Vulnerabilities in web applications increased by 17.6% in 2019 compared to 2018. Almost half of vulnerabilities (47%) have a public exploit available to hackers. Injections (28.1%) were the most common vulnerabilities seen in 2019. Remote command execution (RCE) was the bigger issue, with 3,869 vulnerabilities (19%), compared to 1,610 vulnerabilities (8%) for SQLi. Remote Code/Command Execution (393 vulnerabilities) was runner-up with 157 new vulnerabilities.”]
Source: https://informationsecuritybuzz.com/articles/the-state-of-vulnerabilities-in-2019/

