Edgescan, an international provider of risk-based vulnerability management and penetration testing, has released its 2024 Vulnerability Statistics Report, revealing that critical vulnerabilities from as far back as 2015 continue to be exploited by malicious actors. The report underscores the persistent threat of unpatched systems and the urgent need for organizations to adopt comprehensive vulnerability management strategies.
The report found that more than 33% of vulnerabilities discovered during the reporting period were classified as critical or high severity. SQL Injection remains the most prevalent critical vulnerability in web applications, accounting for 19.47% of detected vulnerabilities and requiring an average of 15 days to remedy. Cross-Site Scripting (Stored) follows at 10.5% of high/critical security vulnerabilities, with an average remediation time of 100 days, potentially leading to stolen personal information or account takeovers. Additionally, Malicious File Upload, representing 7.25% of high/critical severity vulnerabilities, takes 117 days to fix and can enable attackers to upload viruses or malware onto websites.
Eoin Keary, Founder & CEO of Edgescan, emphasized the urgency of the findings: 'Our Vulnerability Statistics Report serves as a wake-up call to organizations across industries and around the world. Despite advancements in cybersecurity, the persistence of critical vulnerabilities from several years ago is a clear indication that organizations need to do much more to adopt and manage proactive and comprehensive vulnerability strategies.' The report highlights that vulnerabilities are not just new discoveries but also unresolved issues from years past, indicating a systemic failure in patch management and security hygiene.
The implications of this announcement are significant for businesses and nonprofits in the New York City metro area, a region heavily dependent on digital infrastructure. Organizations that fail to address these lingering vulnerabilities risk data breaches, financial losses, and reputational damage. The report’s data suggests that without a proactive approach, organizations remain exposed to attacks that exploit known weaknesses. For example, SQL injection vulnerabilities, which allow hackers to gain unauthorized access to private information and databases, remain a top threat, emphasizing the need for robust input validation and regular security testing.
Edgescan’s report serves as a critical resource for IT and security teams, offering insights into the most common vulnerabilities and their remediation timelines. By understanding these trends, organizations can prioritize patching and allocate resources more effectively. For more information and access to the full 2024 Vulnerability Statistics Report, visit Edgescan's website.
