Skip to content

Products › Server applications and development

Server applications and development

ERP, business applications and databases

ERP and CRM suites, business applications, business intelligence tools and databases.

For example: SAP NetWeaver, Oracle E-Business Suite, Metabase, SQL Server.

Category RSS feed

Pace of additions

Number of “Business apps and data” vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on October 3, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 9, 2025 to Oct 8, 20253
Oct 9, 2025 to Nov 7, 20253
Nov 8, 2025 to Dec 7, 20250
Dec 8, 2025 to Jan 6, 20262
Jan 7, 2026 to Feb 5, 20260
Feb 6, 2026 to Mar 7, 20260
Mar 8, 2026 to Apr 6, 20260
Apr 7, 2026 to May 6, 20261
May 7, 2026 to Jun 5, 20260
Jun 6, 2026 to Jul 5, 20262
Jul 6, 2026 to Aug 4, 20261
Aug 5, 2026 to Sep 3, 20262
Sep 4, 2026 to Oct 3, 2026 (in progress)0

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1

    MetabaseCVE-2026-72898

    Metabase SQL Injection Vulnerability

    Active CERT-FR alertHunt for compromise (CISA)

    CVSS severity 10.0critical

    Added Aug 11, 2026

  2. Rank 2

    Oracle E-Business SuiteCVE-2026-46817

    Oracle E-Business Suite Improper Privilege Management Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Jul 15, 2026

  3. Rank 3

    PTC Windchill and FlexPLMCVE-2026-12569

    PTC Windchill and FlexPLM Improper Input Validation Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Jun 25, 2026

  4. Rank 4

    Oracle PeopleSoftCVE-2026-35273

    Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Jun 12, 2026

  5. Rank 5

    Samsung MagicINFO ServerCVE-2024-7399

    Samsung MagicINFO 9 Server Path Traversal Vulnerability

    CVE from 2024, added in 2026

    CVSS severity 9.8critical

    Added Apr 24, 2026

  6. Rank 6

    OSGeo GeoServerCVE-2025-58360

    OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability

    CVSS severity 9.8critical

    Added Dec 11, 2025

  7. Rank 7

    Oracle E-Business SuiteCVE-2025-61882

    Oracle E-Business Suite Unspecified Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Oct 6, 2025

