (6) · sap netweaver application server java (2) · sap commerce cloud (2)
- 19 CVECVSS 5.9taurus-an00b firmware (6) · p30 pro firmware (5) · mate 20 firmware (3)
- 17 CVE2 critCVSS 7.7PoC 1firefox (10) · network security services (6) · firefox esr (5)
- 16 CVECVSS 6.9PoC 1enterprise linux (5) · enterprise linux workstation (4) · enterprise linux desktop (4)
- 15 CVE2 critCVSS 6.7NEWPoC 6bigbluebutton (14) · greenlight (1)
- 15 CVE4 critCVSS 8.0foxit reader (12) · phantompdf (12) · 3d (3)
- 15 CVE1 critCVSS 5.9PoC 2gitlab (14) · gitlab runner (2) · runner (1)
- 15 CVE2 critCVSS 7.1bmc firmware (9) · bios (5) · driver \& support assistant (1)
- 15 CVECVSS 7.2Nuclei 1PoC 15junos (15) · junos os evolved (1)
- 14 CVE1 critCVSS 6.7NEWKEV 1PoC 1pulse secure desktop client (10) · pulse connect secure (4) · pulse policy secure (4)
- 14 CVE3 critCVSS 6.2PoC 3tensorflow (2) · tensorflow-cpu (2) · tensorflow-gpu (2)
- 13 CVE1 critCVSS 6.8Nuclei 2PoC 1nifi (4) · calcite (1) · ant (1)
- 13 CVECVSS 5.6jenkins active choices plugin (2) · jenkins maven cascade release plugin (2) · jenkins audit trail plugin (2)
- 13 CVE1 critCVSS 7.3NEWKEV 1sonicosv (11) · sonicos (11) · global vpn client (2)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | apple | 241 | 21 | 2 | · | KEV 2PoC 2 | macos (166) · mac os x (164) · iphone os (154) | — | |
| 2 | oracle | 173 | 10 | 4 | 12 | KEV 4Nuclei 12PoC 5 | mysql (48) · jdk (8) · openjdk (8) | — | |
| 3 | oracle corp. | 164 | 9 | 4 | 12 | KEV 4Nuclei 12PoC 4 | mysql server (47) · database (13) · java se (8) | — | |
| 4 | oracle corporation | 160 | 9 | 4 | 12 | KEV 4Nuclei 12PoC 4 | mysql server (48) · java se jdk and jre (8) · peoplesoft enterprise pt peopletools (7) | — | |
| 5 | microsoft corp | 91 | · | · | 2 | Nuclei 2PoC 3 | windows 10 1909 (51) · windows 10 2004 (51) · windows 10 1903 (50) | — | |
| 6 | microsoft | 90 | · | · | 2 | Nuclei 2PoC 3 | windows 10 (55) · windows server 2016 (52) · windows 10 version 2004 (51) | — | |
| 7 | сообщество свободного программного обеспечения | 73 | 8 | · | 10 | Nuclei 10PoC 12 | debian gnu/linux (66) · linux (7) · cups (4) | — | |
| 8 | hp | 67 | 41 | · | 1 | Nuclei 1PoC 1 | intelligent management center (64) · ezmeral container platform (1) · universal cmbd foundation (1) | — | |
| 9 | debian | 65 | 8 | · | 11 | Nuclei 11PoC 9 | debian linux (65) | — | |
| 10 | netapp | 58 | 1 | · | · | PoC 3 | oncommand insight (51) · active iq unified manager (49) · oncommand workflow automation (42) | — | |
| 11 | cisco | 56 | · | 1 | 1 | KEV 1Nuclei 1PoC 54 | firepower threat defense (30) · cisco adaptive security appliance (asa) software (20) · adaptive security appliance software (19) | — | |
| 12 | cisco systems inc. | 56 | · | 1 | 1 | KEV 1Nuclei 1PoC 54 | firepower threat defense (30) · adaptive security appliance (20) · cisco firepower management center (9) | — | |
| 13 | fedoraproject | 55 | 6 | · | 8 | Nuclei 8PoC 7 | fedora (55) | — | |
| 14 | ibm | 52 | 2 | · | · | PoC 1 | curam spm (9) · curam social program management (9) · security access manager (6) | — | |
| 15 | ао "нппкт" | 44 | · | · | · | PoC 7 | осон основа оnyx (44) | — | |
| 16 | ао «концерн вниинс» | 43 | 3 | · | · | PoC 4 | ос он «стрелец» (43) | — | |
| 17 | maven | 41 | 4 | · | 2 | Nuclei 2PoC 1 | org.apache.nifi:nifi (3) · com.barchart.jenkins:maven-release-cascade (2) · org.biouno:uno-choice (2) | — | |
| 18 | npm | 40 | 4 | · | 2 | Nuclei 2PoC 8 | electron (2) · npm-user-validate (2) · hermes-engine (2) | — | |
| 19 | 38 | 6 | · | · | PoC 1 | android (35) · tensorflow (2) · tink java (1) | — | ||
