Site icon TheCyberThrone

Top 15 Most Exploited Vulnerabilities in 2023

Advertisements

In a joint cybersecurity advisory, the security agencies across the world have identified the most exploited vulnerabilities of 2023. This advisory, coauthored by the Cybersecurity and Infrastructure Security Agency (CISA), FBI, NSA, Australian Cyber Security Centre (ACSC), Canadian Centre for Cyber Security (CCCS), and other national cybersecurity teams, highlights the critical CVEs (Common Vulnerabilities and Exposures) frequently targeted by malicious actors.

As per the notes In 2023, threat actors exploited a greater number of zero-day vulnerabilities compared to 2022, enabling them to conduct sophisticated operations against high-value targets.

Advertisements

The advisory lists the 15 most exploited vulnerabilities, revealing patterns in the types of systems and software that are most frequently targeted. Here are the vulnerabilities:

CVEVendorProduct(s)Vulnerability Type
CVE-2023-3519CitrixNetScaler ADC & NetScaler GatewayCode Injection
CVE-2023-4966CitrixNetScaler ADC & NetScaler GatewayBuffer Overflow
CVE-2023-20198CiscoIOS XE Web UIPrivilege Escalation
CVE-2023-20273CiscoIOS XEWeb UI Command Injection
CVE-2023-27997FortinetFortiOS & FortiProxy SSL-VPNHeap-Based Buffer Overflow
CVE-2023-34362ProgressMOVEit TransferSQL Injection
CVE-2023-22515AtlassianConfluence Data Center and ServerBroken Access Control
CVE-2021- 44228ApacheLog4j2Remote Code Execution (RCE)
CVE-2023-2868Barracuda NetworksESG ApplianceImproper Input Validation
CVE-2022-47966ZohoManageEngine Multiple ProductsRemote Code Execution
CVE-2023-27350PaperCutMF/NGImproper Access Control
CVE-2020-1472MicrosoftNetlogonPrivilege Escalation
CVE-2023-42793JetBrainsTeamCityAuthentication Bypass
CVE-2023-23397MicrosoftOffice OutlookPrivilege Escalation
CVE-2023-49103ownCloudgraphapiInformation Disclosur
Exit mobile version