  8. Rank 8

    Dassault Systèmes DELMIA AprisoCVE-2025-6205

    Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability

    CVSS severity 9.1critical

    Added Oct 28, 2025

  9. Rank 9

    Microsoft SQL ServerCVE-2019-1068

    Microsoft SQL Server Remote Code Execution Vulnerability

    Hunt for compromise (CISA)CVE from 2019, added in 2026

    CVSS severity 8.8high

    Added Aug 26, 2026

  10. Rank 10

    Dassault Systèmes DELMIA AprisoCVE-2025-6204

    Dassault Systèmes DELMIA Apriso Code Injection Vulnerability

    CVSS severity 8.0high

    Added Oct 28, 2025

Show 62 more vulnerabilities
  1. Rank 11

    MongoDB ServerCVE-2025-14847

    MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability

    CVSS severity 7.5high

    Added Dec 29, 2025

  2. Rank 12

    Oracle E-Business SuiteCVE-2025-61884

    Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

    Ransomware

    CVSS severity 7.5high

    Added Oct 20, 2025

  3. Rank 13

    OSGeo GeoServerCVE-2022-24816

    OSGeo GeoServer JAI-EXT Code Injection Vulnerability

    CVE from 2022, added in 2024

    CVSS severity 10.0critical

    Added Jun 26, 2024

  4. Rank 14

    SAP NetWeaverCVE-2022-22536

    SAP Multiple Products HTTP Request Smuggling Vulnerability

    CVSS severity 10.0critical

    Added Aug 18, 2022

  5. Rank 15

    Redis ServerCVE-2022-0543

    Debian-specific Redis Server Lua Sandbox Escape Vulnerability

    CVSS severity 10.0critical

    Added Mar 28, 2022

  6. Rank 16

    Elastic KibanaCVE-2019-7609

    Kibana Arbitrary Code Execution

    CVE from 2019, added in 2022

    CVSS severity 10.0critical

    Added Jan 10, 2022

  7. Rank 17

    SAP NetWeaverCVE-2010-5326

    SAP NetWeaver Remote Code Execution Vulnerability

    CVE from 2010, added in 2021

    CVSS severity 10.0critical

    Added Nov 3, 2021

  8. Rank 18

    SAP NetWeaverCVE-2020-6287

    SAP NetWeaver Missing Authentication for Critical Function Vulnerability

    CVSS severity 10.0critical

    Added Nov 3, 2021

  9. Rank 19

    Qlik SenseCVE-2023-48365

    Qlik Sense HTTP Tunneling Vulnerability

    RansomwareCVE from 2023, added in 2025

    CVSS severity 9.9critical

    Added Jan 13, 2025

  10. Rank 20

    Qlik SenseCVE-2023-41265

    Qlik Sense HTTP Tunneling Vulnerability

    Ransomware

    CVSS severity 9.9critical

    Added Dec 7, 2023

  11. Rank 21

    MongoDB mongo-expressCVE-2019-10758

    MongoDB mongo-express Remote Code Execution Vulnerability

    CVE from 2019, added in 2021

    CVSS severity 9.9critical

    Added Dec 10, 2021

  12. Rank 22

    Samsung MagicINFO ServerCVE-2025-4632

    Samsung MagicINFO 9 Server Path Traversal Vulnerability

    CVSS severity 9.8critical

    Added May 22, 2025

  13. Rank 23

    SAP NetWeaverCVE-2025-31324

    SAP NetWeaver Unrestricted File Upload Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Apr 29, 2025

  14. Rank 24

    Hitachi Vantara Pentaho Business Analytics (BA) ServerCVE-2022-43939

    Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability

    CVE from 2022, added in 2025

    CVSS severity 9.8critical

    Added Mar 3, 2025

  15. Rank 25

    Apache HugeGraphCVE-2024-27348

    Apache HugeGraph-Server Improper Access Control Vulnerability

    CVSS severity 9.8critical

    Added Sep 18, 2024

  16. Rank 26

    Apache OFBizCVE-2024-38856

    Apache OFBiz Incorrect Authorization Vulnerability

    CVSS severity 9.8critical

    Added Aug 27, 2024

  17. Rank 27

    Apache OFBizCVE-2024-32113

    Apache OFBiz Path Traversal Vulnerability

    CVSS severity 9.8critical

    Added Aug 7, 2024

  18. Rank 28

    OSGeo GeoServerCVE-2024-36401

    OSGeo GeoServer GeoTools Eval Injection Vulnerability

    CVSS severity 9.8critical

    Added Jul 15, 2024

  19. Rank 29

    Progress Telerik Report ServerCVE-2024-4358

    Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability

    CVSS severity 9.8critical

    Added Jun 13, 2024

  20. Rank 30

    NextGen Healthcare Mirth ConnectCVE-2023-43208

    NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added May 20, 2024

  21. Rank 31

    Apache SupersetCVE-2023-27524

    Apache Superset Insecure Default Initialization of Resource Vulnerability

    CVSS severity 9.8critical

    Added Jan 8, 2024

  22. Rank 32

    Novi SurveyCVE-2023-29492

    Novi Survey Insecure Deserialization Vulnerability

    CVSS severity 9.8critical

    Added Apr 13, 2023

  23. Rank 33

    Oracle E-Business SuiteCVE-2022-21587

    Oracle E-Business Suite Unspecified Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Feb 2, 2023

  24. Rank 34

    Apache CouchDBCVE-2022-24706

    Apache CouchDB Insecure Default Initialization of Resource Vulnerability

    CVSS severity 9.8critical

    Added Aug 25, 2022

  25. Rank 35

    SAP NetWeaverCVE-2016-2386

    SAP NetWeaver SQL Injection Vulnerability

    CVE from 2016, added in 2022

    CVSS severity 9.8critical

    Added Jun 9, 2022

  26. Rank 36

    phpMyAdminCVE-2009-1151

    phpMyAdmin Remote Code Execution Vulnerability

    CVE from 2009, added in 2022

    CVSS severity 9.8critical

    Added Mar 25, 2022

  27. Rank 37

    Elastic ElasticsearchCVE-2015-1427

    Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability

    CVE from 2015, added in 2022

    CVSS severity 9.8critical

    Added Mar 25, 2022

  28. Rank 38

    IBM Planning Analytics (TM1)CVE-2019-4716

    IBM Planning Analytics Remote Code Execution Vulnerability

    CVE from 2019, added in 2021

    CVSS severity 9.8critical

    Added Nov 3, 2021

  29. Rank 39

    SAP Solution ManagerCVE-2020-6207

    SAP Solution Manager Missing Authentication for Critical Function Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

