Over 40,000 CVEs Published in 2024, Marking a 38% Increase from 2023

The year 2024 marked a significant milestone in cybersecurity, featuring an extraordinary surge in Common Vulnerabilities and Exposures (CVE) data.

With the release of over 40,000 CVEs, the industry has seen a dramatic increase of more than 38% compared to the 28,818 CVEs published in 2023.

CVEs By The Numbers

The statistics from 2024 reveal an average of 108 CVEs published daily. May stood out as the month with the highest activity, recording a total of 5,010 CVEs—12.5% of the yearly total.

Notably, Tuesdays emerged as the leading days for publishing, accounting for 9,706 CVEs, or 24.3% of the year’s releases. The peak day was May 3, when 824 CVEs were published in just 24 hours.

Monthly Breakdown of CVEs

MonthCVEsPercentage
January25936.5
February27786.9
March33108.3
April36229.1
May501012.5
June30807.7
July31247.8
August29007.2
September25226.3
October35738.9
November405810.1
December34398.6

Weekly Breakdown of CVEs

DayCVEsPercentage
Monday644916.1
Tuesday970624.3
Wednesday714317.9
Thursday632115.8
Friday710017.7
Saturday18584.6
Sunday14323.6

Top CVE Publishing Days

The most active days for CVE publications included:

DateCVEs
May 3, 2024845
May 14, 2024824
July 9, 2024471
May 21, 2024436
October 21, 2024436
November 22, 2024385
April 9, 2024384
November 19, 2024383
December 12, 2024341
November 12, 2024333

CVE Growth Analysis

This year marks the seventh consecutive year of record-high CVE publications since 2017, with 40,009 CVEs released, an increase of 38.83% from the previous year.

Notably, 15.32% of all CVEs released to date occurred in 2024 alone.

The average CVSS (Common Vulnerability Scoring System) score for vulnerabilities in 2024 was 6.67.

A significant finding was the 231 vulnerabilities that achieved a perfect score of 10.0, while CVE-2024-2365 recorded the lowest published CVSS score of 1.6.

In 2024, a total of 19,807 distinct CPEs were recorded in CVEs. The most prevalent CPE was cpe:2.3:o:linux:linux_kernel::::::::*, which appeared 8,093 times.

The vulnerability CVE-2024-20433, associated with Cisco’s IOS Software, led with the highest number of unique vulnerable configurations at 2,434.

Role of CVE Numbering Authorities (CNAs)

There are currently 433 CNAs authorized to assign CVE IDs, with 350 having published at least one CVE this year. The top five CNAs include:

CNAPublished CVEsOverall Percentage
Patchstack4,56611.41
Kernel.org4,32510.81
Wordfence3,5258.81
VulDB2,9367.34
GitHub2,1215.30

Together, these five CNAs accounted for 43.67% of all CVEs in 2024, primarily focusing on open-source projects and WordPress plugins.

Common Weakness Enumeration (CWE)

In 2024, 237 out of 940 CWEs were assigned to CVEs, with CWE-79 being the most frequent at 6,227 assignments (15.56%). The NVD categorized 6,292 CVEs as lacking CWE information.

A noteworthy 695 rejected CVEs were removed from this year’s dataset.

For ongoing insights and data visualization, interested parties can explore the GitHub repository featuring Jupyter notebooks related to this analysis.

CVE.ICU, an open-source project curated by the author, continues to track these data points in real-time, ensuring stakeholders remain informed on the evolving landscape of CVE data.

Also Read:

Kaaviya
Kaaviyahttps://cyberpress.org/
Kaaviya is a Security Editor and fellow reporter with Cyber Press. She is covering various cyber security incidents happening in the Cyber Space.

Recent Articles

Related Stories

LEAVE A REPLY

Please enter your comment!
Please enter your name here