CVE Tools

Consumer Software

25,003 CVEs tracked since 1999. In the last 12 months, 5,765, +154% on the 12 before.

Consumer Software by subsector, Sep 2026 so far

Sep 2026 so far: 874 CVEs across 6 subsectors. Area is each subsector's share; inside are the products it counted most. Point at one to read it.
  • Browsers44351% · 4 vendors
  • Productivity32537% · 12 vendors
  • Not yet sub-classified69The tagger has not placed these yet

Also: File utilities 27, Media players 6, Games 4.

Month by month

Every monthly snapshot of Consumer Software. A column is the CVEs published that month.

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Consumer Software CVEs per month
MonthCVEs
2021-09193
2021-1057
2021-11103
2021-12101
2022-0198
2022-0276
2022-03113
2022-0448
2022-05161
2022-06205
2022-0798
2022-08112
2022-09139
2022-1092
2022-1159
2022-12304
2023-01140
2023-0273
2023-030
2023-04107
2023-0560
2023-06143
2023-0771
2023-08101
2023-09159
2023-1066
2023-11134
2023-12283
2024-01133
2024-02113
2024-03119
2024-04142
2024-05349
2024-06252
2024-0757
2024-08155
2024-0980
2024-10136
2024-11356
2024-12233
2025-0164
2025-02109
2025-03141
2025-04140
2025-0588
2025-06382
2025-07353
2025-08185
2025-09140
2025-10104
2025-1192
2025-12346
2026-01147
2026-02220
2026-03305
2026-04227
2026-05729
2026-061401
2026-071021
2026-081033
2026-09874

Vendors

Who shipped the most Consumer Software CVEs in Sep 2026 so far, with their rank across all vendors.

  1. Adobe171#8
  2. Mozilla113#11
  3. Siyuan-note29#38
  4. Rclone11#113
  5. Gnome6#186

Weaknesses

The weakness classes behind Consumer Software CVEs in Sep 2026 so far.

  1. CWE-79 XSS132
  2. CWE-416 Use After Free120
  3. CWE-863 Incorrect Authorization66
  4. CWE-125 Out-of-bounds Read63
  5. CWE-122 Heap Buffer Overflow52
  6. CWE-862 Missing Authorization41

Latest CVEs

The 15 most recently published vulnerabilities in Consumer Software.

  1. CVE-2026-100646SiYuan before v3.8.4 Authentication Bypass via Missing Origin Header8.1
  2. CVE-2026-100644SiYuan before v3.8.4 SQL Injection via dailyNoteSavePath7.5
  3. CVE-2026-100645SiYuan 3.7.0 before 3.8.4 Stored XSS via Gallery Kanban8.0
  4. CVE-2026-100643SiYuan before v3.8.4 Stored XSS via Attribute View textarea8.0
  5. CVE-2026-100642SiYuan v2.1.0 before v3.8.4 Cross-Site Request Forgery via CheckAuth7.6
  6. CVE-2026-100641SiYuan before v3.8.4 Stored XSS via Unescaped Flashcard Content8.0
  7. CVE-2026-100640SiYuan before v3.8.4 Clipboard Data Disclosure via IPC4.7
  8. CVE-2026-100639SiYuan before v3.8.4 Cross-Site Scripting via Kramdown IAL8.8
  9. CVE-2026-100637SiYuan before v3.8.4 Path Traversal via checkoutRepo sessionID7.6
  10. CVE-2026-100638SiYuan before v3.8.4 Path Traversal via setNotebookIcon7.6
  11. CVE-2026-100636SiYuan before v3.8.4 Path Traversal via exportBrowserHTML folder7.6
  12. CVE-2026-100635SiYuan before v3.8.4 Authentication Bypass via Plaintext Session Cookie5.9
  13. CVE-2026-100634SiYuan before v3.8.4 Missing Authorization via siyuan-send-windows4.7
  14. CVE-2026-100633SiYuan 3.8.0 through 3.8.3 Path Traversal via MCP File Operations6.5
  15. CVE-2026-57449Actual Sync Server: CORS Proxy GitHub API Allowlist Prefix Bypass Leaks Private Repositories Through the Server GitHub Token—

The record

Busiest month
Jun 2026, 1,401 CVEs
Sep 2026 so far
874 CVEs from 44 vendors
Deployment
On-prem, 97%
Monthly snapshots
294 since 1999
All 15 sectors on one map

Is your business exposed to threats like these?

Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.

Request an assessment

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store