  30. Rank 40

    BQE BillQuick Web SuiteCVE-2021-42258

    BQE BillQuick Web Suite SQL Injection Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Nov 3, 2021

  31. Rank 41

    SAP NetWeaverCVE-2025-42999

    SAP NetWeaver Deserialization Vulnerability

    Ransomware

    CVSS severity 9.1critical

    Added May 15, 2025

  32. Rank 42

    Dassault Systèmes DELMIA AprisoCVE-2025-5086

    Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability

    CVSS severity 9.0critical

    Added Sep 11, 2025

  33. Rank 43

    Advantive VeraCoreCVE-2024-57968

    Advantive VeraCore Unrestricted File Upload Vulnerability

    CVSS severity 8.8high

    Added Mar 10, 2025

  34. Rank 44

    Oracle Agile PLMCVE-2024-20953

    Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability

    CVSS severity 8.8high

    Added Feb 24, 2025

  35. Rank 45

    Trimble CityworksCVE-2025-0994

    Trimble Cityworks Deserialization Vulnerability

    CVSS severity 8.8high

    Added Feb 7, 2025

  36. Rank 46

    Microsoft SQL ServerCVE-2020-0618

    Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

    RansomwareCVE from 2020, added in 2024

    CVSS severity 8.8high

    Added Sep 18, 2024

  37. Rank 47

    Apache SparkCVE-2022-33891

    Apache Spark Command Injection Vulnerability

    CVSS severity 8.8high

    Added Mar 7, 2023

  38. Rank 48

    SugarCRM Sugar (Sell, Serve, Enterprise)CVE-2023-22952

    Multiple SugarCRM Products Remote Code Execution Vulnerability

    CVSS severity 8.8high

    Added Feb 2, 2023

  39. Rank 49

    TIBCO JasperReportsCVE-2018-5430

    TIBCO JasperReports Server Information Disclosure Vulnerability

    CVE from 2018, added in 2022

    CVSS severity 8.8high

    Added Dec 29, 2022

  40. Rank 50

    SAP NetWeaverCVE-2021-38163

    SAP NetWeaver Unrestricted File Upload Vulnerability

    CVSS severity 8.8high

    Added Jun 9, 2022

  41. Rank 51

    Apache KylinCVE-2020-1956

    Apache Kylin OS Command Injection Vulnerability

    CVE from 2020, added in 2022

    CVSS severity 8.8high

    Added Mar 25, 2022

  42. Rank 52

    Justice AV Solutions (JAVS) JAVS ViewerCVE-2024-4978

    Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability

    CVSS severity 8.4high

    Added May 29, 2024

  43. Rank 53

    Acclaim Systems USAHERDSCVE-2021-44207

    Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability

    CVE from 2021, added in 2024

    CVSS severity 8.1high

    Added Dec 23, 2024

  44. Rank 54

    Elastic ElasticsearchCVE-2014-3120

    Elasticsearch Remote Code Execution Vulnerability

    CVE from 2014, added in 2022

    CVSS severity 8.1high

    Added Mar 25, 2022

  45. Rank 55

    SAP NetWeaverCVE-2017-12637

    SAP NetWeaver Directory Traversal Vulnerability

    CVE from 2017, added in 2025

    CVSS severity 7.5high

    Added Mar 19, 2025

  46. Rank 56

    Advantive VeraCoreCVE-2025-25181

    Advantive VeraCore SQL Injection Vulnerability

    CVSS severity 7.5high

    Added Mar 10, 2025

  47. Rank 57

    Apache OFBizCVE-2024-45195

    Apache OFBiz Forced Browsing Vulnerability

    CVSS severity 7.5high

    Added Feb 4, 2025

  48. Rank 58

    Oracle Agile PLMCVE-2024-21287

    Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability

    CVSS severity 7.5high

    Added Nov 21, 2024

  49. Rank 59