| 20 | opensuse | 37 | 3 | · | 1 | Nuclei 1PoC 4 | leap (37) · backports sle (7) | — | |
| 21 | netgear | 36 | 16 | 1 | 1 | NEWKEV 1Nuclei 1 | rbr850 firmware (13) · rbs850 firmware (13) · rbk852 firmware (13) | — | |
| 22 | ао «ивк» | 34 | 1 | · | · | PoC 5 | альт 8 сп (34) | — | |
| 23 | juniper | 30 | · | · | 1 | Nuclei 1PoC 27 | junos (25) · junos os evolved (3) · mist cloud ui (3) | — | |
| 24 | juniper networks | 30 | · | · | 1 | NEWNuclei 1PoC 27 | junos os (25) · junos os evolved (4) · mist cloud ui (3) | — | |
| 25 | ооо «русбитех-астра» | 30 | 1 | · | · | PoC 5 | astra linux special edition (28) · astra linux special edition для «эльбрус» (12) · astra linux common edition (10) | — | |
| 26 | mozilla | 28 | 3 | · | · | PoC 2 | firefox (22) · thunderbird (10) · firefox esr (9) | — | |
| 27 | netapp inc. | 28 | · | · | · | NEW | snapcenter (28) · oncommand insight (28) · oncommand workflow automation (28) | — | |
| 28 | red hat inc. | 28 | 2 | · | · | PoC 4 | red hat enterprise linux (23) · openshift container platform (4) · openshift service mesh (1) | — | |
| 29 | canonical ltd. | 27 | 2 | · | · | PoC 3 | ubuntu (27) | — | |
| 30 | fedora project | 26 | 6 | · | 10 | Nuclei 10PoC 5 | fedora (26) | — | |
| 31 | novell inc. | 25 | 3 | · | 1 | Nuclei 1PoC 4 | opensuse leap (22) · suse linux enterprise server for sap applications (9) · suse linux enterprise server (9) | — | |
| 32 | nvidia | 24 | 2 | · | · | NEW | virtual gpu manager (11) · nvidia dgx servers (9) · nvidia vgpu software (7) | — | |
| 33 | adobe | 22 | · | · | · | illustrator (7) · animate (4) · after effects (2) | — | ||
| 34 | adobe systems inc. | 21 | · | · | · | illustrator 2020 (7) · animate (4) · adobe after effects (2) | — | ||
| 35 | packagist | 21 | 1 | · | 2 | Nuclei 2PoC 7 | baserproject/basercms (3) · shopware/core (2) · pyrocms/pyrocms (2) | — | |
| 36 | sap | 21 | 1 | · | 1 | Nuclei 1PoC 2 | 3d visual enterprise viewer (6) · commerce cloud (2) · netweaver application server java (2) | — | |
| 37 | sap se | 20 | 1 | · | 1 | Nuclei 1PoC 2 | sap 3d visual enterprise viewer (6) · sap netweaver application server java (2) · sap commerce cloud (2) | — | |
| 38 | huawei | 19 | · | · | · | taurus-an00b firmware (6) · p30 pro firmware (5) · mate 20 firmware (3) | — | ||
| 39 | mozilla corp. | 17 | 2 | · | · | PoC 1 | firefox (10) · network security services (6) · firefox esr (5) | — | |
| 40 | redhat | 16 | · | · | · | PoC 1 | enterprise linux (5) · enterprise linux workstation (4) · enterprise linux desktop (4) | — | |
| 41 | bigbluebutton | 15 | 2 | · | · | NEWPoC 6 | bigbluebutton (14) · greenlight (1) | — | |
| 42 | foxitsoftware | 15 | 4 | · | · | foxit reader (12) · phantompdf (12) · 3d (3) | — | ||
| 43 | gitlab | 15 | 1 | · | · | PoC 2 | gitlab (14) · gitlab runner (2) · runner (1) | — | |
| 44 | intel | 15 | 2 | · | · | bmc firmware (9) · bios (5) · driver \& support assistant (1) | — | ||
| 45 | juniper networks inc. | 15 | · | · | 1 | Nuclei 1PoC 15 | junos (15) · junos os evolved (1) | — | |
| 46 | pulsesecure | 14 | 1 | 1 | · | NEWKEV 1PoC 1 | pulse secure desktop client (10) · pulse connect secure (4) · pulse policy secure (4) | — | |
| 47 | pypi | 14 | 3 | · | · | PoC 3 | tensorflow (2) · tensorflow-cpu (2) · tensorflow-gpu (2) | — | |
| 48 | apache | 13 | 1 | · | 2 | Nuclei 2PoC 1 | nifi (4) · calcite (1) · ant (1) | — | |
| 49 | jenkins project | 13 | · | · | · | jenkins active choices plugin (2) · jenkins maven cascade release plugin (2) · jenkins audit trail plugin (2) | — | ||
| 50 | sonicwall | 13 | 1 | 1 | · | NEWKEV 1 | sonicosv (11) · sonicos (11) · global vpn client (2) | — |