Action1, a provider of autonomous endpoint management (AEM) solutions, has released its 2025 Software Vulnerability Ratings Report, revealing a 61% year-over-year surge in discovered software vulnerabilities and a 96% spike in exploited vulnerabilities throughout 2024.
Based on analysis of data from NVD and CVEdetails.com, the report highlights vulnerability trends over the past year, identifying which software categories are most at risk – and most exploited.
With vulnerability volumes and exploitation rates spiking across key tools widely used in modern enterprise environments, the research seeks to equip security leaders with insights needed to navigate the growing, complex threat landscape and prioritise proactive security measures.
Key Vulnerability Trends and Threat Areas
The report reveals a dramatic escalation in security risks across multiple software categories, underscoring the widening attack surface facing organisations.
In 2024, the total number of discovered software vulnerabilities jumped by 61% year-on-year, while critical vulnerabilities increased by 37.1%.
Further, the number of known exploited vulnerabilities nearly doubled over the year — a 96% rise that points to heightened activity among threat actors and the growing frequency of real-world attacks.
Linux and macOS systems have become major targets. Vulnerabilities in Linux surged by a staggering 967%, while macOS flaws rose by 95%, signalling a marked shift in attacker focus toward UNIX-based systems.
Web browsers and Microsoft Office applications also came under intensified pressure. Exploits in browsers increased by 657%, with Chrome topping the list of products under attack. Office applications saw a 433% rise in exploits, making them one of the fastest-growing threat categories.
Database platforms weren’t spared either. Vulnerabilities in database software grew by 213% year-on-year, with critical flaws spiking by 505%. Platforms like MSSQL and MySQL now represent a significant and expanding risk to enterprise data environments.
The Action1 report also points to a shift in how software vendors handle CVE attribution, adding new layers to the vulnerability management challenge.
Recommended reading
- Data Security Holding Back Growth for UK Financial Services Firms
- DIGIT FS Tech Summit | Back to Basics for An AI Future
- UK Finance Chiefs Bet Big on AI – Is The Workforce Ready?
As organisations navigate this increasingly volatile threat environment, taking a proactive stance on patch management, risk assessment, and overall security hygiene is no longer optional – it’s foundational.
“The findings in this year’s report confirm a seismic shift in the cyber threat landscape, which many security professionals have sensed— attackers move faster than manual processes can respond,” said Mike Walters, President and Co-Founder at Action1.
“To stay ahead, organisations must embrace more autonomous, scalable approaches to vulnerability remediation and adopt a mindset of continuous security readiness. Our report offers the data-driven clarity leaders need to recalibrate risk priorities before threats become breaches.”





