Security Products
16,823 CVEs tracked since 1999. In the last 12 months, 3,435, +104% on the 12 before.
Security Products by subsector, Sep 2026 so far
- Identity & access15340% · 21 vendors
- Vulnerability scanners12132% · 23 vendors
- Not yet sub-classified35The tagger has not placed these yet
- SIEM & SOAR339% · 7 vendors
- Endpoint, AV & EDR185% · 8 vendors
- Secure gateways & VPN164% · 8 vendors
- PKI & crypto72% · 4 vendors
Month by month
Every monthly snapshot of Security Products. A column is the CVEs published that month.
| Month | CVEs |
|---|---|
| 2021-09 | 108 |
| 2021-10 | 50 |
| 2021-11 | 96 |
| 2021-12 | 120 |
| 2022-01 | 75 |
| 2022-02 | 69 |
| 2022-03 | 109 |
| 2022-04 | 80 |
| 2022-05 | 145 |
| 2022-06 | 82 |
| 2022-07 | 78 |
| 2022-08 | 80 |
| 2022-09 | 91 |
| 2022-10 | 130 |
| 2022-11 | 99 |
| 2022-12 | 90 |
| 2023-01 | 99 |
| 2023-02 | 111 |
| 2023-03 | 0 |
| 2023-04 | 94 |
| 2023-05 | 95 |
| 2023-06 | 159 |
| 2023-07 | 70 |
| 2023-08 | 149 |
| 2023-09 | 127 |
| 2023-10 | 166 |
| 2023-11 | 96 |
| 2023-12 | 121 |
| 2024-01 | 129 |
| 2024-02 | 123 |
| 2024-03 | 114 |
| 2024-04 | 121 |
| 2024-05 | 176 |
| 2024-06 | 86 |
| 2024-07 | 101 |
| 2024-08 | 126 |
| 2024-09 | 121 |
| 2024-10 | 165 |
| 2024-11 | 184 |
| 2024-12 | 116 |
| 2025-01 | 197 |
| 2025-02 | 126 |
| 2025-03 | 152 |
| 2025-04 | 99 |
| 2025-05 | 130 |
| 2025-06 | 132 |
| 2025-07 | 152 |
| 2025-08 | 107 |
| 2025-09 | 86 |
| 2025-10 | 235 |
| 2025-11 | 131 |
| 2025-12 | 167 |
| 2026-01 | 149 |
| 2026-02 | 283 |
| 2026-03 | 449 |
| 2026-04 | 423 |
| 2026-05 | 343 |
| 2026-06 | 301 |
| 2026-07 | 336 |
| 2026-08 | 532 |
| 2026-09 | 383 |
Vendors
Who shipped the most Security Products CVEs in Sep 2026 so far, with their rank across all vendors.
Weaknesses
The weakness classes behind Security Products CVEs in Sep 2026 so far.
Latest CVEs
The 15 most recently published vulnerabilities in Security Products.
- CVE-2026-85984miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 - Unauthenticated Authentication Bypass via 'mo_wp_login_intent' Parameter9.8
- CVE-2026-100604ClawHub Authentication Bypass via Former Publisher Skill Control5.4
- CVE-2026-100602ClawHub Changelog Preview Information Disclosure via Authorization Bypass6.5
- CVE-2026-100603ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports5.4
- CVE-2026-100601ClawHub SSRF via Unchecked DNS Resolution in Profile Image5.3
- CVE-2026-100600ClawHub before 8c2de6c506 Quota Exhaustion via Anonymous API5.3
- CVE-2026-100583OpenClaw Discord before 2026.7.1 Authorization Bypass4.3
- CVE-2026-100582OpenClaw Channel Plugins before 2026.8.1 Channel Read Allowlist Bypass6.5
- CVE-2026-100575OpenClaw Slack before 2026.8.1 Authentication Bypass via Group DM8.8
- CVE-2026-100566OpenClaw LINE before 2026.8.1 Access Control Inheritance6.5
- CVE-2026-100541OpenClaw Matrix before 2026.8.1 Authorization Bypass via Case Folding7.5
- CVE-2026-100540OpenClaw Feishu before 2026.8.1 Authentication Bypass via Disabled Account6.8
- CVE-2026-100532openclaw WhatsApp before 2026.8.1 Authentication Bypass8.1
- CVE-2026-100531openclaw Slack before 2026.8.1 Authorization Bypass6.5
- CVE-2026-100526Vulnerability in discord5.3
The record
- Busiest month
- Aug 2026, 532 CVEs
- Sep 2026 so far
- 383 CVEs from 77 vendors
- Deployment
- On-prem, 86%
- Monthly snapshots
- 295 since 1999
Is your business exposed to threats like these?
Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.
Request an assessment