Skip to content
Appaloosa Scout
Language selector
fr en

Annual recap

App security · 2024

2024 recap indexed by Appaloosa Scout: 2,049 CVEs published during the year on tracked apps, 45 added to the CISA KEV catalog (exploited in the wild), 9 apps affected by at least one KEV.

See multi-year trends in the Threat Observatory

CVE indexed this year
2,049
CISA KEV added
45
Tracked apps affected
9

Severity distribution

CRITICAL 99
HIGH 1,408
MEDIUM 481
LOW 61

Top 10 KEVs of the year

Sorted by CVSS severity. “Apps” counts tracked catalog apps: many KEVs are OS-level and legitimately show 0.

CVE Severity
CVE-2024-9680
2 apps
CRITICAL 9.8
CVE-2014-0497
2 apps
CRITICAL 9.8
CVE-2024-4577
0 apps
CRITICAL 9.8
CVE-2024-21410
0 apps
CRITICAL 9.8
CVE-2023-29357
0 apps
CRITICAL 9.8
CVE-2024-7971
3 apps
CRITICAL 9.6
CVE-2024-5274
2 apps
CRITICAL 9.6
CVE-2024-4947
2 apps
CRITICAL 9.6
CVE-2024-4671
2 apps
CRITICAL 9.6
CVE-2024-7965
2 apps
HIGH 8.8

Top vendors by KEV this year

  1. 1 Google LLC 10 KEV · 1 apps
  2. 2 Mozilla 1 KEV · 2 apps
  3. 3 Authy 1 KEV · 1 apps
  4. 4 Microsoft 1 KEV · 1 apps
  5. 5 Microsoft Corporation 1 KEV · 1 apps
  6. 6 Microsoft Office 1 KEV · 1 apps

Most affected apps

Methodology

KEV: added to the CISA catalog during the year (kev_added_date). CVE: NVD publication date. Apps: those indexed in Scout at query time; the history evolves as new mappings are added.