Edgescan Releases 2024 Vulnerability Statistics Report
Mean time to remediate most common critical vulnerabilities remains over 2 months
One of the most alarming findings: critical vulnerabilities from as far back as 2015 are still being discovered and leveraged today by malicious actors. This highlights the urgent need for organizations to prioritize vulnerability management and ensure their systems are adequately and proactively protected against these growing threats.
Additional findings from the 2023 report include:
- More than 33% of the vulnerabilities discovered during the reporting period were classified as 'critical' or 'high severity'.
- SQL Injection remains the foremost critical vulnerability in web applications, accounting for 19.47% of vulnerabilities detected and requiring 15 days to remedy. SQL Injection is where hackers force a website into providing access to private information and gain database access by manipulating query data.
- Cross-Site Scripting (Stored) was responsible for 10.5% of High/Critical Security Vulnerabilities and averaging 100 days to remedy. Cross-Site Scripting (Stored) can lead to stolen personal information like usernames and passwords, redirect users to malicious websites, or even take control of the user's account. It allows attackers to exploit the data that users have access to in a website, potentially leading to identity theft, financial loss, or other security breaches.
- Malicious File Upload was responsible for 7.25% of High/Critical Severity Vulnerabilities requiring 117 days to remedy. Malicious File Upload is when attackers upload viruses or malware onto a website, usually through forms or file upload features. These files can then be used to infect visitors' devices or compromise the security of the website itself.
By understanding the evolving threats and implementing effective safeguards, organizations can protect their systems and data from the devastating impact of ransomware, malware, and other malicious types of cyberattacks. Edgescan remains at the forefront of vulnerability management, helping organizations identify and remediate vulnerabilities before they can be exploited.
Methodology
The 2024 Vulnerability Statistics Report is Edgescan's ninth edition. Each year, Edgescan reviews the results of thousands of security assessments and penetration tests on millions of assets performed globally by the Edgescan Cybersecurity Platform. The Edgescan platform and team validate all vulnerabilities presented. Thus, this report provides a unique glimpse into the actual state of risk worldwide today.
About Edgescan
Edgescan's Risk-Based Vulnerability Management (RBVM) Platform provides comprehensive visibility into your digital enterprise via Network Security Testing, API Security Testing, Dynamic Application Security Testing (DAST), Mobile Application Security Testing (MAST), External Attack Surface Management (EASM), and Penetration Testing as a Service.
For more information and access to the full 2024 Vulnerability Statistics Report, visit Edgescan's website here.
To arrange an interview with Edgescan executives, please contact:
Vice President, Revenue Development & Operations
+1.917.565.9530
[email protected]
This press release was issued through 24-7PressRelease.com. For further information, visit http://www.24-7pressrelease.com.
View original content:https://www.prnewswire.com/news-releases/edgescan-releases-2024-vulnerability-statistics-report-302108941.html
SOURCE Edgescan
Serious News for Serious Traders! Try StreetInsider.com Premium Free!
You May Also Be Interested In
- Hanwha Power Marks U.S. Market with Successful Commissioning of Trumbull Energy Center CCGT
- Jocelyn Freimuth and Camino Compass to Lead First-Ever Qualified Evaluator Workshop at Compounding360 Studio Sessions
- OCI N.V. confirms receipt of unsolicited voluntary cash offer from NNS of EUR 4.10 per Share
Create E-mail Alert Related Categories
PRNewswire, Press ReleasesSign up for StreetInsider Free!
Receive full access to all new and archived articles, unlimited portfolio tracking, e-mail alerts, custom newswires and RSS feeds - and more!



Tweet
Share