Edgescan 2023 Vulnerability Statistics Report
The 2023 report is our 8th edition and provides a statistical model of the most common weaknesses 
faced by organizations across the globe to enable data-driven decisions 
for managing risks and exposures more effectively. 
 
This year's report delves into Risk Density, Mean Time to Remediate (MTTR) critical vulnerabilities, and the convergence of vulnerability management and penetration testing output. The report outlines the importance of visibility in controlling risks, as well as the need for patching and maintenance in protecting against known exploitables.
Additionally, the report emphasizes the importance of Risk Based Vulnerability Management, taking into account asset criticality to prioritize risks, and the difference between compliance and security. Finally, the report provides insight into the most common vulnerabilities in the web application, API, and Device/Host layers and how to prioritize them for remediation.
Interesting Findings Include:
- Non-internet facing systems have a significant risk density
- Mean Time To Remediation (MTTR) for Critical Severity vulnerabilities is 65 day
- 1/3 of all vulnerabilities across the full stack discovered in 2022 were either High or Critical Severity
- The most common application layer and API vulnerabilities are still Injection related
- 13.5% of vulnerabilities in an enterprise’s backlog are either high or critical severity
- 12% of all Risk accepted vulnerabilities in 2022 were considered (in isolation) Critical Risks
Mean Time to Remediate by Industry

Get Your Copy
Edgescan requires the data you provide in order to share product information. By submitting this form, you agree to our collection and use of your information in accordance with our Privacy Policy. You may opt out at any time.

