Solution sectors / enterprise-software
Enterprise Software
Enterprise software — ERP, CRM, HR and finance, collaboration and IT service management — runs core business processes and holds sensitive corporate data. This hub tracks CVE trends across it.
itsm-monitoring · 293document-mgmt · 128collaboration-groupware · 42erp · 22hr-finance · 8crm · 7bi-reporting · 5
Cumulative CVEs
47,064
across 294 monthly snapshots
Latest month
1,054 · proj
-33.8% MoM · +82.7% YoY
Peak month
1,591
Aug 26
KEV this month
2
70 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem96%
- Mixed3%
- SaaS1%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Enterprise Software.
- CVE-2026-90842PHPGurukul Blood Donor Management System Login_Model.php cleartext storage in file3.7
- CVE-2026-90841PHPGurukul Blood Donor Management System Report Endpoint Report.php sql injection7.3
- CVE-2026-90840PHPGurukul Blood Donor Management System Admin Controllers Dashboard.php __construct improper authentication7.3
- CVE-2026-12756Multiple secuirty vulnerabilies addressed with IBM Business Automation Workflow August 20267.1
- CVE-2026-12758Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.5.4
- CVE-2026-12759Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.6.5
- CVE-2026-13265IBM MQ Managed File Transfer REST API is vulnerable to XML external entity injection6.8
- CVE-2026-13275IBM MQ Managed File Transfer is vulnerable to XML external entity injection7.1
- CVE-2026-13285IBM MQ Managed File Transfer is vulnerable to XML external entity injection7.1
- CVE-2026-13293IBM MQ Java messaging is vulnerable to remote code execution8.8
- CVE-2026-13287IBM MQ Managed File Transfer is vulnerable to XML external entity injection7.1
- CVE-2026-14275IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities6.3
- CVE-2026-14276IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities6.3
- CVE-2026-14277IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities6.3
- CVE-2026-19273The Dashboard of IBM Sterling B2B Integrator and IBM Sterling File Gateway are Vulnerable to Improper Access Control5.4
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| dell | 134 | 8 | · |
| ibm | 121 | 10 | · |
| grokability | 46 | · | · |
| itsourcecode | 28 | · | · |
| sap_se | 17 | 4 | · |
| siemens | 14 | 2 | · |
| commvault | 11 | 3 | · |
| librenms | 10 | · | · |
| kimai | 7 | · | · |
| snipeitapp | 6 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| itsm-monitoring | 293 | 23 | 2 | 33 | — | secure connect gateway 5.0 - appliance (104) · secure connect gateway 5.0 - application (103) · snipe-it (52) |
| document-mgmt | 128 | 1 | · | 9 | — | experience manager (104) · online medicine delivery system (5) · filerun (4) |
| collaboration-groupware | 42 | 5 | · | 10 | — | microsoft sharepoint server subscription edition (16) · sharepoint server (16) · reyrolle 7sr5 (9) |
| — | 22 | 1 | · | 3 | — | app connect enterprise (10) · websphere application server (5) · solidinvoice (4) |
| erp | 22 | 4 | · | 4 | — | sap s/4hana (finance for advanced payment management) (3) · dolibarr (2) · sage ar automation (2) |
| hr-finance | 8 | · | · | 2 | — | kimai (7) · graphina – charts and graphs for elementor (1) |
| crm | 7 | · | · | 6 | — | crm (2) · crmeb (2) · espocrm (1) |
| bi-reporting | 5 | · | · | 3 | — | openedx-platform (3) · metabase (1) · rentsyst (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification