Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Flexera Software LLC

First CVE: Feb 24, 2016Active for: 10 yearsTotal CVEs: 16
39.3
VTI Score
Medium

Flexera Software provides license management, software intelligence, and deployment automation platforms that span FlexNet Publisher, Code Insight, InstallShield, and related inventory and lifecycle-management tools, presenting a concentrated but strategically positioned attack surface across enterprise software supply chains. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur across resource-exhaustion, input-validation, and cross-site scripting weakness classes that are typical of web-facing management and analytics platforms. Defenders should prioritize updates to this vendor's tools, particularly those exposed to network access, since these products sit at the boundary between software deployment, licensing infrastructure, and configuration visibility; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Flexera Software LLC over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 24, 2016
10 years ago
Most Recent CVE
Jan 26, 2024
910 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-20033CRITICAL
A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory b
Feb 25, 20199.833NONO
CVE-2018-20034HIGH
A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attac
Mar 21, 20197.526NONO
CVE-2018-20032HIGH
A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to s
Mar 21, 20197.526NONO
CVE-2021-41526HIGH
A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of
Mar 29, 20237.825NONO
CVE-2017-6894HIGH
A vulnerability exists in FlexNet Manager Suite releases 2015 R2 SP3 and earlier (including FlexNet Manager Platform 9.2 and earlier) that affects the inventory gathering component
Mar 29, 20237.825NONO
CVE-2018-20031HIGH
A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attac
Mar 21, 20197.525NONO
CVE-2016-2542HIGH
Untrusted search path vulnerability in Flexera InstallShield through 2015 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory of a set
Feb 24, 20167.825NONO
CVE-2019-8963HIGH
A Denial of Service (DoS) vulnerability was discovered in FlexNet Publisher's lmadmin 11.16.5, when doing a crafted POST request on lmadmin using the web-based tool.
Mar 29, 20237.524NONO
CVE-2020-12083CRITICAL
An elevated privileges issue related to Spring MVC calls impacts Code Insight v7.x releases up to and including 2020 R1 (7.11.0-64).
Sep 17, 20219.924NONO
CVE-2020-12080HIGH
A Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6. A certain message protocol can be exploited to cause lmadmin to crash.
Sep 17, 20217.520NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
19%
69%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (31.3%)
Network11 (68.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (93.8%)
Unknown0 (0.0%)
Required1 (6.3%)
Privileges Required
Low7 (43.8%)
High0 (0.0%)
None9 (56.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Flexera Software LLC.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Flexera Software LLC — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Flexera Software LLC's Products

View all 1 CNAs →

Top CWEs