MITRE has shared this year's list of the top 25 software bugs (most common and dangerous). It's worth noting that from June 2023 (when the previous list was released) to June 2024, more than 31,000 vulnerabilities.

Software vulnerabilities refer to defects, bugs, vulnerabilities and errors found in the code, architecture, implementation or design of software.
Attackers can exploit them to compromise systems, which may allow them to gain control of affected devices, gain access to sensitive data, or launch DDoS attacks.
See also: Vulnerability in Atlassian Sourcetree allows code execution
MITRE warned that these bugs are easily discovered and can be exploited by various malicious actors.
“Uncovering the root causes of these vulnerabilities serves as a powerful guide for investments, policies, and practices to prevent them from occurring in the first place. This would work to the benefit of both industry and government agencies.“.
Understanding and addressing these vulnerabilities is crucial to maintaining strong practices cybersecurity. Regularly updating software and conducting rigorous security audits can help identify and patch these weaknesses before they can be exploited by malicious actors. Additionally, implementing secure coding practices and educating developers about the importance of security can significantly reduce the occurrence of these vulnerabilities in future software developments.

To create this year's list of top software bugs, MITRE rated each vulnerability based on its severity and frequency, after analyzing 31,770 CVE entries for vulnerabilities reported in 2023 and 2024. Particular emphasis was placed on security flaws added to CISA's Known Exploited Vulnerabilities (KEV) list.
See also: Microsoft Zero Day Quest: Hacking event to find vulnerabilities in cloud and AI
“This annual list identifies the most critical software vulnerabilities that attackers often exploit to compromise systems, steal sensitive data , or disrupt essential services,” CISA added.
“Organizations are encouraged to review this list and use it to inform their software security strategies. Prioritizing these weaknesses helps avoid vulnerabilities at the core of the software lifecycle“.
| Rank | ID | Name | Score | KEV CVEs | Change |
|---|---|---|---|---|---|
| 1 | CWE-79 | Cross-site Scripting | 56.92 | 3 | +1 |
| 2 | CWE-787 | Out-of-bounds Write | 45.20 | 18 | -1 |
| 3 | CWE-89 | SQL Injection | 35.88 | 4 | 0 |
| 4 | CWE-352 | Cross-Site Request Forgery (CSRF) | 19.57 | 0 | +5 |
| 5 | CWE-22 | Path Traversal | 12.74 | 4 | +3 |
| 6 | CWE-125 | Out-of-bounds Read | 11.42 | 3 | +1 |
| 7 | CWE-78 | OS Command Injection | 11.30 | 5 | -2 |
| 8 | CWE-416 | Use After Free | 10.19 | 5 | -4 |
| 9 | CWE-862 | Missing Authorization | 10.11 | 0 | +2 |
| 10 | CWE-434 | Unrestricted Upload of File with Dangerous Type | 10.03 | 0 | 0 |
| 11 | CWE-94 | Code Injection | 7.13 | 7 | +12 |
| 12 | CWE-20 | Improper Input Validation | 6.78 | 1 | -6 |
| 13 | CWE-77 | Command Injection | 6.74 | 4 | +3 |
| 14 | CWE-287 | Improper Authentication | 5.94 | 4 | -1 |
| 15 | CWE-269 | Improper Privilege Management | 5.22 | 0 | +7 |
| 16 | CWE-502 | Deserialization of Untrusted Data | 5.07 | 5 | -1 |
| 17 | CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | 5.07 | 0 | +13 |
| 18 | CWE-863 | Incorrect Authorization | 4.05 | 2 | +6 |
| 19 | CWE-918 | Server-Side Request Forgery (SSRF) | 4.05 | 2 | 0 |
| 20 | CWE-119 | Improper Operations Restriction in Memory Buffer Bounds | 3.69 | 2 | -3 |
| 21 | CWE-476 | NULL Pointer Dereference | 3.58 | 0 | -9 |
| 22 | CWE-798 | Use of Hard-coded Credentials | 3.46 | 2 | -4 |
| 23 | CWE-190 | Integer Overflow or Wraparound | 3.37 | 3 | -9 |
| 24 | CWE-400 | Uncontrolled Resource Consumption | 3.23 | 0 | +13 |
| 25 | CWE-306 | Missing Authentication for Critical Function | 2.73 | 5 | -5 |
Unfortunately, software bugs are an inevitable reality in the world of software development. However, their timely detection and response are essential for the security of systems.
See also: Google Chrome fixed critical vulnerabilities
Last week, the FBI, NSA, and Five Eyes cybersecurity authorities released a list of the top 15 most frequently exploited security vulnerabilities last year. The agencies warned that attackers focused on targeting zero-days.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Organizations must address these known vulnerabilities, but they must also remain vigilant against emerging threats. As technology advances, new vulnerabilities may emerge. Organizations must continually evaluate their systems and update their defenses accordingly.
Source: www.bleepingcomputer.com
