CVE Statistics

Vulnerability counts, continuously synced

CVEs in the database
—

— carry a CVSS score and are broken down below. The rest are published but not yet scored by NVD, which is normal for recent records and permanent for some older ones.

Publication rate
— CVEs published in the last 24 hours

From the rolling window that feeds Latest CVEs, synced continuously.

Known exploitation
— confirmed exploited in the wild

— ransomware-linked · — added in the last 30 days.

Predicted exploitation (EPSS)
—
≥ 10% chance
—
≥ 50% chance
—
≥ 90% chance

EPSS estimates the probability a CVE is exploited in the next 30 days. Of — scored CVEs, these are the counts above each threshold — a different question from severity, and usually a smaller number than people expect.

Developer API

REST search, CVE detail, and the OSV-compatible /api/v2/query scanner endpoint.

API Reference