    MetabaseCVE-2021-41277

    Metabase GeoJSON API Local File Inclusion Vulnerability

    CVE from 2021, added in 2024

    CVSS severity 7.5high

    Added Nov 12, 2024

  50. Rank 60

    Apache FlinkCVE-2020-17519

    Apache Flink Improper Access Control Vulnerability

    CVE from 2020, added in 2024

    CVSS severity 7.5high

    Added May 23, 2024

  51. Rank 61

    Oracle Business Intelligence (OBIEE / BI Publisher)CVE-2020-14864

    Oracle Business Intelligence Enterprise Edition Path Transversal

    CVE from 2020, added in 2022

    CVSS severity 7.5high

    Added Jan 18, 2022

  52. Rank 62

    SAP NetWeaverCVE-2016-3976

    SAP NetWeaver Directory Traversal Vulnerability

    CVE from 2016, added in 2021

    CVSS severity 7.5high

    Added Nov 3, 2021

  53. Rank 63

    Apache SolrCVE-2019-17558

    Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability

    CVE from 2019, added in 2021

    CVSS severity 7.5high

    Added Nov 3, 2021

  54. Rank 64

    AdminerCVE-2021-21311

    Adminer Server-Side Request Forgery Vulnerability

    CVE from 2021, added in 2025

    CVSS severity 7.2high

    Added Sep 29, 2025

  55. Rank 65

    Hitachi Vantara Pentaho Business Analytics (BA) ServerCVE-2022-43769

    Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability

    CVE from 2022, added in 2025

    CVSS severity 7.2high

    Added Mar 3, 2025

  56. Rank 66

    Oracle Business Intelligence (OBIEE / BI Publisher)CVE-2019-2616

    Oracle BI Publisher Unauthorized Access Vulnerability

    CVE from 2019, added in 2022

    CVSS severity 7.2high

    Added Mar 25, 2022

  57. Rank 67

    Apache SolrCVE-2019-0193

    Apache Solr DataImportHandler Code Injection Vulnerability

    CVE from 2019, added in 2021

    CVSS severity 7.2high

    Added Dec 10, 2021

  58. Rank 68

    SAP CRMCVE-2018-2380

    SAP Customer Relationship Management (CRM) Path Traversal Vulnerability

    RansomwareCVE from 2018, added in 2021

    CVSS severity 6.6medium

    Added Nov 3, 2021

  59. Rank 69

    Qlik SenseCVE-2023-41266

    Qlik Sense Path Traversal Vulnerability

    Ransomware

    CVSS severity 6.5medium

    Added Dec 7, 2023

  60. Rank 70

    TIBCO JasperReportsCVE-2018-18809

    TIBCO JasperReports Library Directory Traversal Vulnerability

    CVE from 2018, added in 2022

    CVSS severity 6.5medium

    Added Dec 29, 2022

  61. Rank 71

    SAP NetWeaverCVE-2016-9563

    SAP NetWeaver XML External Entity (XXE) Vulnerability

    CVE from 2016, added in 2021

    CVSS severity 6.5medium

    Added Nov 3, 2021

  62. Rank 72

    SAP NetWeaverCVE-2016-2388

    SAP NetWeaver Information Disclosure Vulnerability

    CVE from 2016, added in 2022

    CVSS severity 5.3medium

    Added Jun 9, 2022

End of life: remove

These products are no longer supported: no patch is coming. Remove them or isolate them from the network.

  1. IBM InfoSphere BigInsightsCVE-2013-3993

    IBM InfoSphere BigInsights Invalid Input Vulnerability

    RansomwareEnd of lifeCVE from 2013, added in 2022

    CVSS severity 6.5medium

    Added May 25, 2022

  2. Checkbox SurveyCVE-2021-27852

    Checkbox Survey Deserialization of Untrusted Data Vulnerability

    End of life

    CVSS severity 9.8critical

    Added Apr 11, 2022

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.