February 2020
1,491 CVEs published, −25% on January 2020 and +64% on February 2019. CISA added 0 to KEV.
2020 month by month
| Year | Jan | Feb | Mar | Apr | May | Jun | Jul | Aug | Sep | Oct | Nov | Dec | Year total |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2020 | January 2020: 1,984 CVEs | February 2020: 1,491 CVEs | March 2020: 1,810 CVEs | April 2020: no snapshot | May 2020: no snapshot | June 2020: 1,894 CVEs | July 2020: no snapshot | August 2020: 1,297 CVEs | September 2020: 2,258 CVEs | October 2020: 1,621 CVEs | November 2020: 1,485 CVEs | December 2020: 1,618 CVEs | 15,4589 of 12 months9/12 |
- Critical
- 22716% of the 1,403 with a CVSS score
- Added to CISA KEV
- 016 of this month's CVEs are in KEV, listed a median 636.5 days after publication
- Vendors
- 6613,021 products
- Top weakness
- XSSCWE-79 · 165 CVEs
Who drove it
Vendors by distinct CVEs this month, with how many of those CVEs are now in CISA KEV and how far each moved in the ranking.
- 1MicrosoftWindows Server 2016, Windows 10, Windows Server 201910104new
- 2Сообщество Свободного Программного ОбеспеченияDebian Gnu/linux, Linux, Coturn84102new
- 3DebianDebian Linux, X11-COMMON80122new
- 4OpensuseLeap, Backports Sle, Backports7951new
- 5Red HatRed Hat Enterprise Linux, Enterprise Linux Workstation, Enterprise Linux Server77121new
- 6FedoraprojectFedora, Extra Packages For Enterprise Linux72112new
- 7GoogleChrome, Google Chrome, Android6711new
- 8Ооо «русбитех-астра»Astra Linux Special Edition, Astra Linux Common Edition, Astra Linux Special Edition Для «эльбрус»6752new
- 9CanonicalUbuntu, Ubuntu Linux, Apport643nonenew
- 10IBMSpectrum Protect Plus, Security Directory Server, DB2 For Linux- Unix and Windows538nonenew
- 11Novell Inc.Opensuse Leap, Suse Package Hub For Suse Linux Enterprise, Suse Linux Enterprise Server For Sap Applications5241new
- 12AppleiPhone OS, iPadOS, IOS5111new
- 13Ао «ивк»Альт 8 Сп4931new
- 14Ао «концерн Вниинс»Ос Он «стрелец»4942new
- 15CiscoNX-OS, Linksys E4200 Firmware, Ucs Manager4622new
- 16AdobeAdobe Framemaker, Framemaker, Adobe Acrobat 20154514nonenew
- 17Fedora ProjectFedora4241new
- 18MavenOrg.apache.tomcat.embed:tomcat-embed-core, Org.jenkins-ci.plugins:pipeline-githubnotify-step, Org.apache.tomcat:tomcat4041new
- 19npmAUTH0-LOCK, Bodymen, Codecov3717nonenew
- 20HuaweiSecospace USG6600 Firmware, USG9500 Firmware, NIP6800 Firmware341nonenew
- 21JenkinsJenkins Pipeline GitHub Notify Step Plugin, Pipeline GitHub Notify Step, Git Parameter260nonenew
- 22SusePackage Hub, Suse Linux Enterprise Server, Suse Linux Enterprise Server 12230nonenew
- 23NextcloudNextcloud Server, Nextcloud, Talk210nonenew
- 24FoxitsoftwarePhantompdf, Reader180nonenew
- 25GitLabGitLab181nonenew
Severity
How this month's CVEs score on CVSS; 88 have no score yet. Severity is not exploitation.
- Critical227
- High614
- Medium538
- Low24
New in the top 100
Not in the top 100 in any of the 24 months before.
What kind of weakness
Weakness classes (CWE) by distinct CVEs, with how far each moved in the ranking.
- CWE-79XSS165
- CWE-787Out-of-bounds Write118
- CWE-20Improper Input Validation67
- CWE-78OS Command Injection61
- CWE-352CSRF53
- CWE-287Improper Authentication46
- CWE-125Out-of-bounds Read45
- CWE-89SQL Injection45
- CWE-200Information Exposure44
- CWE-416Use After Free29
- CWE-22Path Traversal28
- CWE-400Resource Consumption26
- CWE-74Injection24
- CWE-120Buffer Overflow23
- CWE-522Insufficiently Protected Credentials21
- CWE-434Unrestricted File Upload16
- CWE-276Incorrect Default Permissions15
- CWE-798Hard-coded Credentials15
- CWE-269Improper Privilege Mgmt13
- CWE-862Missing Authorization12
Where it landed
The month's CVEs by the sector of the software they affect. A CVE that touches several sectors counts in each.
- Operating Systems33619% of sector-tagged CVEs
- Enterprise Software20111% of sector-tagged CVEs
- OSS Libraries20011% of sector-tagged CVEs
- Mobile Apps1579% of sector-tagged CVEs
- Web & CMS Plugins1569% of sector-tagged CVEs
- Networking Infrastructure1378% of sector-tagged CVEs
- Security Products1026% of sector-tagged CVEs
- Consumer Software1016% of sector-tagged CVEs
- Hardware Firmware744% of sector-tagged CVEs
- 6 smaller sectors258
- Not yet classified75
Which weakness, where
The top weakness classes against the vendors and the sectors that carried them.
The lighter the cell, the more CVEs. Point at one to read it.
| By vendor | 79XSS | 787Out-of-bounds Write | 20Improper Input Validation | 78OS Command Injection | 352CSRF | 287Improper Authentication | 125Out-of-bounds Read | 89SQL Injection | 200Information Exposure | 416Use After Free |
|---|---|---|---|---|---|---|---|---|---|---|
| Microsoft | 2 | 8 | 2 | 1 | 1 | 1 | ||||
| Microsoft Corp | 2 | 8 | 2 | 1 | 1 | 1 | ||||
| Сообщество Свободного Программного Обеспечения | 3 | 10 | 8 | 2 | 11 | 1 | 7 | |||
| Debian | 3 | 7 | 4 | 2 | 6 | 2 | 7 | |||
| Opensuse | 4 | 9 | 10 | 2 | 5 | 4 | ||||
| Fedoraproject | 2 | 8 | 5 | 4 | 5 | 1 | 7 | |||
| Ооо «русбитех-астра» | 3 | 10 | 8 | 1 | 6 | 1 | 3 | |||
| 2 | 14 | 7 | 2 | 3 | 7 | |||||
| Red Hat | 3 | 4 | 6 | 1 | 1 | 2 | 4 | |||
| IBM | 4 | 1 | 5 | 2 | 1 | 4 | 1 | |||
| Novell Inc. | 8 | 8 | 1 | 6 | 5 | |||||
| Apple | 1 | 15 | 6 | 6 | 1 |