Flexera Software provides license management, software intelligence, and deployment automation platforms that span FlexNet Publisher, Code Insight, InstallShield, and related inventory and lifecycle-management tools, presenting a concentrated but strategically positioned attack surface across enterprise software supply chains. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur across resource-exhaustion, input-validation, and cross-site scripting weakness classes that are typical of web-facing management and analytics platforms. Defenders should prioritize updates to this vendor's tools, particularly those exposed to network access, since these products sit at the boundary between software deployment, licensing infrastructure, and configuration visibility; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flexera Software LLC over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20033CRITICAL A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory b | Feb 25, 2019 | 9.8 | 33 | NO | NO |
CVE-2018-20034HIGH A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attac | Mar 21, 2019 | 7.5 | 26 | NO | NO |
CVE-2018-20032HIGH A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to s | Mar 21, 2019 | 7.5 | 26 | NO | NO |
CVE-2021-41526HIGH A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of | Mar 29, 2023 | 7.8 | 25 | NO | NO |
CVE-2017-6894HIGH A vulnerability exists in FlexNet Manager Suite releases 2015 R2 SP3 and earlier (including FlexNet Manager Platform 9.2 and earlier) that affects the inventory gathering component | Mar 29, 2023 | 7.8 | 25 | NO | NO |
CVE-2018-20031HIGH A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attac | Mar 21, 2019 | 7.5 | 25 | NO | NO |
CVE-2016-2542HIGH Untrusted search path vulnerability in Flexera InstallShield through 2015 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory of a set | Feb 24, 2016 | 7.8 | 25 | NO | NO |
CVE-2019-8963HIGH A Denial of Service (DoS) vulnerability was discovered in FlexNet Publisher's lmadmin 11.16.5, when doing a crafted POST request on lmadmin using the web-based tool. | Mar 29, 2023 | 7.5 | 24 | NO | NO |
CVE-2020-12083CRITICAL An elevated privileges issue related to Spring MVC calls impacts Code Insight v7.x releases up to and including 2020 R1 (7.11.0-64). | Sep 17, 2021 | 9.9 | 24 | NO | NO |
CVE-2020-12080HIGH A Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6. A certain message protocol can be exploited to cause lmadmin to crash. | Sep 17, 2021 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flexera Software LLC.
Media articles that mention a CVE ID that affects a product developed by Flexera Software LLC — matched by CVE ID, not by vendor name.