Lots of neat data in Cloudflare's year end report - perhaps (not too..) surprisingly though, the open source Log4j vulnerability is still being exploited - years after it was patched.
“As a three-year-old vulnerability, it may be assumed that organizations have had ample time to patch their systems,” David Belson told me.