month report
December 2020
Data as of Jun 4, 2026, 13:25 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
December 2020 closed with 1,618 published CVEs. 292 criticals, сообщество свободного программного обеспечения led volume, mostly via debian gnu/linux. Top weakness class — CWE-79 (198 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
1,618
— MoM— YoY
Severity mix
292 / 573
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
4.4%
71 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
1904.1
n=71
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
330
n=9
Detection gap
KEV pressure, no Nuclei coverage
December 2020 · vendors with active exploitation listed by CISA but no public detection template.
- KEV 3apple68 CVE
- KEV 3apple inc.13 CVE
- KEV 1microsoft61 CVE
- KEV 1microsoft corp57 CVE
- KEV 1fedora project27 CVE
Weakness × Vendor
What's spreading where in December 2020
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
79XSS787Out-of-bounds Write125Out-of-bounds Read89SQL Injection416Use After Free20Improper Input Validation78OS Command Injection862Missing Authorization190Integer Overflow306Missing Auth for Critical Func…сообщество свободного программного обеспечения61281163324google223194143debian464181222crates.io64141ооо «русбитех-астра»17714124apple11288121netgear38111ао "нппкт"58419124ао «концерн вниинс»35312121microsoft21fedoraproject84361122microsoft corp11
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #4crates.io85 CVE
- #7netgear66 CVE
- #32huawei17 CVE
- #35qnap16 CVE
- #36qnap systems inc.16 CVE
- #38docker14 CVE
- #39hcltech14 CVE
- #43trend micro13 CVE
- #44trendmicro13 CVE
- #48solarwinds12 CVE
Top vendors
Ranked by distinct CVE count this period.
- 130 CVE4 critCVSS 6.2KEV 1Nuclei 2PoC 25debian gnu/linux (110) · linux (13) · mediawiki (5)
- 117 CVE7 critCVSS 6.2PoC 1android (96) · asylo (10) · tensorflow (6)
- 96 CVE3 critCVSS 5.7KEV 1Nuclei 3PoC 22debian linux (94) · advanced package tool (2)
- 85 CVE31 critCVSS 7.6NEWPoC 15rusqlite (8) · lock_api (5) · arr (3)
- 80 CVECVSS 5.0PoC 17astra linux special edition (73) · astra linux special edition для «эльбрус» (48) · astra linux common edition (36)
- 68 CVECVSS 7.0KEV 3PoC 6macos (57) · iphone os (44) · ipados (43)
- 66 CVE4 critCVSS 7.4NEWNuclei 1PoC 1r7800 firmware (46) · r9000 firmware (42) · r8900 firmware (42)
- 66 CVECVSS 6.3Nuclei 1PoC 10осон основа оnyx (66)
- 62 CVECVSS 5.4Nuclei 1PoC 16ос он «стрелец» (62)
- 61 CVE2 critCVSS 7.2KEV 1PoC 2windows server 2016 (22) · windows 10 (21) · windows server version 20h2 (20)
- 58 CVE2 critCVSS 6.1KEV 1Nuclei 5PoC 8fedora (58) · extra packages for enterprise linux (1)
- 57 CVE2 critCVSS 7.2KEV 1windows server 2004 (server core installation) (20) · windows server 2019 (20) · windows server 20h2 (server core installation) (20)
- 35 CVE7 critCVSS 7.2KEV 1Nuclei 7PoC 5com.fasterxml.jackson.core:jackson-databind (4) · com.thoughtworks.xstream:xstream (2) · io.jenkins.plugins:chaos-monkey (2)
- 34 CVECVSS 4.5PoC 14imagemagick (34)
- 34 CVE4 critCVSS 6.5Nuclei 1PoC 4cloud backup (8) · ontap select deploy administration utility (6) · solidfire baseboard management controller firmware (6)
