
The number of commercial codebases containing high-risk vulnerabilities integrated through open source components has increased dramatically year-on-year.
A report from Synopsys found almost three-quarters (74%) contained vulnerabilities that are being actively exploited, have proof-of-concepts (PoC), or are classified as remote code execution flaws. The number is up from 48% a year ago.