Month report
November 2020
Rolled up 2026-08-09 20:45 from 370,700 CVE records
1,246 CVEs published, -25.8% on the same month last year. 26 rated critical, 0 listed by CISA as exploited. microsoft led with 112; the most common weakness class was CWE-79 (32). typo3 climbed 77 places, the largest move. 10 vendors ranked for the first time.
Published
1,246
Critical / high
26 / 180
Medium / low
192 / 25
Added to CISA KEV
0
Public exploit
79
Scanner template
0
Publication to KEV
How long before CISA listed them
Median days to listing
365
Listed within 7 days
0%
Listed within 30 days
0%
Vendors
Ranked by distinct CVEs this month
| # | Vendor | Top products | ||||||
|---|---|---|---|---|---|---|---|---|
| 1 | microsoft | 112 | 1 | 1 | 4 | windows 10 version 1903 for x64 based systems (52) · windows 10 version 1909 (52) · windows 10 version 1903 for 32 bit systems (51) | ↑2 | |
| 2 | cisco | 50 | 4 | cisco iot field network director iot fnd (10) · cisco sd wan vmanage (7) · cisco sd wan solution (5) | ↑2 | |||
| 3 | qualcomm | 48 | snapdragon auto snapdragon compute snapdragon connectivity snapdragon consumer electronics connectivity snapdragon consumer iot snapdragon industrial iot snapdragon mobile snapdragon voice music snapdragon wired infrastructure and networking (5) · snapdragon auto snapdragon compute snapdragon consumer iot snapdragon industrial iot snapdragon mobile (5) · snapdragon auto snapdragon compute snapdragon connectivity snapdragon consumer iot snapdragon industrial iot snapdragon mobile snapdragon voice music snapdragon wearables snapdragon wired infrastructure and networking (4) | · | ||||
| 4 | 46 | 2 | 3 | 1 | chrome (46) · android (1) | ↑64 | ||
| 5 | ibm | 42 | 1 | sterling b2b integrator (8) · cloud pak for security (5) · sterling file gateway (4) | — | |||
| 6 | adobe | 25 | 1 | acrobat reader (15) · magento commerce (8) · connect (2) | ↑3 | |||
| 7 | jenkins project | 21 | jenkins active directory plugin (5) · jenkins kubernetes plugin (3) · jenkins mercurial plugin (2) | ↑5 | ||||
| 8 | sap se | 18 | 6 | sap solution manager java stack (4) · sap commerce cloud accelerator payment mock (2) · sap fiori launchpad news tile application (2) | ↑2 | |||
| 9 | trend micro | 15 | trend micro interscan messaging security virtual appliance imsva (6) · trend micro interscan web security virtual appliance (4) · trend micro security consumer (3) | ↑11 | ||||
| 10 | gitlab | 13 | gitlab ce ee (9) · gitlab ee (3) · gitaly (1) | ↑1 | ||||
| 11 | mongodb | 13 | mongodb server (12) · mongodb ops manager (1) | · | ||||
| 12 | mitsubishi electric | 8 | gt14 model of got 1000 series (6) · melsec iq r (1) · melsec iq r series cpu modules (1) | ↑5 | ||||
| 13 | qnap systems | 8 | music station (3) · photo station (3) · qts (2) | ↑20 | ||||
| 14 | atlassian | 5 | crucible (2) · fisheye (2) · automation for jira (1) | ↑8 | ||||
| 15 | mcafee | 5 | endpoint security for windows (2) · mvision endpoint epo extension (2) · mcafee endpoint security ens (1) | ↑4 | ||||
| 16 | micro focus | 5 | 1 | arcsight logger (3) · filr (1) · idol (1) | ↑16 | |||
| 17 | octobercms | 5 | october (5) | · | ||||
