CVE Intelligence
Skip to main content

Month report

June 2020

Rolled up 2026-08-09 20:45 from 370,662 CVE records

1,807 CVEs published, +45.3% on the same month last year. 43 rated critical, 0 listed by CISA as exploited. microsoft led with 129; the most common weakness class was CWE-20 (29). suse climbed 45 places, the largest move. 8 vendors ranked for the first time.

Published

1,807

+77.7%on the previous month

Critical / high

43 / 141

of the 389 scored

Medium / low

178 / 27

the rest of the scored bands

Added to CISA KEV

0

listed as exploited this month

Public exploit

108

exploit code indexed publicly

Scanner template

0

0% of the month

Publication to KEV

How long before CISA listed them

10 published this month and listed since — not the 0 listed during it.

Median days to listing

629

from publication to CISA's date added

Listed within 7 days

0%

of the 10

Listed within 30 days

0%

of the 10

Weakness × vendor

Where the two overlap

CVEs carrying both. Each row is shaded against its own worst class.
VendorCWE-20CWE-79CWE-119CWE-787CWE-77CWE-200CWE-125CWE-22
microsoft61
adobe12
cisco204151242
apple2
ibm
qualcomm
atlassian
google

Vendors

Ranked by distinct CVEs this month

Δ is the move against last month's rank.
Vendors ranked by distinct CVEs published in 2020-06, sorted by CVEs descending
#VendorTop products
1microsoft12914windows 10 version 1903 for x64 based systems (91) · windows 10 version 1903 for 32 bit systems (90) · windows 10 version 2004 for 32 bit systems (90)
2adobe112adobe acrobat and reader (24) · adobe bridge (17) · magento (16)·
3cisco883cisco small business rv series router firmware (17) · cisco ios 12 2 60 ez16 (8) · cisco ios xe software 16 10 1 (4)
4apple6035ios (43) · macos (42) · watchos (32)·
5ibm5321security guardium (10) · security secret server (6) · spectrum protect plus (6)↓3
6qualcomm45snapdragon auto snapdragon compute snapdragon connectivity snapdragon consumer iot snapdragon industrial iot snapdragon mobile snapdragon voice music snapdragon wearables (6) · snapdragon auto snapdragon compute snapdragon connectivity snapdragon consumer iot snapdragon industrial iot snapdragon mobile snapdragon voice music snapdragon wired infrastructure and networking (4) · snapdragon auto snapdragon compute snapdragon consumer iot snapdragon industrial iot snapdragon iot snapdragon mobile snapdragon voice music snapdragon wearables (4)·
7atlassian20crucible (8) · fisheye (8) · jira server (8)·
8google192chrome (16) · guest oslogin (3)↓4
9gitlab181gitlab (17) · gitlab vscode extension (1)·
10mobile industrial robots a s127mir100 (12)new
11nvidia12nvidia gpu display driver (6) · nvidia vgpu software (6)↑24
12sap se121sap commerce (2) · sap business objects business intelligence platform (1) · sap business one backup service (1)↓5
13jenkins project11jenkins echarts api plugin (2) · jenkins project inheritance plugin (2) · jenkins self organizing swarm plug in modules plugin (2)
14vmware10fusion (10) · vmware esxi (10) · workstation (10)↑11
15cybozu9cybozu garoon (9)↑7
16freerdp91freerdp (9)↓10
17lenovo91bios (6) · installation packages (2) · synaptics smart audio uwp app (1)↑15
18mcafee7mcafee virusscan enterprise vse (3) · mcafee advanced threat defense atd (1) · mcafee agent ma (1)↓7
19redhat71activemq artemis (1) · ansible tower (1) · containernetworking plugins (1)↓11
20elastic61kibana (3) · elastic app search (1) · elastic cloud on kubernetes (1)·
21palo alto networks611pan os (4) · globalprotect app (2)↓16
22zephyrproject rtos63zephyr (6)↓10
23dell5dell client consumer and commercial platforms (2) · dell encryption enterprise (1) · unisphere for powermax (1)↓13
24octobercms51october (5)new
25wordpress5wordpress develop (5)·
26apache43apache shiro (1) · apache spark (1) · apache tomcat (1)↑18
27fortinet4fortinet forticlient for windows (1) · fortinet fortideceptor (1) · fortinet fortios and fortiproxy (1)·
28opensuse4opensuse leap 15 1 (4) · opensuse factory (2) · opensuse backports sle 15 sp1 (1)↑8
29siemens4simatic pcs 7 v8 2 and earlier (2) · simatic pcs 7 v9 0 (2) · simatic pdm (2)·
30tibco software42tibco managed file transfer command center (2) · tibco managed file transfer internet server (2) · tibco managed file transfer platform server for ibm i (2)↑10
31geovision3door access control device (3)new
32mitsubishi electric3mitsubishi electoric fa engineering software (2) · melsec iq r iq f q l and fx series cpu modules (1)·
33suse3opensuse leap 15 1 (2) · opensuse backports sle 15 sp1 (1) · opensuse factory (1)↑45
34bitdefender21bitdefender antivirus free (1) · bitdefender total security 2020 (1)↑12
35bolt21bolt (2)new
36isc2bind9 (2)↓8
37kata containers21kata containers (2)↓6
38philips2intellibridge enterprise ibe (1) · ultrasound clearvue (1) · ultrasound cx (1)·
39rapid72metasploit pro (2)·
40spring by vmware211spring batch (1) · spring cloud config (1)↓1
41the document foundation2libreoffice (2)↑41
42xiaomi2xiaomi router r3600 (2)·
43zenphoto2zenphoto (2)·
44auth01express jwt (1)·
45avaya11ip office (1)·
46beckhoff1twincat driver for intel 8254x tcl8254x sys (1) · twincat driver for intel 8255x tcl8255x sys (1)·
47cabsoftware1reportexpress proplus (1)new
48citrix1xenapp (1)new
49commax1wallpad (1)new
50coturn1coturn (1)new

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2020-06 that are on the CISA KEV catalog today. The 0 in the headline is what CISA listed during the month, whenever those CVEs were published. All 50 ranked vendors are listed; a zero count renders as a dot.

Weaknesses

CWE classes by distinct CVEs

  • 1CWE-20290 critical↑1
  • 2CWE-79210 critical↓1
  • 3CWE-119162 critical↑4
  • 4CWE-787160 critical↑28
  • 5CWE-77140 critical↑39
  • 6CWE-200130 critical↑4
  • 7CWE-12591 critical↓4
  • 8CWE-2290 critical↑4
  • 9CWE-30681 critical·
  • 10CWE-50280 critical↑31
  • 1CWE-27673 critical↑43
  • 2CWE-31970 critical↑48
  • 3CWE-79874 critical↑20
  • 4CWE-25960 critical·
  • 5CWE-26461 critical·
  • 6CWE-26960 critical↑37
  • 7CWE-28460 critical↓13
  • 8CWE-28560 critical↓1
  • 9CWE-28760 critical↓6
  • 10CWE-7861 critical↓14

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.