- 33 CVE14 critCVSS 8.1PoC 10multi-ini (2) · corenlp-js-interface (1) · corenlp-js-prefab (1)
- 32 CVE1 critCVSS 6.2Nuclei 2PoC 6enterprise linux (22) · openshift container platform (5) · keycloak (2)
- 31 CVECVSS 4.4PoC 13imagemagick (31)
- 30 CVE1 critCVSS 6.7Nuclei 1PoC 5tensorflow-cpu (6) · tensorflow (6) · tensorflow-gpu (6)
- 30 CVECVSS 6.1PoC 8red hat enterprise linux (20) · openshift container platform (3) · red hat openshift container platform (3)
- 29 CVE1 critCVSS 7.0KEV 1Nuclei 2PoC 5communications cloud native core policy (9) · peoplesoft enterprise peopletools (7) · zfs storage appliance kit (7)
- 27 CVECVSS 6.2KEV 1PoC 5fedora (27)
- 27 CVE2 critCVSS 6.6Nuclei 4PoC 9moodle/moodle (5) · shopware/platform (3) · shopware/core (3)
- 27 CVE1 critCVSS 7.2PoC 2logo\! 8 bm firmware (8) · logo! 8 bm (incl. siplus variants) (8) · xhq (7)
- 25 CVE2 critCVSS 6.1financial transaction manager (6) · financial transaction manager for multiplatform (5) · security secret server (4)
- 24 CVE4 critCVSS 6.7Nuclei 1PoC 3github.com/dhowden/tag (4) · github.com/kubernetes/kubernetes (3) · k8s.io/kubernetes (2)
- 24 CVE1 critCVSS 6.8Nuclei 1PoC 9opensuse leap (19) · suse linux enterprise server (16) · suse linux enterprise server for sap applications (10)
- 22 CVE4 critCVSS 7.6modicon m340 bmxp342000 firmware (10) · modicon m340 bmxp3420302 firmware (10) · modicon m340 bmxp3420102 firmware (10)
- 21 CVE6 critCVSS 7.3KEV 1Nuclei 6PoC 3airflow (4) · struts (3) · nuttx (2)
- 21 CVE2 critCVSS 7.0big-ip access policy manager (11) · big-ip advanced firewall manager (8) · big-ip domain name system (8)
- 21 CVECVSS 7.0PoC 1firefox (20) · thunderbird (12) · firefox esr (11)
- 17 CVECVSS 7.3NEWcloudengine 5800 firmware (4) · cloudengine 6800 firmware (4) · cloudengine 12800 firmware (4)
- 17 CVECVSS 6.3PoC 3альт 8 сп (17)
- 16 CVE4 critCVSS 7.0KEV 1Nuclei 5PoC 2apache airflow (4) · apache nuttx (incubating) (2) · apache apisix (1)
- 16 CVE3 critCVSS 7.0NEWqts (9) · quts hero (7) · qes (4)
- 16 CVE3 critCVSS 7.0NEWqts (9) · quts hero (7) · qes (4)
- 15 CVECVSS 6.5xen (14) · xapi (1)
- 14 CVE13 critCVSS 9.5NEWPoC 13adminer (1) · composer docker image (1) · crux linux docker image (1)
- 14 CVE4 critCVSS 7.5NEWdomino (6) · notes (4) · hcl inotes (2)
- 14 CVE4 critCVSS 8.4modicon quantum (5) · modicon premium (5) · modicon quantum with integrated ethernet copro (5)
- 13 CVECVSS 7.4KEV 3PoC 3watchos (12) · ipados (12) · macos (12)
- 13 CVE1 critCVSS 6.5odoo (13) · odoo community (13) · odoo enterprise (13)
- 13 CVE2 critCVSS 6.1NEWPoC 2trend micro interscan web security virtual appliance (7) · trend micro officescan (5) · apex one (5)
- 13 CVE2 critCVSS 6.3NEWPoC 2interscan web security virtual appliance (7) · apex one (5) · officescan (5)
- 12 CVECVSS 6.9PoC 3linux kernel (12)
- 12 CVE4 critCVSS 7.5Nuclei 2PoC 5solution manager (3) · netweaver application server java (3) · netweaver application server abap (2)
- 12 CVE4 critCVSS 7.5Nuclei 2PoC 5sap solution manager (user experience monitoring) (2) · sap business warehouse (1) · sap bw4hana (1)
