Solution sectors / enterprise-software
Enterprise Software
Enterprise software — ERP, CRM, HR and finance, collaboration and IT service management — runs core business processes and holds sensitive corporate data. This hub tracks CVE trends across it.
itsm-monitoring · 52collaboration-groupware · 22document-mgmt · 11erp · 3crm · 3bi-reporting · 2hr-finance · 1
Cumulative CVEs
45,051
across 293 monthly snapshots
Latest month
271 · proj
-78.1% MoM · -56.1% YoY
Peak month
1,240
Jul 26
KEV this month
2
42 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem80%
- Mixed18%
- SaaS2%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Enterprise Software.
- CVE-2026-46731Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potenti...7.8
- CVE-2026-59914Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potenti...7.8
- CVE-2026-59917Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit ...7.8
- CVE-2026-59916Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit ...7.8
- CVE-2026-18499IBM WebSphere Application Server Liberty is affected by a privilege escalation8.1
- CVE-2026-47234Admidio writes session IDs and auto-login cookie values to application logs4.4
- CVE-2026-47233Admidio: Any logged-in user can delete inventory fields via `mode=field_delete` — incomplete fix of #20246.5
- CVE-2026-47232Admidio PKCS#12 private key export action lacks CSRF protection4.3
- CVE-2026-47231Admidio has IDOR in `documents-files.php` `mode=move_save` that lets any folder-uploader exfiltrate files from private folders8.1
- CVE-2026-47230Admidio: IDOR in documents-files.php allows cross-folder file rename and description changes by unauthorized uploaders6.5
- CVE-2026-47229Admidio: CSRF in SSO client `enable` action toggles SAML/OIDC clients without token validation5.4
- CVE-2026-47228Admidio's CSRF in registration `send_login` mode resets arbitrary user passwords5.2
- CVE-2026-47227Admidio module-administrator can delete or reorder categories owned by other modules via dead authorization check in `modules/categories.php`6.5
- CVE-2026-47226Admidio: Authorization bypass in file_delete enables cross-folder file removal by authenticated users without delete privileges6.5
- CVE-2026-14863FileRun 2026.2.0 RCE via Thumbnail Generation Command Injection8.8
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| ibm | 32 | · | · |
| progress software corporation | 10 | 7 | · |
| frappe | 9 | · | · |
| dell | 8 | 2 | · |
| itsourcecode | 8 | · | · |
| datadog | 6 | · | · |
| koha community | 6 | · | · |
| admidio | 5 | · | · |
| decidim | 5 | · | · |
| openemr | 5 | 1 | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| itsm-monitoring | 52 | 12 | 2 | 19 | — | marklogic server (10) · android app (6) · openemr (5) |
| collaboration-groupware | 22 | 1 | · | 6 | — | frappe (8) · admidio (5) · decidim (5) |
| document-mgmt | 11 | · | · | 5 | — | koha (6) · kodbox (2) · invoiceninja (1) |
| — | 11 | · | · | 3 | — | hospital management system (8) · crater (2) · websphere application server (1) |
| crm | 3 | · | · | 3 | — | erp (1) · groundhogg — crm, newsletters, and marketing automation (1) · pega infinity (1) |
| erp | 3 | · | · | 3 | — | e-logo purchasing portal (1) · erpnext (1) · warehouse (1) |
| bi-reporting | 2 | · | · | 2 | — | firefly-iii (1) · ghostfolio (1) |
| hr-finance | 1 | · | · | 1 | — | akaunting (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification