CVE Intelligence
Skip to main content

Month report

January 2021

Rolled up 2026-08-09 20:45 from 370,877 CVE records

1,514 CVEs published, -8.5% on the same month last year. 63 rated critical, 0 listed by CISA as exploited. cisco led with 155; the most common weakness class was CWE-121 (69). oracle climbed 75 places, the largest move. 11 vendors ranked for the first time.

Published

1,514

-1.6%on the previous month

Critical / high

63 / 317

of the 718 scored

Medium / low

321 / 17

the rest of the scored bands

Added to CISA KEV

0

listed as exploited this month

Public exploit

75

exploit code indexed publicly

Scanner template

0

0% of the month

Publication to KEV

How long before CISA listed them

9 published this month and listed since — not the 0 listed during it.

Median days to listing

361

from publication to CISA's date added

Listed within 7 days

0%

of the 9

Listed within 30 days

0%

of the 9

Weakness × vendor

Where the two overlap

CVEs carrying both. Each row is shaded against its own worst class.
VendorCWE-121CWE-79CWE-20CWE-122CWE-400CWE-787CWE-74CWE-119
cisco61142418
oracle
ibm
microsoft
google1
qualcomm
siemens469
sap se

Vendors

Ranked by distinct CVEs this month

Δ is the move against last month's rank.
Vendors ranked by distinct CVEs published in 2021-01, sorted by CVEs descending
#VendorTop products
1cisco1559cisco small business rv series router firmware (74) · cisco data center network manager (15) · cisco sd wan solution (14)↑26
2oracle14198mysql server (38) · vm virtualbox (17) · weblogic server (14)↑75
3ibm83engineering lifecycle optimization (10) · engineering test management (10) · engineering workflow management (10)
4microsoft8214windows 10 version 2004 (63) · windows 10 version 1909 (60) · windows 10 version 20h2 (60)↓2
5google46133chrome (46)↑6
6qualcomm341snapdragon auto snapdragon compute snapdragon connectivity snapdragon consumer iot snapdragon industrial iot snapdragon iot snapdragon mobile snapdragon voice music snapdragon wearables snapdragon wired infrastructure and networking (9) · snapdragon auto snapdragon compute snapdragon connectivity snapdragon consumer iot snapdragon industrial iot snapdragon mobile snapdragon voice music snapdragon wearables (7) · snapdragon auto snapdragon compute snapdragon connectivity snapdragon consumer electronics connectivity snapdragon consumer iot snapdragon industrial iot snapdragon mobile snapdragon voice music snapdragon wired infrastructure and networking (3)·
7siemens28jt2go (18) · teamcenter visualization (18) · solid edge se2020 (6)↓2
8sap se272sap 3d visual enterprise viewer (16) · sap business warehouse (3) · cla assistant (1)↑2
9nvidia211nvidia virtual gpu manager (8) · nvidia gpu display driver (6) · shield tv (3)·
10juniper networks191junos os (16) · junos os evolved (3) · contrail networking (1)·
11dell184avamar (3) · powerstore (3) · unity (3)↑19
12jenkins project14jenkins (11) · jenkins bumblebee hp alm plugin (1) · jenkins tics plugin (1)↑10
13mozilla13firefox (13) · firefox esr (7) · thunderbird (7)↓9
14apache11113apache flink (2) · apache activemq (1) · apache activemq artemis (1)↓5
15theonedev107onedev (10)new
16adobe8magento commerce (2) · animate (1) · campaign (1)↑9
17nec7aterm wg2600hp and aterm wg2600hp2 (2) · univerge sv9500 sv8500 series (2) · aterm wf800hp (1)↑12
18combodo5itop (5)·
19debian53agile plm (5) · autovue for agile product lifecycle management (5) · banking digital experience (5)·
20fasterxml53agile plm (5) · autovue for agile product lifecycle management (5) · banking digital experience (5)·
21gitlab5gitlab (5)↓9
22kubernetes52kubernetes secrets store csi driver (2) · csi snapshotter (1) · kubernetes (1)↑6
23netapp53agile plm (5) · autovue for agile product lifecycle management (5) · banking digital experience (5)·
24bosch41fsm 2500 (2) · fsm 5000 (2) · praesensa (2)·
25pepper fuchs4comtrol io link master (4)new
26trend micro4trend micro serverprotect for linux (3) · trend micro housecall for home networks (1)↓18
27atlassian3bamboo (1) · confluence server (1) · crucible (1)↑19
28hgiga31oaksv20 oaklouds document v3 (1) · oaksv20 oaklouds document v3 2 0 (1) · oaksv20 oaklouds mol course v3 2 0 (1)↓13
29joomla project3joomla cms (3)↓12
30openmage3magento lts (3)·
31the eclipse foundation31eclipse hawkbit (1) · eclipse hono (1) · eclipse openj9 (1)·
32canonical2linux kernel (1) · remote login service (1)↓18
33eaton2easysoft software (2)·
34fortinet2fortinet fortiweb (2)·
35hyweb2hycms j1 (2)new
36identitypython21pysaml2 (2)new
37mcafee2mcafee agent (1) · network security management nsm (1)↓4
38nodejs21node (2)·
39palo alto networks2pan os (2)↑3
40reolink2rlc 4xx series (2) · rlc 5xx series (2) · rln x10 series (2)new
41seeds co2acmailer and acmailer db (2)new
42sonicwall21sma100 (1) · sonicwall netextender (1)·
43spring by vmware2spring cloud data flow (1) · spring cloud task (1)·
44tibco software2tibco bpm enterprise (1) · tibco bpm enterprise distribution for tibco silver fabric (1) · tibco ebx add ons (1)↑46
45ziv automation24cct ea6 334126bf (2)new
46arcserve1d2d (1)new
47bigprof software1online invoicing system (1)new
48ca technologies a broadcom1ca service catalog (1)·
49chatter social1creeper (1)new
50ckeditor1ckeditor5 (1)new

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored. The KEV column counts CVEs published in 2021-01 that are on the CISA KEV catalog today. The 0 in the headline is what CISA listed during the month, whenever those CVEs were published. All 50 ranked vendors are listed; a zero count renders as a dot.

Weaknesses

CWE classes by distinct CVEs

  • 1CWE-121690 critical↑23
  • 2CWE-79410 critical↓1
  • 3CWE-20325 critical↑1
  • 4CWE-122160 critical↑2
  • 5CWE-400140 critical↑7
  • 6CWE-787140 critical↑9
  • 7CWE-74126 critical↑48
  • 8CWE-119113 critical↑11
  • 9CWE-22111 critical↑17
  • 10CWE-125100 critical↑3
  • 1CWE-89102 critical↓2
  • 2CWE-41681 critical↓4
  • 3CWE-50280 critical↑27
  • 4CWE-7881 critical↓4
  • 5CWE-35270 critical↑5
  • 6CWE-42770 critical↑5
  • 7CWE-47670 critical↑31
  • 8CWE-27665 critical↑54
  • 9CWE-43461 critical↑28
  • 10CWE-20050 critical↓4

One CVE is counted once per vendor, product or weakness class it lists, so a ranking column sums to more than the month's total. Only the month's top 100 keys per dimension are stored.