Solution sectors / consumer-software
Consumer Software
Consumer desktop software — browsers, media players, productivity apps and utilities — is installed on hundreds of millions of machines, making it a broad attack surface. This hub tracks CVEs across it.
Cumulative CVEs
22,571
across 292 monthly snapshots
Latest month
569 · proj
-59.4% MoM · +61.2% YoY
Peak month
1,401
Jun 26
KEV this month
0
40 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem85%
- Mixed15%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Consumer Software.
- CVE-2026-57990Microsoft Edge (Chromium-based) Information Disclosure Vulnerability7.4
- CVE-2026-57989Microsoft Edge (Chromium-based) Information Disclosure Vulnerability7.4
- CVE-2026-57978Microsoft Edge (Chromium-based) Spoofing Vulnerability5.4
- CVE-2026-66012SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP10.0
- CVE-2026-16802Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via s...6.5
- CVE-2026-16801Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permissi...8.8
- CVE-2026-16800Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permis...8.8
- CVE-2026-16799Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute aut...5.0
- CVE-2026-16798Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read per...6.5
- CVE-2026-16804Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. ...8.3
- CVE-2026-16805Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)8.8
- CVE-2026-16806Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)8.8
- CVE-2026-16807Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)8.8
- CVE-2026-65607SiYuan before v3.7.2 Path Traversal via /export/temp/6.5
- CVE-2026-65606SiYuan before v3.7.2 Cross-Site Scripting to RCE9.6
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| adobe | 93 | 14 | · |
| foxitsoftware | 28 | · | · |
| foxit software inc. | 28 | · | · |
| uvnc | 10 | 2 | · |
| mozilla | 6 | · | · |
| siyuan-note | 6 | · | · |
| actualbudget | 5 | · | · |
| devolutions | 5 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| productivity | 190 | 30 | · | 11 | — | 365 apps (77) · microsoft 365 apps for enterprise (77) · office 2021 (77) |
| browser | 147 | 18 | · | 4 | — | chrome (94) · microsoft edge (chromium-based) (48) · firefox (3) |
| — | 102 | 22 | · | 9 | — | coldfusion (16) · adobe commerce (14) · commerce (14) |
| file-utility | 56 | 2 | · | 15 | — | foxit pdf editor (28) · pdf editor (28) · pdf reader (28) |
| gaming | 1 | · | · | 1 | — | parsec (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification