logo

Top 10 web application vulnerabilities in 2021–2023

ID: cdfb70bf-eb61-5798-9527-b88ef357a583

STIX ID: report--cdfb70bf-eb61-5798-9527-b88ef357a583

Feed Name: Securelist by Kaspersky

Threat Score
50/100

Date Published: 2024-03-12

Date Updated: 2026-04-29

Author: Oxana Andreeva, Kaspersky Security Services

...
...

Kaspersky analyzed web application assessments from 2021–2023 and produced a Top 10 ranking of widespread vulnerabilities (Broken Access Control, Sensitive Data Exposure, SSRF, SQL Injection, XSS, Broken Authentication, Security Misconfiguration, Insufficient Brute-Force Protection, Weak User Passwords, and Using Components with Known Vulnerabilities), including prevalence statistics, risk-level distributions, illustrative examples and actionable mitigation advice to help organizations prioritize fixes and improve their SSDLC and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.