Enterprise Software
47,569 CVEs tracked since 1999. In the last 12 months, 9,362, +59% on the 12 before.
Enterprise Software by subsector, Sep 2026 so far
- ITSM & monitoring50649% · 50 vendors
- Document management15915% · 12 vendors
- Not yet sub-classified106The tagger has not placed these yet
- Collaboration899% · 20 vendors
- CRM606% · 9 vendors
- ERP485% · 7 vendors
- BI & reporting434% · 7 vendors
- HR & finance212% · 4 vendors
Month by month
Every monthly snapshot of Enterprise Software. A column is the CVEs published that month.
| Month | CVEs |
|---|---|
| 2021-09 | 301 |
| 2021-10 | 369 |
| 2021-11 | 260 |
| 2021-12 | 295 |
| 2022-01 | 402 |
| 2022-02 | 357 |
| 2022-03 | 337 |
| 2022-04 | 356 |
| 2022-05 | 351 |
| 2022-06 | 345 |
| 2022-07 | 350 |
| 2022-08 | 364 |
| 2022-09 | 290 |
| 2022-10 | 397 |
| 2022-11 | 364 |
| 2022-12 | 346 |
| 2023-01 | 249 |
| 2023-02 | 397 |
| 2023-03 | 0 |
| 2023-04 | 407 |
| 2023-05 | 340 |
| 2023-06 | 332 |
| 2023-07 | 361 |
| 2023-08 | 367 |
| 2023-09 | 310 |
| 2023-10 | 458 |
| 2023-11 | 334 |
| 2023-12 | 457 |
| 2024-01 | 372 |
| 2024-02 | 449 |
| 2024-03 | 453 |
| 2024-04 | 381 |
| 2024-05 | 609 |
| 2024-06 | 414 |
| 2024-07 | 434 |
| 2024-08 | 601 |
| 2024-09 | 321 |
| 2024-10 | 340 |
| 2024-11 | 540 |
| 2024-12 | 431 |
| 2025-01 | 433 |
| 2025-02 | 406 |
| 2025-03 | 609 |
| 2025-04 | 581 |
| 2025-05 | 668 |
| 2025-06 | 441 |
| 2025-07 | 517 |
| 2025-08 | 617 |
| 2025-09 | 577 |
| 2025-10 | 691 |
| 2025-11 | 535 |
| 2025-12 | 512 |
| 2026-01 | 494 |
| 2026-02 | 658 |
| 2026-03 | 863 |
| 2026-04 | 676 |
| 2026-05 | 591 |
| 2026-06 | 934 |
| 2026-07 | 1240 |
| 2026-08 | 1591 |
| 2026-09 | 1032 |
Vendors
Who shipped the most Enterprise Software CVEs in Sep 2026 so far, with their rank across all vendors.
Weaknesses
The weakness classes behind Enterprise Software CVEs in Sep 2026 so far.
Latest CVEs
The 15 most recently published vulnerabilities in Enterprise Software.
- CVE-2026-100720Froxlor before 2.3.12 Stored XSS via SSL certificate issuer8.7
- CVE-2026-100718Froxlor before 2.3.12 Authentication Bypass via EmailSender.add7.1
- CVE-2026-100719Froxlor before 2.3.12 Credential Disclosure via DirProtections API6.5
- CVE-2026-100717froxlor before 2.3.12 CRLF Injection via validateUrl userinfo9.9
- CVE-2026-100716Froxlor before 2.3.12 Privilege Escalation via Symlink9.9
- CVE-2026-100715Froxlor before 2.3.12 Arbitrary File Deletion via Symlink9.6
- CVE-2026-100714Froxlor before 2.3.12 Command Injection via letsencryptchallengepath9.1
- CVE-2026-100712froxlor before 2.3.12 Two-Factor Authentication Bypass via CSRF6.5
- CVE-2026-100713Froxlor before 2.3.12 Privilege Escalation via SSH Key Sync7.8
- CVE-2026-100711froxlor before 2.3.12 Authentication Bypass via Session Persistence7.5
- CVE-2026-100710Froxlor before 2.3.12 DKIM Private Key Disclosure via API4.9
- CVE-2026-100709Froxlor before 2.3.12 2FA Bypass via Namespace Confusion7.5
- CVE-2026-100708Froxlor before 2.3.13 Private Key Disclosure via Certificates API7.1
- CVE-2026-86066Horilla attendance approval endpoint is vulnerable to cross-site request forgery—
- CVE-2026-96795Horilla: Authenticated RCE in Horilla List-View Export8.8
The record
- Busiest month
- Aug 2026, 1,591 CVEs
- Sep 2026 so far
- 1,032 CVEs from 115 vendors
- Deployment
- On-prem, 98%
- Monthly snapshots
- 294 since 1999
Is your business exposed to threats like these?
Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.
Request an assessment