CVE Intelligence
Skip to main content

Month report

February 2020

Rolled up 2026-08-09 20:45 from 381,136 CVE records

1,397 CVEs published, +66.7% on the same month last year. 32 rated critical, 0 listed by CISA as exploited. microsoft led with 99; the most common weakness class was CWE-79 (19). d link climbed 47 places, the largest move. 9 vendors ranked for the first time.

Published

1,397

-15.6%on the previous month

Critical / high

32 / 109

of the 259 scored

Medium / low

110 / 8

the rest of the scored bands

Added to CISA KEV

0

listed as exploited this month

Public exploit

154

exploit code indexed publicly

Scanner template

0

0% of the month

Publication to KEV

How long before CISA listed them

16 published this month and listed since — not the 0 listed during it.

Median days to listing

636.5

from publication to CISA's date added

Listed within 7 days

0%

of the 16

Listed within 30 days

0%

of the 16

Weakness × vendor

Where the two overlap

CVEs carrying both. Each row is shaded against its own worst class.
VendorCWE-79CWE-78CWE-787CWE-20CWE-284CWE-125CWE-400CWE-416
microsoft21
ibm
apple1
google
adobe1
cisco641611
jenkins project
huawei

Vendors

Ranked by distinct CVEs this month

Δ is the move against last month's rank.
Vendors ranked by distinct CVEs published in 2020-02, sorted by CVEs descending
#VendorTop products
1microsoft99148windows (77) · windows server (77) · windows 10 version 1909 for x64 based systems (74)↑1
2ibm525security directory server (6) · spectrum protect plus (6) · db2 for linux unix and windows (5)↑5
3apple4712ios (31) · macos (26) · tvos (21)·
4google4612chrome (42) · android (4)↑13
5adobe441adobe framemaker (21) · adobe acrobat and reader (17) · adobe digital editions (2)↑4
6cisco36122cisco data center network manager (3) · cisco unified computing system managed (3) · cisco adaptive security appliance asa software (2)↓3
7jenkins project26jenkins pipeline github notify step plugin (3) · jenkins git parameter plugin (2) · jenkins harvest scm plugin (2)↑1
8huawei22nip6800 (9) · secospace usg6600 usg9500 (5) · secospace usg6600 (4)↑29
9foxit18phantompdf (10) · reader (8)·
10qualcomm142snapdragon auto snapdragon compute snapdragon connectivity snapdragon consumer iot snapdragon industrial iot snapdragon iot snapdragon mobile snapdragon voice music snapdragon wearables (2) · snapdragon auto snapdragon compute snapdragon consumer electronics connectivity snapdragon consumer iot snapdragon industrial iot snapdragon mobile snapdragon voice music (2) · snapdragon auto snapdragon compute snapdragon consumer iot snapdragon industrial iot snapdragon iot snapdragon mobile snapdragon voice music snapdragon wearables (2)↓5
11sap se13sap host agent (2) · sap landscape management (2) · sap netweaver sap basis (2)↑16
12atlassian12jira server (9) · application links (1) · confluence data center (1)↑22
13apache7112apache tomcat (3) · apache jclouds (1) · apache kylin (1)↓2
14changing61servisign windows versions (3) · syuan gu da shih (3)new
15joomla62joomla (3) · joomla core (1) · tiny browser included with tinymce 3 0 (1)↑17
16lenovo6xclarity administrator lxca (3) · bios (1) · ez media backup center ix2 (1)·
17redhat6enterprise virtualization hypervisor aka rhev h (1) · keycloak (1) · openshift mysql apb (1)↓11
18siemens6scalance s602 (3) · scalance s612 (3) · scalance s623 (3)↑10
19snyk6bodymen (1) · component flatten (1) · dot object (1)·
20canonical5apport (4) · whoopsie (1)·
21dell5dell client consumer and commercial platforms (2) · elastic cloud storage (1) · isilon onefs (1)↑14
22php group5php (5)·
23bosch42divar ip 3000 (4) · divar ip 7000 (4) · divar ip all in one 5000 (3)·
24cloud foundry4capi (1) · credhub (1) · routing (1)·
25fortinet4fortinet forticlientlinux (4)↑11
26mozilla4webthings gateway (2) · firefox (1) · persona (1)↓22
27nec4aterm series (2) · aterm wg2600hs (2)·
28ca technologies a broadcom32ca unified infrastructure management nimsoft uim (3)·
29f53big ip (2) · edge client for windows (1)↑20
30mcafee3data exchange layer dxl broker (1) · mcafee endpoint security ens (1) · web advisor wa (1)·
31nodejs31node (3)new
32palo alto networks3expedition (1) · globalprotect (1) · pan os (1)·
33taiwan secom co31door access control system (3) · personnel attendance system (3)new
34trend micro3trend micro im security ims trend micro control manager tmcm trend micro officescan osce trend micro endpoint sensor tmes trend micro security consumer trend micro scanmail for microsoft exchange smex trend micro serverprotect sp trend micro mobile security enterprise tmms enterprise (1) · trend micro security consumer (1) · trend micro vulnerability protection (1)↓5
35vmware3vrealize operations for horizon adapter (3)↑36
36yokogawa3b m9000 vp (3) · b m9000cs (3) · centum cs 1000 (3)·
37broadcom2wifi drivers (2)↑8
38brocade2brocade fabric os (2)new
39d link2dap 1330 (1) · dap 2610 (1)↑47
40imagemagick2imagemagick (2)·
41linuxmint2mint (2)new
42netapp2netapp fas 8300 8700 and aff a400 baseboard management controller (1) · oncommand cloud manager (1)·
43samsung2galaxy s10 (1) · knox (1)·
44smf21smf (2)new
45smoothwall2smoothwall express (2)new
46tonnet2dvr (2)new
47xiaomi2browser (2)·
48zte21e8820v3 (2)·
491up lab1oneup uploader bundle (1)new
50abb1asset suite (1)·

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2020-02 that are on the CISA KEV catalog today. The 0 in the headline is what CISA listed during the month, whenever those CVEs were published. All 50 ranked vendors are listed; a zero count renders as a dot.

Weaknesses

CWE classes by distinct CVEs

  • 1CWE-79190 critical—
  • 2CWE-78122 critical↑5
  • 3CWE-787122 critical↑24
  • 4CWE-20110 critical↓2
  • 5CWE-284101 critical↑1
  • 6CWE-12580 critical↑24
  • 7CWE-40080 critical↑9
  • 8CWE-41660 critical↑3
  • 9CWE-2250 critical↑1
  • 10CWE-12240 critical↑19
  • 1CWE-28740 critical↑9
  • 2CWE-35240 critical↑10
  • 3CWE-79842 critical↓4
  • 4CWE-9441 critical·
  • 5CWE-12031 critical↓12
  • 6CWE-19030 critical·
  • 7CWE-28530 critical↑2
  • 8CWE-12121 critical↓10
  • 9CWE-20020 critical↓14
  • 10CWE-26420 critical↓5

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.