CVE Tools

Enterprise Software

47,569 CVEs tracked since 1999. In the last 12 months, 9,362, +59% on the 12 before.

Enterprise Software by subsector, Sep 2026 so far

Sep 2026 so far: 1,032 CVEs across 8 subsectors. Area is each subsector's share; inside are the products it counted most. Point at one to read it.
  • ITSM & monitoring50649% · 50 vendors
  • Document management15915% · 12 vendors
  • Not yet sub-classified106The tagger has not placed these yet
  • Collaboration899% · 20 vendors
  • CRM606% · 9 vendors
  • ERP485% · 7 vendors
  • BI & reporting434% · 7 vendors
  • HR & finance212% · 4 vendors

Month by month

Every monthly snapshot of Enterprise Software. A column is the CVEs published that month.

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Enterprise Software CVEs per month
MonthCVEs
2021-09301
2021-10369
2021-11260
2021-12295
2022-01402
2022-02357
2022-03337
2022-04356
2022-05351
2022-06345
2022-07350
2022-08364
2022-09290
2022-10397
2022-11364
2022-12346
2023-01249
2023-02397
2023-030
2023-04407
2023-05340
2023-06332
2023-07361
2023-08367
2023-09310
2023-10458
2023-11334
2023-12457
2024-01372
2024-02449
2024-03453
2024-04381
2024-05609
2024-06414
2024-07434
2024-08601
2024-09321
2024-10340
2024-11540
2024-12431
2025-01433
2025-02406
2025-03609
2025-04581
2025-05668
2025-06441
2025-07517
2025-08617
2025-09577
2025-10691
2025-11535
2025-12512
2026-01494
2026-02658
2026-03863
2026-04676
2026-05591
2026-06934
2026-071240
2026-081591
2026-091032

Vendors

Who shipped the most Enterprise Software CVEs in Sep 2026 so far, with their rank across all vendors.

  1. IBM297#5
  2. Dell177#7
  3. Grokability46#20
  4. Snipeitapp44#22
  5. Itsourcecode36#28
  6. Kimai17#68
  7. Sap_se17#70
  8. Siemens15#79

Weaknesses

The weakness classes behind Enterprise Software CVEs in Sep 2026 so far.

  1. CWE-284 Improper Access Control210
  2. CWE-79 XSS169
  3. CWE-269 Improper Privilege Mgmt97
  4. CWE-89 SQL Injection88
  5. CWE-862 Missing Authorization81
  6. CWE-639 Auth Bypass via User Key54

Latest CVEs

The 15 most recently published vulnerabilities in Enterprise Software.

  1. CVE-2026-100720Froxlor before 2.3.12 Stored XSS via SSL certificate issuer8.7
  2. CVE-2026-100718Froxlor before 2.3.12 Authentication Bypass via EmailSender.add7.1
  3. CVE-2026-100719Froxlor before 2.3.12 Credential Disclosure via DirProtections API6.5
  4. CVE-2026-100717froxlor before 2.3.12 CRLF Injection via validateUrl userinfo9.9
  5. CVE-2026-100716Froxlor before 2.3.12 Privilege Escalation via Symlink9.9
  6. CVE-2026-100715Froxlor before 2.3.12 Arbitrary File Deletion via Symlink9.6
  7. CVE-2026-100714Froxlor before 2.3.12 Command Injection via letsencryptchallengepath9.1
  8. CVE-2026-100712froxlor before 2.3.12 Two-Factor Authentication Bypass via CSRF6.5
  9. CVE-2026-100713Froxlor before 2.3.12 Privilege Escalation via SSH Key Sync7.8
  10. CVE-2026-100711froxlor before 2.3.12 Authentication Bypass via Session Persistence7.5
  11. CVE-2026-100710Froxlor before 2.3.12 DKIM Private Key Disclosure via API4.9
  12. CVE-2026-100709Froxlor before 2.3.12 2FA Bypass via Namespace Confusion7.5
  13. CVE-2026-100708Froxlor before 2.3.13 Private Key Disclosure via Certificates API7.1
  14. CVE-2026-86066Horilla attendance approval endpoint is vulnerable to cross-site request forgery—
  15. CVE-2026-96795Horilla: Authenticated RCE in Horilla List-View Export8.8

The record

Busiest month
Aug 2026, 1,591 CVEs
Sep 2026 so far
1,032 CVEs from 115 vendors
Deployment
On-prem, 98%
Monthly snapshots
294 since 1999
All 15 sectors on one map

Is your business exposed to threats like these?

Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.

Request an assessment

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store