Now that 2015 is officially over, let's take a look back at what happened over the past year in terms of critical or very critical security vulnerabilities.
During the last 365 days (of 2015) independent security researchers, cybersecurity firms, and even software vendors reported security vulnerabilities, and, where appropriate, requested a CVE (Common Vulnerabilities and Exposures) identifier.

These CVE numbers are used to track security vulnerabilities across products all year round, and if you’ve been around INFOSEC circles for any length of time, you understand how important a security researcher’s job can be.
According to CVE Details, a website that maintains an inventory of vulnerabilities based on CVE identifiers, during 2015, the company with the most new CVE numbers was Apple.
Security researchers discovered 654 security vulnerabilities in Apple products, 83 more security flaws than the 571 total vulnerabilities at Microsoft, the company that came in second.
The rest of the Top 10 continues with Cisco – 488 security bugs, Oracle – 479 bugs, Adobe – 460 bugs, Google – 323 bugs, IBM – 312 bugs, Mozilla – 188 bugs, Canonical – 153 bugs and Novell – 143 bugs.
If you’re wondering where Apple in the last few years, IBM was in that position in 2014 (455 bugs), Oracle in 2013 (496 bugs), Oracle again in 2012 (380 bugs), and Google in 2011 (295 bugs). Between 1999 and 2010, Microsoft “won” the title every year.
As for software products, an Apple product also won that title, with the OS X operating system coming in first with 384 security bugs and iOS coming in second, with 375 bugs.
Third on the list is Adobe Flash Player, which many security experts expected to come first, especially after the large number of security flaws that had surfaced after the Hacking Team data breach. In 2015, Flash had “only” 316 security flaws.
The rest of the Top 10 is as follows: Adobe AIR – 246 security flaws, Internet Explorer – 231 flaws, Google Chrome – 187 flaws, Mozilla Firefox – 178 flaws, Windows Server 2012 – 155 flaws, Ubuntu – 152 flaws, and Windows 8.1 – 151 flaws.
In previous years, the software products that were most vulnerable were: Internet Explorer in 2014 (243 bugs), Linux Kernel in 2013 (189 bugs), Google Chrome in 2012 (249 bugs), Google Chrome again in 2011 (266 bugs), Google Chrome for the third consecutive year in 2010 (152 bugs), Mozilla Firefox in 2009 (126 bugs), Mozilla Firefox bundled with Apple OS X in 2008 (96 bugs), PHP in 2007 (114 bugs), Apple OS X in 2006 (106 bugs), Linux Kernel in 2005 (133 bugs), Internet Explorer in 2004 (59 bugs), Solaris OS in 2003 (44 bugs), Internet Explorer in 2002 (54 bugs), RedHat Linux in 2001 (47 bugs), RedHat Linux again in 2000 (47 bugs) and Windows NT. in 1999 (64 bugs).
As you can see, Flash was never as "vulnerable" as we thought!
