Provides macro-level trend data on CVE volume, vendor proliferation, and the increasing absolute number of 'Known Exploited' attack vectors.
The CVE landscape has changed substantially over 20 years, with publication rates accelerating toward an expected 500+ new CVEs per week in 2025. Research indicates a steady proliferation of vendors: those publishing their first CVE are increasing at 18% per year. While CVSSv3 average severity (High) is higher than v2 (Medium), the average severity within each version has remained flat for a decade, suggesting 'severity inflation' is a bureaucratic artifact rather than a technical trend. Most critically, CISA's Known Exploited Vulnerability (KEV) list represents only 0.5% of all CVEs, yet this steady proportion masks a 17% monthly increase in the absolute number of distinct attack vectors available to threat actors. Exploit code has largely migrated from ExploitDB to GitHub, where approximately 5% of new CVEs now have proof-of-concept code published.
The report confirms that CVE publication is accelerating, with an expected 10% annual growth in weekly volume through 2025.
becoming overwhelmed by a flood of new vulnerability disclosures without an automated prioritization framework
accelerating publication rates are the primary driver of 'vulnerability fatigue', making high-frequency detection a requirement for modern security operations.
The size of the CISA Known Exploited Vulnerability List continues to grow... equivalent to a 17% increase in new CVEs on the KEV per month... distinct approaches attackers are choosing from is constantly growing.
Risk Guard treats all CVEs as important but doesn't explicitly prioritize the 0.5% of 'Known Exploited' (KEV) vulnerabilities that pose the most immediate threat.
Risk Guard would be better if it integrated the CISA KEV list as a high-priority risk weight, ensuring that 'Known Exploited' flaws always top the remediation list.