cvestatisticskevvulnerability-trendscvss

F5 Labs - The Evolving CVE Landscape

Provides macro-level trend data on CVE volume, vendor proliferation, and the increasing absolute number of 'Known Exploited' attack vectors.

Summary

The CVE landscape has changed substantially over 20 years, with publication rates accelerating toward an expected 500+ new CVEs per week in 2025. Research indicates a steady proliferation of vendors: those publishing their first CVE are increasing at 18% per year. While CVSSv3 average severity (High) is higher than v2 (Medium), the average severity within each version has remained flat for a decade, suggesting 'severity inflation' is a bureaucratic artifact rather than a technical trend. Most critically, CISA's Known Exploited Vulnerability (KEV) list represents only 0.5% of all CVEs, yet this steady proportion masks a 17% monthly increase in the absolute number of distinct attack vectors available to threat actors. Exploit code has largely migrated from ExploitDB to GitHub, where approximately 5% of new CVEs now have proof-of-concept code published.

Related Checks

VULN_RECENT_FREQUENCY

The report confirms that CVE publication is accelerating, with an expected 10% annual growth in weekly volume through 2025.

Adverse Outcome

becoming overwhelmed by a flood of new vulnerability disclosures without an automated prioritization framework

Because

accelerating publication rates are the primary driver of 'vulnerability fatigue', making high-frequency detection a requirement for modern security operations.

Gaps Analysis

Evidence

The size of the CISA Known Exploited Vulnerability List continues to grow... equivalent to a 17% increase in new CVEs on the KEV per month... distinct approaches attackers are choosing from is constantly growing.

Blind Spot

Risk Guard treats all CVEs as important but doesn't explicitly prioritize the 0.5% of 'Known Exploited' (KEV) vulnerabilities that pose the most immediate threat.

Actionable Capability

Risk Guard would be better if it integrated the CISA KEV list as a high-priority risk weight, ensuring that 'Known Exploited' flaws always top the remediation list.

← Previous Next →