CVE Analysis
How CVE volume, exploitation, and patch/exploit timing are trending over time
Each column counts CVEs published within that trailing window. Vendor / product / min-CVSS filters apply to the whole table.
| Metric | 1D | 1W | 30D | 90D | 1Y | 2Y | 5Y | All |
|---|---|---|---|---|---|---|---|---|
| Loading… | ||||||||
% of CVEs per period with a known exploit.
Absolute number of CVEs with a known exploit per period.
Discovery → public disclosure (0–1825 day window).
Days from public patch to first known exploit/PoC.
Vendors and products active for 4+ years whose newly-published CVEs jumped sharply over the last ~180 days versus their own 5-year baseline — a pattern often tied to new AI-assisted bug-finding & fixing programs. This data doesn't reveal who is discovering the bugs — they may be found by the vendor's own teams or reported by external researchers. Jump is how many standard deviations the recent per-quarter rate sits above the historical quarterly mean, shown for both all CVEs (the sort order) and exploited CVEs. Δ Severity is the change in average CVSS base score — which may hint at the quality of the bugs being found or at how the vendor is prioritizing which issues to fix (a drop toward lower-severity bugs is also common with AI fuzzing noise). Each cell's small text is baseline → recent. Click any name to open it in the analysis filters below.
| # | Vendor | CVE Jump | Expl Jump | Δ Severity |
|---|---|---|---|---|
| Loading… | ||||
| # | Product | CVE Jump | Expl Jump | Δ Severity |
|---|---|---|---|---|
| Loading… | ||||