- 12 CVE1 critCVSS 7.3NEWKEV 1Nuclei 1PoC 1n-central (6) · webhelpdesk (3) · help desk (1)
- 12 CVECVSS 6.4xen (12)
- 11 CVECVSS 7.1PoC 1ubuntu (11)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | сообщество свободного программного обеспечения | 130 | 4 | 1 | 2 | KEV 1Nuclei 2PoC 25 | debian gnu/linux (110) · linux (13) · mediawiki (5) | — | |
| 2 | 117 | 7 | · | · | PoC 1 | android (96) · asylo (10) · tensorflow (6) | — | ||
| 3 | debian | 96 | 3 | 1 | 3 | KEV 1Nuclei 3PoC 22 | debian linux (94) · advanced package tool (2) | — | |
| 4 | crates.io | 85 | 31 | · | · | NEWPoC 15 | rusqlite (8) · lock_api (5) · arr (3) | — | |
| 5 | ооо «русбитех-астра» | 80 | · | · | · | PoC 17 | astra linux special edition (73) · astra linux special edition для «эльбрус» (48) · astra linux common edition (36) | — | |
| 6 | apple | 68 | · | 3 | · | KEV 3PoC 6 | macos (57) · iphone os (44) · ipados (43) | — | |
| 7 | netgear | 66 | 4 | · | 1 | NEWNuclei 1PoC 1 | r7800 firmware (46) · r9000 firmware (42) · r8900 firmware (42) | — | |
| 8 | ао "нппкт" | 66 | · | · | 1 | Nuclei 1PoC 10 | осон основа оnyx (66) | — | |
| 9 | ао «концерн вниинс» | 62 | · | · | 1 | Nuclei 1PoC 16 | ос он «стрелец» (62) | — | |
| 10 | microsoft | 61 | 2 | 1 | · | KEV 1PoC 2 | windows server 2016 (22) · windows 10 (21) · windows server version 20h2 (20) | — | |
| 11 | fedoraproject | 58 | 2 | 1 | 5 | KEV 1Nuclei 5PoC 8 | fedora (58) · extra packages for enterprise linux (1) | — | |
| 12 | microsoft corp | 57 | 2 | 1 | · | KEV 1 | windows server 2004 (server core installation) (20) · windows server 2019 (20) · windows server 20h2 (server core installation) (20) | — | |
| 13 | maven | 35 | 7 | 1 | 7 | KEV 1Nuclei 7PoC 5 | com.fasterxml.jackson.core:jackson-databind (4) · com.thoughtworks.xstream:xstream (2) · io.jenkins.plugins:chaos-monkey (2) | — | |
| 14 | imagemagick | 34 | · | · | · | PoC 14 | imagemagick (34) | — | |
| 15 | netapp | 34 | 4 | · | 1 | Nuclei 1PoC 4 | cloud backup (8) · ontap select deploy administration utility (6) · solidfire baseboard management controller firmware (6) | — | |
| 16 | npm | 33 | 14 | · | · | PoC 10 | multi-ini (2) · corenlp-js-interface (1) · corenlp-js-prefab (1) | — | |
| 17 | redhat | 32 | 1 | · | 2 | Nuclei 2PoC 6 | enterprise linux (22) · openshift container platform (5) · keycloak (2) | — | |
| 18 | imagemagick studio llc | 31 | · | · | · | PoC 13 | imagemagick (31) | — | |
| 19 | pypi | 30 | 1 | · | 1 | Nuclei 1PoC 5 | tensorflow-cpu (6) · tensorflow (6) · tensorflow-gpu (6) | — | |
| 20 | red hat inc. | 30 | · | · | · | PoC 8 | red hat enterprise linux (20) · openshift container platform (3) · red hat openshift container platform (3) | — | |
| 21 | oracle | 29 | 1 | 1 | 2 | KEV 1Nuclei 2PoC 5 | communications cloud native core policy (9) · peoplesoft enterprise peopletools (7) · zfs storage appliance kit (7) | — | |
| 22 | fedora project | 27 | · | 1 | · | KEV 1PoC 5 | fedora (27) | — | |
| 23 | packagist | 27 | 2 | · | 4 | Nuclei 4PoC 9 | moodle/moodle (5) · shopware/platform (3) · shopware/core (3) | — | |
