Highlights the accelerating volume of open-source vulnerabilities and the growing need for automated vulnerability detection.
In 2024, the number of new vulnerabilities reached a record 40,009 CVEs, representing a 38% year-on-year increase and a 520% rise since 2016. An average of 108 CVE records were published daily. Much of this growth was driven by five CVE Numbering Authorities (CNAs) focused on open-source projects and WordPress plugins, which collectively published 43.67% of the year's CVEs. Additionally, a Synopsys report highlighted that 84% of analyzed codebases contained at least one known open-source vulnerability, with 74% harboring high-risk vulnerabilities.
40,009 CVEs published in 2024 (38% YoY increase) with 108 daily, driven heavily by open-source CNAs — packages with high recent vulnerability frequency demand immediate attention.
dependency on packages experiencing accelerating vulnerability discovery rates that outpace remediation capacity
the 520% increase in CVE volume since 2016 makes identifying packages with high recent vulnerability frequency essential to prioritize scarce remediation resources.
Investments in security testing, from automated scans to pentests, red team exercises and Bug Bounty, are duly increasing.
Risk Guard does not evaluate whether a repository participates in proactive security testing initiatives like bug bounties or public penetration tests.
Risk Guard would be better if it could detect the presence of a formal bug bounty program or linked third-party security audits.