CVE Analysis

How CVE volume, exploitation, and patch/exploit timing are trending over time

Metrics Over Time
Updating… Trailing windows

Each column counts CVEs published within that trailing window. Vendor / product / min-CVSS filters apply to the whole table.

Metric 1D1W30D90D1Y2Y5YAll
Volume
New CVEs 216 1,844 9,409 24,208 66,710 110,603 197,071 355,096
Critical (9.0+) 36 274 1,278 2,865 6,645 10,613 21,215 43,887
High (7.0–8.9) 69 628 3,892 10,040 25,072 40,011 71,651 127,396
Exploitation
Known Exploits 3 44 224 712 1,826 3,385 7,050 33,198
% With Exploit 1.4% 2.4% 2.4% 2.9% 2.7% 3.1% 3.6% 9.3%
Actively Exploited (KEV) 0 2 14 56 177 382 851 1,657
Exploited After Patch 1 7 41 115 262 419 818 8,957
% Post-Patch Exploit 0.5% 0.4% 0.4% 0.5% 0.4% 0.4% 0.4% 2.5%
0-Day (Before Patch) 2 17 25 33 65 189 239 14,493
Timing
Avg Days to Patch 28d 34d 38d 48d 93d 168d 140d 108d
Avg Days to Exploit 13d 37d 22d 55d 76d 136d 201d 263d
Total Tracked CVEs
New 24h
New 7d
Active Exploits / KEV
Exploited 24h
Exploited 7d
High Risk Prioritized
Critical
High

CVSS Severity Distribution

Dicing tomatoes…
% With Exploit
% Post-Patch Exploit
Median Days to Patch
discovery → disclosure
Median Days to Exploit
patch → exploit

Exploit Rate Over Time

⤢ expand
Seasoning with salt hashes…

% of CVEs per period with a known exploit.

Exploit Count Over Time

⤢ expand
Flambéing the firewall…

Absolute number of CVEs with a known exploit per period.

Days to Patch

⤢ expand
Brewing fresh queries…

Discovery → public disclosure (0–1825 day window).

Days: Patch → Exploit

⤢ expand
Fermenting the results…

Days from public patch to first known exploit/PoC.

CVE Surge — Possible AI-Assisted Bug Hunting Last 2 Quarters

Vendors and products active for 4+ years whose newly-published CVEs jumped sharply over the last ~180 days versus their own 5-year baseline — a pattern often tied to new AI-assisted bug-finding & fixing programs. This data doesn't reveal who is discovering the bugs — they may be found by the vendor's own teams or reported by external researchers. Jump is how many standard deviations the recent per-quarter rate sits above the historical quarterly mean, shown for both all CVEs (the sort order) and exploited CVEs. Δ Severity is the change in average CVSS base score — which may hint at the quality of the bugs being found or at how the vendor is prioritizing which issues to fix (a drop toward lower-severity bugs is also common with AI fuzzing noise). Each cell's small text is baseline → recent. Click any name to open it in the analysis filters below.