| 24 | siemens | 27 | 1 | · | · | PoC 2 | logo\! 8 bm firmware (8) · logo! 8 bm (incl. siplus variants) (8) · xhq (7) | — | |
| 25 | ibm | 25 | 2 | · | · | financial transaction manager (6) · financial transaction manager for multiplatform (5) · security secret server (4) | — | ||
| 26 | go | 24 | 4 | · | 1 | Nuclei 1PoC 3 | github.com/dhowden/tag (4) · github.com/kubernetes/kubernetes (3) · k8s.io/kubernetes (2) | — | |
| 27 | novell inc. | 24 | 1 | · | 1 | Nuclei 1PoC 9 | opensuse leap (19) · suse linux enterprise server (16) · suse linux enterprise server for sap applications (10) | — | |
| 28 | schneider-electric | 22 | 4 | · | · | modicon m340 bmxp342000 firmware (10) · modicon m340 bmxp3420302 firmware (10) · modicon m340 bmxp3420102 firmware (10) | — | ||
| 29 | apache | 21 | 6 | 1 | 6 | KEV 1Nuclei 6PoC 3 | airflow (4) · struts (3) · nuttx (2) | — | |
| 30 | f5 | 21 | 2 | · | · | big-ip access policy manager (11) · big-ip advanced firewall manager (8) · big-ip domain name system (8) | — | ||
| 31 | mozilla | 21 | · | · | · | PoC 1 | firefox (20) · thunderbird (12) · firefox esr (11) | — | |
| 32 | huawei | 17 | · | · | · | NEW | cloudengine 5800 firmware (4) · cloudengine 6800 firmware (4) · cloudengine 12800 firmware (4) | — | |
| 33 | ао «ивк» | 17 | · | · | · | PoC 3 | альт 8 сп (17) | — | |
| 34 | apache software foundation | 16 | 4 | 1 | 5 | KEV 1Nuclei 5PoC 2 | apache airflow (4) · apache nuttx (incubating) (2) · apache apisix (1) | — | |
| 35 | qnap | 16 | 3 | · | · | NEW | qts (9) · quts hero (7) · qes (4) | — | |
| 36 | qnap systems inc. | 16 | 3 | · | · | NEW | qts (9) · quts hero (7) · qes (4) | — | |
| 37 | xen | 15 | · | · | · | xen (14) · xapi (1) | — | ||
| 38 | docker | 14 | 13 | · | · | NEWPoC 13 | adminer (1) · composer docker image (1) · crux linux docker image (1) | — | |
| 39 | hcltech | 14 | 4 | · | · | NEW | domino (6) · notes (4) · hcl inotes (2) | — | |
| 40 | schneider electric | 14 | 4 | · | · | modicon quantum (5) · modicon premium (5) · modicon quantum with integrated ethernet copro (5) | — | ||
| 41 | apple inc. | 13 | · | 3 | · | KEV 3PoC 3 | watchos (12) · ipados (12) · macos (12) | — | |
| 42 | odoo | 13 | 1 | · | · | odoo (13) · odoo community (13) · odoo enterprise (13) | — | ||
| 43 | trend micro | 13 | 2 | · | · | NEWPoC 2 | trend micro interscan web security virtual appliance (7) · trend micro officescan (5) · apex one (5) | — | |
| 44 | trendmicro | 13 | 2 | · | · | NEWPoC 2 | interscan web security virtual appliance (7) · apex one (5) · officescan (5) | — | |
| 45 | linux | 12 | · | · | · | PoC 3 | linux kernel (12) | — | |
| 46 | sap | 12 | 4 | · | 2 | Nuclei 2PoC 5 | solution manager (3) · netweaver application server java (3) · netweaver application server abap (2) | — | |
| 47 | sap se | 12 | 4 | · | 2 | Nuclei 2PoC 5 | sap solution manager (user experience monitoring) (2) · sap business warehouse (1) · sap bw4hana (1) | — | |
| 48 | solarwinds | 12 | 1 | 1 | 1 | NEWKEV 1Nuclei 1PoC 1 | n-central (6) · webhelpdesk (3) · help desk (1) | — | |
| 49 | the linux foundation | 12 | · | · | · | xen (12) | — | ||
| 50 | canonical ltd. | 11 | · | · | · | PoC 1 | ubuntu (11) | — |