CVE System Fails to Score Majority of Vulnerabilities
Article Content
Browse articles
A report by Sonatype reveals that the Common Vulnerabilities and Exposures (CVE) system is unable to score nearly two-thirds (64%) of the 1,552 open source vulnerabilities disclosed in 2025. This inadequacy affects the ability of organizations to assess and prioritize security risks effectively. The findings indicate a growing disconnect between the CVE system and the rapid pace of modern software development.
Ask AI about this cluster
Answers cite the sources they use
Updated 193d ago How this analysis works
More articles in this cluster (3)
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
Log4j2 Deserialization Bypass Enables Remote Code Execution Recent research has revealed a vulnerability in Apache Log4j2 that allows remote code execution (RCE) through unsafe Java deserialization. The issue affects versions 2.11.0 to 2.26.1 of log4j-api and 2.8.0 to 2.26.1 of log4j-core, specifically in configurations that deserialize serialized LogEvent objects from…