Consumer Software
25,003 CVEs tracked since 1999. In the last 12 months, 5,765, +154% on the 12 before.
Consumer Software by subsector, Sep 2026 so far
- Browsers44351% · 4 vendors
- Productivity32537% · 12 vendors
- Not yet sub-classified69The tagger has not placed these yet
Also: File utilities 27, Media players 6, Games 4.
Month by month
Every monthly snapshot of Consumer Software. A column is the CVEs published that month.
| Month | CVEs |
|---|---|
| 2021-09 | 193 |
| 2021-10 | 57 |
| 2021-11 | 103 |
| 2021-12 | 101 |
| 2022-01 | 98 |
| 2022-02 | 76 |
| 2022-03 | 113 |
| 2022-04 | 48 |
| 2022-05 | 161 |
| 2022-06 | 205 |
| 2022-07 | 98 |
| 2022-08 | 112 |
| 2022-09 | 139 |
| 2022-10 | 92 |
| 2022-11 | 59 |
| 2022-12 | 304 |
| 2023-01 | 140 |
| 2023-02 | 73 |
| 2023-03 | 0 |
| 2023-04 | 107 |
| 2023-05 | 60 |
| 2023-06 | 143 |
| 2023-07 | 71 |
| 2023-08 | 101 |
| 2023-09 | 159 |
| 2023-10 | 66 |
| 2023-11 | 134 |
| 2023-12 | 283 |
| 2024-01 | 133 |
| 2024-02 | 113 |
| 2024-03 | 119 |
| 2024-04 | 142 |
| 2024-05 | 349 |
| 2024-06 | 252 |
| 2024-07 | 57 |
| 2024-08 | 155 |
| 2024-09 | 80 |
| 2024-10 | 136 |
| 2024-11 | 356 |
| 2024-12 | 233 |
| 2025-01 | 64 |
| 2025-02 | 109 |
| 2025-03 | 141 |
| 2025-04 | 140 |
| 2025-05 | 88 |
| 2025-06 | 382 |
| 2025-07 | 353 |
| 2025-08 | 185 |
| 2025-09 | 140 |
| 2025-10 | 104 |
| 2025-11 | 92 |
| 2025-12 | 346 |
| 2026-01 | 147 |
| 2026-02 | 220 |
| 2026-03 | 305 |
| 2026-04 | 227 |
| 2026-05 | 729 |
| 2026-06 | 1401 |
| 2026-07 | 1021 |
| 2026-08 | 1033 |
| 2026-09 | 874 |
Vendors
Who shipped the most Consumer Software CVEs in Sep 2026 so far, with their rank across all vendors.
Weaknesses
The weakness classes behind Consumer Software CVEs in Sep 2026 so far.
Latest CVEs
The 15 most recently published vulnerabilities in Consumer Software.
- CVE-2026-100646SiYuan before v3.8.4 Authentication Bypass via Missing Origin Header8.1
- CVE-2026-100644SiYuan before v3.8.4 SQL Injection via dailyNoteSavePath7.5
- CVE-2026-100645SiYuan 3.7.0 before 3.8.4 Stored XSS via Gallery Kanban8.0
- CVE-2026-100643SiYuan before v3.8.4 Stored XSS via Attribute View textarea8.0
- CVE-2026-100642SiYuan v2.1.0 before v3.8.4 Cross-Site Request Forgery via CheckAuth7.6
- CVE-2026-100641SiYuan before v3.8.4 Stored XSS via Unescaped Flashcard Content8.0
- CVE-2026-100640SiYuan before v3.8.4 Clipboard Data Disclosure via IPC4.7
- CVE-2026-100639SiYuan before v3.8.4 Cross-Site Scripting via Kramdown IAL8.8
- CVE-2026-100637SiYuan before v3.8.4 Path Traversal via checkoutRepo sessionID7.6
- CVE-2026-100638SiYuan before v3.8.4 Path Traversal via setNotebookIcon7.6
- CVE-2026-100636SiYuan before v3.8.4 Path Traversal via exportBrowserHTML folder7.6
- CVE-2026-100635SiYuan before v3.8.4 Authentication Bypass via Plaintext Session Cookie5.9
- CVE-2026-100634SiYuan before v3.8.4 Missing Authorization via siyuan-send-windows4.7
- CVE-2026-100633SiYuan 3.8.0 through 3.8.3 Path Traversal via MCP File Operations6.5
- CVE-2026-57449Actual Sync Server: CORS Proxy GitHub API Allowlist Prefix Bypass Leaks Private Repositories Through the Server GitHub Token—
The record
- Busiest month
- Jun 2026, 1,401 CVEs
- Sep 2026 so far
- 874 CVEs from 44 vendors
- Deployment
- On-prem, 97%
- Monthly snapshots
- 294 since 1999
Is your business exposed to threats like these?
Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.
Request an assessment