{"id":10362,"date":"2020-11-13T07:00:00","date_gmt":"2020-11-13T15:00:00","guid":{"rendered":"http:\/\/formtek.com\/blog\/?p=10362"},"modified":"2020-08-23T12:54:58","modified_gmt":"2020-08-23T20:54:58","slug":"security-the-top-25-most-exploited-software-flaws","status":"publish","type":"post","link":"https:\/\/formtek.com\/blog\/security-the-top-25-most-exploited-software-flaws\/","title":{"rendered":"Security: The Top 25 Most Exploited Software Flaws"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Hacking and exploits have unfortunately become common-place hazards of working with computers.  <a href=\"https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2020\/08\/20\/2020-cwe-top-25-most-dangerous-software-weaknesses\" data-type=\"URL\" data-id=\"https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2020\/08\/20\/2020-cwe-top-25-most-dangerous-software-weaknesses\">The Department of Homeland Security (DHS) recently released the 2020 list<\/a> of most dangerous software vulnerabilities, a list that they&#8217;re calling the Common Weakness Enumeration (CWE).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The CWE report explains that &#8220;these weaknesses are dangerous because they are often easy to find, exploit, and can allow adversaries to completely take over a system, steal data, or prevent an application from working.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The ranking of the software vulnerabilities was determined based on a score that considered prevalence and severity (<a href=\"https:\/\/www.first.org\/cvss\/specification-document\" data-type=\"URL\" data-id=\"https:\/\/www.first.org\/cvss\/specification-document\">The Common Vulnerability Scoring System<\/a>).  The ranking gives an idea about which vulnerabilities are most commonly exploited by cybercriminals.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"768\" height=\"530\" src=\"http:\/\/formtek.com\/blog\/wp-content\/uploads\/2020\/08\/image-12.png\" alt=\"\" class=\"wp-image-10363\" srcset=\"https:\/\/formtek.com\/blog\/wp-content\/uploads\/2020\/08\/image-12.png 768w, https:\/\/formtek.com\/blog\/wp-content\/uploads\/2020\/08\/image-12-300x207.png 300w\" sizes=\"auto, (max-width: 768px) 100vw, 768px\" \/><figcaption>From: CWE, Common Weakness Enumeration<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The number one software flaw is <a href=\"https:\/\/outpost24.com\/blog\/How-identify-Cross-Site-Scripting-vulnerabilities\" data-type=\"URL\" data-id=\"https:\/\/outpost24.com\/blog\/How-identify-Cross-Site-Scripting-vulnerabilities\">Cross Site Scriptin<\/a>g.  The injection of code into the client communication with the server can  allow a cyberhacker to steal user identify, hijack accounts, steal credentials, access data, redirect content and introduce face content on the web site.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/nofluffjuststuff.com\/conference\/speaker\/steve_kosten\" data-type=\"URL\" data-id=\"https:\/\/nofluffjuststuff.com\/conference\/speaker\/steve_kosten\">Steve Kosten<\/a>, security consultant at cypress data defense, <a href=\"https:\/\/medium.com\/faun\/the-impact-of-cross-site-scripting-vulnerabilities-and-their-prevention-8ae6376ddbca\" data-type=\"URL\" data-id=\"https:\/\/medium.com\/faun\/the-impact-of-cross-site-scripting-vulnerabilities-and-their-prevention-8ae6376ddbca\">said that<\/a> &#8220;XSS, cross-site scripting, is one of the most common security vulnerabilities found in web applications and it can cause severe damage if not mitigated in a timely manner&#8230; What\u2019s worse is that victims of XSS attacks, both the user and the developer of the web application, often won\u2019t be aware that they\u2019re being attacked.&#8221;<\/p>\n<div class=\"lightsocial_container\"><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/digg.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-the-top-25-most-exploited-software-flaws%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/digg.png\" alt=\"Digg This\" title=\"Digg This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.reddit.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-the-top-25-most-exploited-software-flaws%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/reddit.png\" alt=\"Reddit This\" title=\"Reddit This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.stumbleupon.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-the-top-25-most-exploited-software-flaws%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/stumbleupon.png\" alt=\"Stumble Now!\" title=\"Stumble Now!\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/buzz.yahoo.com\/buzz?targetUrl=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-the-top-25-most-exploited-software-flaws%2F&amp;headline=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/yahoo_buzz.png\" alt=\"Buzz This\" title=\"Buzz This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dzone.com\/links\/add.html?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-the-top-25-most-exploited-software-flaws%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dzone.png\" alt=\"Vote on DZone\" title=\"Vote on DZone\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.facebook.com\/sharer.php?t=&amp;u=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-the-top-25-most-exploited-software-flaws%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/facebook.png\" alt=\"Share on Facebook\" title=\"Share on Facebook\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/delicious.com\/save?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-the-top-25-most-exploited-software-flaws%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/delicious.png\" alt=\"Bookmark this on Delicious\" title=\"Bookmark this on Delicious\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dotnetkicks.com\/kick\/?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-the-top-25-most-exploited-software-flaws%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetkicks.png\" alt=\"Kick It on DotNetKicks.com\" title=\"Kick It on DotNetKicks.com\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/dotnetshoutout.com\/Submit?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-the-top-25-most-exploited-software-flaws%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetshoutout.png\" alt=\"Shout it\" title=\"Shout it\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.linkedin.com\/shareArticle?mini=true&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-the-top-25-most-exploited-software-flaws%2F&amp;title=&amp;summary=&amp;source=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/linkedin.png\" alt=\"Share on LinkedIn\" title=\"Share on LinkedIn\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.technorati.com\/faves?add=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-the-top-25-most-exploited-software-flaws%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/technorati.png\" alt=\"Bookmark this on Technorati\" title=\"Bookmark this on Technorati\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/twitter.com\/home?status=Reading+https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-the-top-25-most-exploited-software-flaws%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/twitter.png\" alt=\"Post on Twitter\" title=\"Post on Twitter\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.google.com\/buzz\/post?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-the-top-25-most-exploited-software-flaws%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/google_buzz.png\" alt=\"Google Buzz (aka. Google Reader)\" title=\"Google Buzz (aka. Google Reader)\" \/><\/a><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>Hacking and exploits have unfortunately become common-place hazards of working with computers. The Department of Homeland Security (DHS) recently released the 2020 list of most dangerous software vulnerabilities, a list that they&#8217;re calling the Common Weakness Enumeration (CWE). The CWE<span class=\"ellipsis\">&hellip;<\/span><\/p>\n<div class=\"read-more\"><a href=\"https:\/\/formtek.com\/blog\/security-the-top-25-most-exploited-software-flaws\/\">Read more &#8250;<\/a><\/div>\n<p><!-- end of .read-more --><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-10362","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/10362","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/comments?post=10362"}],"version-history":[{"count":1,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/10362\/revisions"}],"predecessor-version":[{"id":10364,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/10362\/revisions\/10364"}],"wp:attachment":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/media?parent=10362"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/categories?post=10362"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/tags?post=10362"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}