More Software Vulnerabilities Disclosed in 2016 Than Ever Before

1 - More Software Vulnerabilities Disclosed in 2016 Than Ever Before
2 - The Number of Vulnerabilities Keeps Rising
3 - Vulnerability Impact Varies
4 - Vulnerabilities Were More Severe in 2016
5 - Most Vulnerabilities Are Verified by Vendors
6 - Bug Bounty Programs Are Finding More Flaws
7 - Vendor Response Times Vary
8 - XSS is the Most Common Web Vulnerability
1 of 8

More Software Vulnerabilities Disclosed in 2016 Than Ever Before

Risk Based Security's software vulnerability report for 2016 shows find that the number of new flaws found during the year set a record and that bug bounty programs are an important source of new discoveries.

2 of 8

The Number of Vulnerabilities Keeps Rising

According to Risk Based Security's VulnDB vulnerability tracking system, there were 15,000 reported vulnerabilities in 2016, setting a new record.

3 of 8

Vulnerability Impact Varies

Not all of the vulnerabilities reported in any given year have the same impact. Common Vulnerabilities Scoring System (CVSS) scores, which attempt to measure the impact of a given vulnerability, have been trending higher in recent years, showing that both the volume and severity of vulnerabilities are on the rise.

4 of 8

Vulnerabilities Were More Severe in 2016

Looking specifically at 2016, 21.3 percent of vulnerabilities in VulnDB had a CVSS score of between 9.0 and 10.0.

5 of 8

Most Vulnerabilities Are Verified by Vendors

Of the vulnerabilities reported by VulnDB for the year, 80.1 percent were verified by a vendor, prior to being disclosed.

6 of 8

Bug Bounty Programs Are Finding More Flaws

According to VulnDB, since 2013, bug bounty programs have becoming a leading source of disclosures, outpacing vendors' own abilities to discover flaws.

7 of 8

Vendor Response Times Vary

Different vendors had different response rates for dealing with vulnerabilities in 2016. VulnDB tracks the rates with its Vulnerability Timeline and Exposure Metrics (VTEM) system. Google had the fasted response time at only three days.

8 of 8

XSS is the Most Common Web Vulnerability

Looking specifically at web vulnerabilities, Cross Site Scripting (XSS) accounted for 37 percent of reported web vulnerabilities in 2016, according to VulnDB.

Top White Papers and Webcasts