HomeSecurityMITRE: The new list of the 25 most dangerous software bugs

MITRE: The new list of the 25 most dangerous software bugs

MITRE has shared this year's list of the top 25 software bugs (most common and dangerous). It's worth noting that from June 2023 (when the previous list was released) to June 2024, more than 31,000 vulnerabilities.

MITRE software errors

Software vulnerabilities refer to defects, bugs, vulnerabilities and errors found in the code, architecture, implementation or design of software.

Attackers can exploit them to compromise systems, which may allow them to gain control of affected devices, gain access to sensitive data, or launch DDoS attacks.

See also: Vulnerability in Atlassian Sourcetree allows code execution

MITRE warned that these bugs are easily discovered and can be exploited by various malicious actors.

“Uncovering the root causes of these vulnerabilities serves as a powerful guide for investments, policies, and practices to prevent them from occurring in the first place. This would work to the benefit of both industry and government agencies.“.

Understanding and addressing these vulnerabilities is crucial to maintaining strong practices cybersecurity. Regularly updating software and conducting rigorous security audits can help identify and patch these weaknesses before they can be exploited by malicious actors. Additionally, implementing secure coding practices and educating developers about the importance of security can significantly reduce the occurrence of these vulnerabilities in future software developments.

MITRE: The new list of the 25 most dangerous software bugs

To create this year's list of top software bugs, MITRE rated each vulnerability based on its severity and frequency, after analyzing 31,770 CVE entries for vulnerabilities reported in 2023 and 2024. Particular emphasis was placed on security flaws added to CISA's Known Exploited Vulnerabilities (KEV) list.

See also: Microsoft Zero Day Quest: Hacking event to find vulnerabilities in cloud and AI

“This annual list identifies the most critical software vulnerabilities that attackers often exploit to compromise systems, steal sensitive data , or disrupt essential services,” CISA added.

“Organizations are encouraged to review this list and use it to inform their software security strategies. Prioritizing these weaknesses helps avoid vulnerabilities at the core of the software lifecycle“.

RankIDNameScoreKEV CVEsChange
1CWE-79Cross-site Scripting56.923+1
2CWE-787Out-of-bounds Write45.2018-1
3CWE-89SQL Injection35.8840
4CWE-352Cross-Site Request Forgery (CSRF)19.570+5
5CWE-22Path Traversal12.744+3
6CWE-125Out-of-bounds Read11.423+1
7CWE-78OS Command Injection11.305-2
8CWE-416Use After Free10.195-4
9CWE-862Missing Authorization10.110+2
10CWE-434Unrestricted Upload of File with Dangerous Type10.0300
11CWE-94Code Injection7.137+12
12CWE-20Improper Input Validation6.781-6
13CWE-77Command Injection6.744+3
14CWE-287Improper Authentication5.944-1
15CWE-269Improper Privilege Management5.220+7
16CWE-502Deserialization of Untrusted Data5.075-1
17CWE-200Exposure of Sensitive Information to an Unauthorized Actor5.070+13
18CWE-863Incorrect Authorization4.052+6
19CWE-918Server-Side Request Forgery (SSRF)4.0520
20CWE-119Improper Operations Restriction in Memory Buffer Bounds3.692-3
21CWE-476NULL Pointer Dereference3.580-9
22CWE-798Use of Hard-coded Credentials3.462-4
23CWE-190Integer Overflow or Wraparound3.373-9
24CWE-400Uncontrolled Resource Consumption3.230+13
25CWE-306Missing Authentication for Critical Function2.735-5

Unfortunately, software bugs are an inevitable reality in the world of software development. However, their timely detection and response are essential for the security of systems.

See also: Google Chrome fixed critical vulnerabilities

Last week, the FBI, NSA, and Five Eyes cybersecurity authorities released a list of the top 15 most frequently exploited security vulnerabilities last year. The agencies warned that attackers focused on targeting zero-days.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Organizations must address these known vulnerabilities, but they must also remain vigilant against emerging threats. As technology advances, new vulnerabilities may emerge. Organizations must continually evaluate their systems and update their defenses accordingly.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS