CVE Tools

Security Products

16,823 CVEs tracked since 1999. In the last 12 months, 3,435, +104% on the 12 before.

Security Products by subsector, Sep 2026 so far

Sep 2026 so far: 383 CVEs across 7 subsectors. Area is each subsector's share; inside are the products it counted most. Point at one to read it.
  • Identity & access15340% · 21 vendors
  • Vulnerability scanners12132% · 23 vendors
  • Not yet sub-classified35The tagger has not placed these yet
  • SIEM & SOAR339% · 7 vendors
  • Endpoint, AV & EDR185% · 8 vendors
  • Secure gateways & VPN164% · 8 vendors
  • PKI & crypto72% · 4 vendors

Month by month

Every monthly snapshot of Security Products. A column is the CVEs published that month.

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Security Products CVEs per month
MonthCVEs
2021-09108
2021-1050
2021-1196
2021-12120
2022-0175
2022-0269
2022-03109
2022-0480
2022-05145
2022-0682
2022-0778
2022-0880
2022-0991
2022-10130
2022-1199
2022-1290
2023-0199
2023-02111
2023-030
2023-0494
2023-0595
2023-06159
2023-0770
2023-08149
2023-09127
2023-10166
2023-1196
2023-12121
2024-01129
2024-02123
2024-03114
2024-04121
2024-05176
2024-0686
2024-07101
2024-08126
2024-09121
2024-10165
2024-11184
2024-12116
2025-01197
2025-02126
2025-03152
2025-0499
2025-05130
2025-06132
2025-07152
2025-08107
2025-0986
2025-10235
2025-11131
2025-12167
2026-01149
2026-02283
2026-03449
2026-04423
2026-05343
2026-06301
2026-07336
2026-08532
2026-09383

Vendors

Who shipped the most Security Products CVEs in Sep 2026 so far, with their rank across all vendors.

  1. Misp43#23
  2. Tanium28#42
  3. Misp-project20#52
  4. Openidentityplatform19#58
  5. Okta17#69
  6. Fortinet10#118
  7. Ivanti10#119
  8. Palo Alto Networks9#135

Weaknesses

The weakness classes behind Security Products CVEs in Sep 2026 so far.

  1. CWE-862 Missing Authorization56
  2. CWE-79 XSS29
  3. CWE-284 Improper Access Control28
  4. CWE-863 Incorrect Authorization21
  5. CWE-639 Auth Bypass via User Key20
  6. CWE-269 Improper Privilege Mgmt17

Latest CVEs

The 15 most recently published vulnerabilities in Security Products.

  1. CVE-2026-85984miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 - Unauthenticated Authentication Bypass via 'mo_wp_login_intent' Parameter9.8
  2. CVE-2026-100604ClawHub Authentication Bypass via Former Publisher Skill Control5.4
  3. CVE-2026-100602ClawHub Changelog Preview Information Disclosure via Authorization Bypass6.5
  4. CVE-2026-100603ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports5.4
  5. CVE-2026-100601ClawHub SSRF via Unchecked DNS Resolution in Profile Image5.3
  6. CVE-2026-100600ClawHub before 8c2de6c506 Quota Exhaustion via Anonymous API5.3
  7. CVE-2026-100583OpenClaw Discord before 2026.7.1 Authorization Bypass4.3
  8. CVE-2026-100582OpenClaw Channel Plugins before 2026.8.1 Channel Read Allowlist Bypass6.5
  9. CVE-2026-100575OpenClaw Slack before 2026.8.1 Authentication Bypass via Group DM8.8
  10. CVE-2026-100566OpenClaw LINE before 2026.8.1 Access Control Inheritance6.5
  11. CVE-2026-100541OpenClaw Matrix before 2026.8.1 Authorization Bypass via Case Folding7.5
  12. CVE-2026-100540OpenClaw Feishu before 2026.8.1 Authentication Bypass via Disabled Account6.8
  13. CVE-2026-100532openclaw WhatsApp before 2026.8.1 Authentication Bypass8.1
  14. CVE-2026-100531openclaw Slack before 2026.8.1 Authorization Bypass6.5
  15. CVE-2026-100526Vulnerability in discord5.3

The record

Busiest month
Aug 2026, 532 CVEs
Sep 2026 so far
383 CVEs from 77 vendors
Deployment
On-prem, 86%
Monthly snapshots
295 since 1999
All 15 sectors on one map

Is your business exposed to threats like these?

Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.

Request an assessment

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store