| 18 | palo alto networks | 5 | pan os (5) | · | ||||
| 19 | lenovo | 4 | bios (2) · desktop and workstation systems (1) · pcmanager (1) | ↑6 | ||||
| 20 | neuroinformatics unit integrative computational brain science collaboration division riken center for brain science | 4 | xoonips (4) | · | ||||
| 21 | puncsky | 4 | 1 | touchbase ai (4) | new | |||
| 22 | redhat | 4 | kernel (2) · keycloak (1) · open cluster management (1) | ↑68 | ||||
| 23 | typo3 | 4 | typo3 cms (3) · fluid (1) | ↑77 | ||||
| 24 | apache | 3 | 1 | 1 | 2 | airflow (1) · apache airflow (1) · apache cxf (1) | · | |
| 25 | b braun melsungen | 3 | onlinesuite (3) | new | ||||
| 26 | ethereum | 3 | go ethereum (3) | new | ||||
| 27 | hcl | 3 | hcl domino (2) · hcl notes (1) | · | ||||
| 28 | silver peak systems | 3 | unity orchestrator (3) | · | ||||
| 29 | avaya | 2 | avaya equinox conferencing (1) · system manager (1) · weblm (1) | · | ||||
| 30 | bookstackapp | 2 | bookstack (2) | · | ||||
| 31 | endress hauser | 2 | 1 | orsg35 ecograph t neutral private label (2) · rsg35 ecograph t (2) · orsg45 memograph m neutral private label (1) | new | |||
| 32 | 2 | whatsapp business for ios (2) · whatsapp for ios (2) | ↓17 | |||||
| 33 | freedesktop | 2 | 1 | accountsservice (2) | new | |||
| 34 | go toolchain | 2 | cmd go (2) · cmd cgo (1) | new | ||||
| 35 | jupyter | 2 | jupyter server (1) · notebook (1) | new | ||||
| 36 | kuka roboter | 2 | visual components network license server 2 0 8 (2) | · | ||||
| 37 | packagekit | 2 | packagekit (2) | new | ||||
| 38 | prestashop | 2 | prestashop (1) · productcomments (1) | · | ||||
| 39 | synology | 2 | 1 | safe access (2) | ↓25 | |||
| 40 | the eclipse foundation | 2 | eclipse hono (1) · eclipse jetty (1) | ↑5 | ||||
| 41 | the tcpdump group | 2 | 1 | tcpdump (2) | · | |||
| 42 | ubuntu | 2 | 1 | 1 | libvirt (1) · tmux (1) | · | ||
| 43 | alerta | 1 | 1 | alerta (1) | new | |||
| 44 | amazon | 1 | aws sdk (1) | · | ||||
| 45 | auth0 | 1 | ad ldap connector (1) | ↑6 | ||||
| 46 | beckhoff | 1 | twincat xar 3 1 (1) | · | ||||
| 47 | bitdefender | 1 | bitdefender update server (1) | ↓12 | ||||
| 48 | canonical | 1 | pulseaudio (1) | ↑5 | ||||
| 49 | crixp | 1 | 1 | 1 | opencrx (1) | new | ||
| 50 | cybozu | 1 | cybozu garoon (1) | · |
One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2020-11 that are on the CISA KEV catalog today. The 0 in the headline is what CISA listed during the month, whenever those CVEs were published. All 50 ranked vendors are listed; a zero count renders as a dot.
Weaknesses
CWE classes by distinct CVEs
- 1CWE-79320 critical—
- 2CWE-20180 critical—
- 3CWE-284160 critical↑10
- 4CWE-78143 critical↑5
- 5CWE-122101 critical↑36
- 6CWE-26991 critical↑9
- 7CWE-78790 critical—
- 8CWE-11981 critical↑2
- 9CWE-20070 critical↑2
- 10CWE-28570 critical↑33
- 1CWE-28771 critical↓3
- 2CWE-8070 critical↑44
- 3CWE-86370 critical↑6
- 4CWE-41660 critical↑21
- 5CWE-12550 critical↓11
- 6CWE-2250 critical↓4
- 7CWE-8951 critical↑12
- 8CWE-12041 critical↓13
- 9CWE-12140 critical↑1
- 10CWE-27642 critical·
One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.