As seen abo e, the popularit of each CVE can be determined in diâferent a s, not
just based on number of posts, meaning it should be considered that a post can
receive many replies and raise interest or not receive any replies at all, while a wide
distribution of posts among a high number of forums in diâferent languages can also
provide information about the CVE’s popularity.
An additional interesting åfnding as disco ered hile checking the “Top ten CVEs”
b number of forums, as e identiåfed a CVE that as disclosed in 2012 - CVE-2012-
0158 (a ulnerabilit in Microsoft Oãfce, CVSS: 9.3)
10
, which has been mentioned in
nine diâferent forums bet een Januar 2020 and March 2021. Of note, it recei ed
onl 16 posts, and therefore, it is not among the “Top ten CVEs” b number of posts.
This æfa as e ploited b threat actors during the COVID-19 outbreak in 2020.
11
The fact that this æfa is still used b threat actors clearl pro es that organi ations
are not patching their systems and are not maintaining a resilient security posture.
The table belo presents the top mentioned CVE in the past åf e ears, according
to the ear it as disclosed:
https://www.cognyte.com/blog/what-you-need-to-know-about-the-top-4-global-ransomware-vulnerabilities-and-how-
to-stay-protected/
11.
https://n d.nist.go / uln/detail/CVE-2016-4437 - a æfa in Apache Shiro. 13.
https://n d.nist.go / uln/detail/CVE-2018-13379 - a æfa in Fortinet FortiOS: https:// .fortiguard.com/psirt/FG-IR-18-384 12.
10.
TOP MENTIONED CVES IN THE PAST FIVE YEARS
Disclosure Year % from all CVEs Top Mentoned CVE by Number of Posts
2020 56.3% CVE-2020-0796 (CVSS:10)
2019 17.3% CVE-2019-19781 (CVSS:9.8)
2018 7.8% CVE-2018-13379 (CVSS:9.8)
12
2017 6.3% CVE-2017-11882 (CVSS:7.8)
2016 1.9% CVE-2016-4437 (CVSS:8.1)
13
6 Vulnerability Threat Intelligence Report