Top Vendors
# Vendor CVE Jump Expl Jump Δ Severity
1 parse-community 27.9σ 2.2→44.5/q -0.4σ0.1→0.0/q -0.4 7.4→7.0
2 Oracle Corporation 20.1σ 84.1→743.5/q 0.2σ2.3→2.5/q +1.8 5.8→7.6
3 Apache Software Foundation 14.4σ 56.0→260.5/q 8.4σ7.2→34.0/q -0.2 7.4→7.2
4 vercel 12.2σ 2.1→17.5/q 0.2σ0.4→0.5/q +0.1 6.1→6.2
5 google 10.1σ 197.7→1139.5/q 2.5σ9.5→21.5/q +0.1 7.1→7.1
6 craftcms 8.0σ 3.5→36.5/q -0.7σ0.4→0.0/q -0.2 6.6→6.4
7 microsoft 7.6σ 269.7→711.5/q 1.6σ19.5→28.5/q +0.1 7.3→7.4
8 dataease 7.5σ 3.9→21.0/q 1.7σ0.1→0.5/q -0.2 8.2→8.0
9 grafana 7.4σ 4.3→20.5/q 0.0σ0.5→0.5/q -0.2 6.6→6.4
10 Devolutions 7.3σ 6.1→32.0/q -0.6 6.5→6.0
11 discourse 6.5σ 10.4→46.0/q -0.5σ0.4→0.0/q -0.7 5.5→4.9
12 Wireshark Foundation 5.7σ 5.1→29.5/q -0.9 6.5→5.6
13 bytecodealliance 5.0σ 2.2→9.5/q -0.2σ0.1→0.0/q +0.5 5.2→5.6
14 checkpoint 4.5σ 2.0→6.5/q 3.6σ0.1→1.0/q +0.7 6.8→7.6
15 gnome 4.0σ 2.7→8.0/q -0.3σ0.1→0.0/q -0.5 7.0→6.5
16 ericsson 3.8σ 2.4→7.0/q -0.4σ0.1→0.0/q -0.2 6.9→6.7
17 ISC 3.8σ 3.2→10.0/q 0.3σ0.3→0.5/q -0.2 7.2→7.1
18 Mattermost 3.8σ 17.4→61.5/q 1.3σ0.1→0.5/q +0.5 4.7→5.2
19 Rapid7 3.7σ 2.7→11.5/q -0.4σ0.1→0.0/q +1.4 5.5→6.9
20 djangoproject 3.4σ 2.9→10.0/q -0.9σ0.5→0.0/q -2.3 7.2→4.8
Top Products
# Product CVE Jump Expl Jump Δ Severity
1 parse-server 30.2σ 2.1→42.5/q -0.4σ0.1→0.0/q -0.6 7.5→6.9
2 Chrome 24.7σ 65.0→1029.0/q 5.7σ3.5→17.5/q -0.5 7.6→7.1
3 Microsoft SharePoint Server Subscription Edition 14.4σ 5.8→42.5/q 2.6σ0.6→2.5/q -1.0 7.6→6.7
4 Microsoft SharePoint Enterprise Server 2016 10.5σ 6.7→43.0/q 2.8σ0.6→3.0/q -1.0 7.7→6.7
5 zephyr 10.2σ 4.9→36.0/q 4.0σ0.1→1.0/q -1.0 7.1→6.1
6 Microsoft SharePoint Server 2019 9.9σ 7.1→43.5/q 2.4σ0.6→3.0/q -0.9 7.6→6.7
7 Visual Studio Code 9.1σ 1.7→8.0/q -0.6σ0.3→0.0/q +0.3 7.3→7.6
8 server 8.9σ 5.1→33.5/q -0.2 6.4→6.2
9 cms 8.3σ 9.3→57.0/q 0.0σ0.5→0.5/q +0.6 5.6→6.2
10 WebSphere Application Server 7.9σ 2.6→16.0/q +2.0 5.7→7.7
11 discourse 7.7σ 9.2→46.0/q -0.5σ0.4→0.0/q -0.7 5.6→4.9
12 Windows 10 Version 1809 6.6σ 121.0→303.0/q 0.9σ10.0→13.0/q -0.1 7.3→7.3
13 Apache Tomcat 6.6σ 2.6→15.0/q 1.1σ1.0→2.5/q +0.3 7.2→7.5
14 postgresql 6.2σ 1.9→8.0/q 1.0σ0.1→0.5/q +1.0 6.2→7.1
15 Kibana 5.7σ 3.4→19.5/q -0.4σ0.1→0.0/q -0.5 6.5→6.1
16 Windows 10 Version 21H2 5.6σ 126.3→314.5/q 0.4σ10.6→12.0/q -0.1 7.3→7.3
17 dataease 5.6σ 3.9→17.0/q 1.7σ0.1→0.5/q -0.1 8.2→8.1
18 Wireshark 5.3σ 4.9→29.0/q -1.0 6.6→5.6
19 Apache Airflow 5.3σ 4.8→23.0/q -0.5σ0.2→0.0/q -0.1 6.7→6.7
20 Microsoft Office LTSC for Mac 2021 5.2σ 10.8→65.0/q 0.1σ0.4→0.5/q -0.4 7.7→7.3

LINK COPIED TO CLIPBOARD