Skip to main content
HomeTopicsVulnerabilities

Vulnerabilities

We've curated 267 cybersecurity statistics about Vulnerabilities to help you understand how software weaknesses and system flaws are being exploited by cybercriminals in 2025. This insight can guide you in fortifying your defenses effectively.

Showing 161-180 of 267 results

Each neglected cloud asset contains on average 115 vulnerabilities.

Orca Security6/5/2025
Cloud

36% of organizations have at least one cloud asset supporting more than 100 attack paths.

Orca Security6/5/2025
CloudAttack path

62% of organizations have at least one vulnerable AI package.

Orca Security6/5/2025
CloudAI

Top challenges in managing cloud vulnerabilities include Budget constraints (35%), Integrating vulnerability management with existing workflows (34%), and Lack of skilled personnel (32%).

Prowler6/4/2025
CloudVulnerability assessment

Organisations detect an average of 17 vulnerabilities in their cloud environments per week.

Prowler6/4/2025
CloudVulnerability assessment

46% of organisations still struggle with cloud vulnerability management.

Prowler6/4/2025
CloudVulnerability assessment

96% of organisations conduct regular cloud vulnerability assessments.

Prowler6/4/2025
CloudVulnerability assessment

67% of organisations conduct cloud vulnerability assessments monthly or more frequently.

Prowler6/4/2025
CloudVulnerability assessment

Recent research from Wiz highlights 6 known vulnerabilities with the underlying AI providers themselves.

FireTail6/1/2025
AI

A vulnerability in the Irish Government COVID-19 Vaccination Portal, present since December 2021, was disclosed in March 2024 and exposed the vaccination records of approximately one million residents.

FireTail6/1/2025
AIIreland

Assets hosted by Azure showed 0.07% with critical vulnerabilities.

CyCognito5/21/2025
CloudAzure

15% of assets hosted by AWS were vulnerable to at least one security issue or misconfiguration.

CyCognito5/21/2025
CloudAWS

Assets hosted by cloud providers other than AWS, Google, and Azure showed approximately 10 times higher rates of critical vulnerabilities compared to AWS, Google Cloud, and Azure.

CyCognito5/21/2025
Cloud

Critical vulnerabilities (CVSS 9.0 or higher) were detected on assets hosted by all cloud providers, though uncommon.

CyCognito5/21/2025
Cloud

Assets hosted by AWS and Google Cloud showed 0.04% with critical vulnerabilities.

CyCognito5/21/2025
CloudAWS

Alternative cloud and hosting providers showed rates ten times higher than AWS for assets with both critical and easily exploitable issues

CyCognito5/21/2025
Cloud

38% of assets hosted by Google Cloud were vulnerable to at least one security issue or misconfiguration. This rate for Google Cloud was over 2.5x more than assets hosted by AWS.

CyCognito5/21/2025
CloudGoogle Cloud

25% of developers report being overwhelmed by the volume of vulnerabilities.

Pynt5/21/2025
Shift Left

10% of assets on hosting providers other than AWS, Google, and Azure had easily exploitable vulnerabilities. This compares to 5 percent hosted on Google Cloud with easily exploitable vulnerabilities and just 2 percent on AWS and Azure with easily exploitable vulnerabilities.

CyCognito5/21/2025
Cloud

AWS showed the lowest rate for assets with both critical and easily exploitable issues at 0.02%.

CyCognito5/21/2025
CloudAWS