CVE Intelligence
Skip to main content

Month report

April 2020

Rolled up 2026-08-09 20:45 from 370,662 CVE records

2,186 CVEs published, +42.8% on the same month last year. 55 rated critical, 0 listed by CISA as exploited. oracle led with 230; the most common weakness class was CWE-79 (35). lenovo climbed 49 places, the largest move. 10 vendors ranked for the first time.

Published

2,186

+24.6%on the previous month

Critical / high

55 / 414

of the 1,063 scored

Medium / low

555 / 39

the rest of the scored bands

Added to CISA KEV

0

listed as exploited this month

Public exploit

76

exploit code indexed publicly

Scanner template

0

0% of the month

Publication to KEV

How long before CISA listed them

16 published this month and listed since — not the 0 listed during it.

Median days to listing

567

from publication to CISA's date added

Listed within 7 days

0%

of the 16

Listed within 30 days

0%

of the 16

Weakness × vendor

Where the two overlap

CVEs carrying both. Each row is shaded against its own worst class.
VendorCWE-79CWE-20CWE-264CWE-200CWE-125CWE-284CWE-121CWE-843
oracle
microsoft10
apple
ibm
qualcomm
abb3391
sap se
google

Vendors

Ranked by distinct CVEs this month

Δ is the move against last month's rank.
Vendors ranked by distinct CVEs published in 2020-04, sorted by CVEs descending
#VendorTop products
1oracle2301014mysql server (34) · vm virtualbox (20) · java (14)↑22
2microsoft11343windows 10 version 1903 for x64 based systems (66) · windows 10 version 1909 for x64 based systems (66) · windows server version 1903 server core installation (66)↓1
3apple501ios (31) · macos (27) · tvos (20)·
4ibm501qradar (10) · security information queue (6) · rational doors next generation (4)↑2
5qualcomm48snapdragon auto snapdragon compute snapdragon consumer iot snapdragon industrial iot snapdragon mobile snapdragon wearables (7) · snapdragon auto snapdragon compute snapdragon consumer iot snapdragon industrial iot snapdragon iot snapdragon mobile snapdragon voice music snapdragon wearables (6) · snapdragon auto snapdragon compute snapdragon connectivity snapdragon consumer iot snapdragon industrial iot snapdragon mobile snapdragon voice music snapdragon wired infrastructure and networking (5)↓3
6abb3441esoms (13) · abb ability system 800xa (5) · advabuild (5)·
7sap se284sap business objects business intelligence platform (5) · sap business objects business intelligence platform web intelligence html interface (2) · sap commerce (2)↑5
8google27chrome (26) · earth pro (1)↑7
9foxit25phantompdf (21) · reader (4)↑12
10juniper networks242junos os (16) · junos os evolved (8) · jatp (1)·
11cisco201013cisco ucs director (9) · cisco aironet access point software (2) · cisco ios xe sd wan software (1)↓1
12prestashop17prestashop (14) · ps linklist (2) · ps socialfollow (1)↑43
13apache144apache ofbiz (3) · apache http server (2) · apache cxf (1)↑19
14huawei12honor v10 (3) · honor v20 (3) · huawei mate 20 (3)↑33
15mcafee12mcafee endpoint security ens (11) · endpoint security ens for window (1)↑12
16mozilla102firefox (8) · firefox esr (7) · thunderbird (5)↓7
17jenkins project9jenkins aws sam plugin (1) · jenkins awseb deployment plugin (1) · jenkins code coverage api plugin (1)↓13
18redhat8ansible (1) · eclipse che (1) · glibc (1)↓13
19canonical7apport (3) · byobu (1) · extplorer (1)↑23
20cybozu7cybozu garoon (7)·
21palo alto networks7global protect agent (3) · pan os (2) · cortex xdr (1)↑14
22wordpress61wordpress (6)·
23dell51cpg bios (1) · dell powerconnect (1) · integrated data protection appliance (1)↓10
24lenovo5vantage (2) · lenovo system interface foundation (1) · lenovoappscenariopluginsystem for lenovo system interface foundation (1)↑49
25siemens5climatix pol908 bacnet ip module (2) · climatix pol909 awm module (2) · development evaluation kits for profinet io ek ertec 200 (1)↓14
26suse51opensuse leap 15 1 (3) · suse linux enterprise module for desktop applications 15 sp1 (2) · suse linux enterprise software development kit 12 sp4 (2)↓2
27ubuntu54shiftfs in the linux kernel (3) · 18 04 lts bionic linux kernel (1) · linux kernel (1)·
28visam5vbase editor (5) · vbase web remote module (5)new
29b r41automation studio (3) · automation runtime (1)new
30busch jaeger426186 11 telefon gateway (4) · tg s 3 2 telephone gateway (4)new
31opensuse4opensuse leap 15 1 (3) · suse linux enterprise module for desktop applications 15 sp1 (2) · suse linux enterprise software development kit 12 sp4 (2)↓1
32php group4php (4)·
33alle information co32school manage system (3)new
34secdo3secdo (3)new
35universal robots31universal robots robot controllers cb 2 cb3 e series (1) · ur3 ur5 and ur10 (1) · urx (1)·
36accellion2file transfer appliance (2)·
37bitdefender2antivirus free (1) · high level antimalware sdk for windows (1)·
38facebook2instagram for android (1) · oculus desktop (1)↓19
39git211git (2)·
40hgiga21c cmail (2)new
41icatch2dvr firmware (2)new
42jquery212jquery (2)new
43linux21linux kernel (2)·
44openshift enterprise2openshift apb base (1) · openshift mariadb apb (1)·
45plat home co2easyblocks ipv6 (2)↑9
46the ceph project2ceph (2)·
47veeam222one agent (2)new
48vmware2esxi (1) · installbuilder (1)↓8
49wagtail2wagtail (2)new
50zoom2meetings (2)·

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2020-04 that are on the CISA KEV catalog today. The 0 in the headline is what CISA listed during the month, whenever those CVEs were published. All 50 ranked vendors are listed; a zero count renders as a dot.

Weaknesses

CWE classes by distinct CVEs

  • 1CWE-79350 critical
  • 2CWE-202211 critical↑2
  • 3CWE-264161 critical↑22
  • 4CWE-200141 critical↑6
  • 5CWE-125110 critical↓2
  • 6CWE-284110 critical↑20
  • 7CWE-121100 critical↑7
  • 8CWE-843100 critical↑86
  • 9CWE-1690 critical↑48
  • 10CWE-8992 critical↑3
  • 1CWE-41680 critical↑10
  • 2CWE-78780 critical↓3
  • 3CWE-2270 critical↓6
  • 4CWE-40060 critical↑1
  • 5CWE-79863 critical↑19
  • 6CWE-26951 critical↑23
  • 7CWE-36750 critical↑56
  • 8CWE-7851 critical↓10
  • 9CWE-28741 critical↑8
  • 10CWE-30642 critical↑8

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.