Tool · CVE Analyser
The exploitation window
Raw disclosure counts reward obscurity. The honest question is how long you have between a vulnerability going public and someone using it.
Exploited before disclosure
By vendor
| Vendor | KEV | Median days | Spread (days) | Zero-day | KEV ratio | Ransomware |
|---|---|---|---|---|---|---|
| 3 | 0 (n=3) | 0–2 | 66.7% | 6.5% | 2 | |
| 3 | 7 (n=3) | 2–26 | 0.0% | 10.3% | 1 | |
| 29 | 7 | 0–2043 | 34.5% | 2.5% | 13 | |
| 89 | 7 | 0–4109 | 27.0% | 0.9% | 0 | |
| 15 | 12 | 0–1711 | 26.7% | 6.2% | 6 | |
| 35 | 27 | 0–922 | 25.7% | 7.2% | 12 | |
| 4 | 33.5 (n=4) | 0–56 | 25.0% | 8.0% | 0 | |
| 93 | 56 | 0–2702 | 25.8% | 1.1% | 0 | |
| 13 | 65 | 0–1184 | 7.7% | 5.3% | 8 | |
| 33 | 89 | 0–1444 | 9.1% | 5.3% | 10 | |
| 18 | 160.5 | 0–2260 | 11.1% | 40.0% | 5 | |
| 7 | 163 | 5–490 | 0.0% | 1.2% | 4 | |
| 17 | 208 | 0–1297 | 17.6% | 8.5% | 10 | |
| 22 | 234.5 | 0–1709 | 22.7% | 8.5% | 7 | |
| 39 | 503 | 0–5776 | 2.6% | 1.2% | 8 | |
| 7 | 546 | 0–1683 | 14.3% | 6.8% | 1 | |
| 382 | 567 | 0–7191 | 22.5% | 1.6% | 104 | |
| 15 | 616 | 9–825 | 0.0% | 1.2% | 0 | |
| 26 | 847.5 | 9–4540 | 0.0% | 0.1% | 2 | |
| 26 | 926 | 7–3915 | 0.0% | 1.0% | 2 | |
| 13 | 1035 | 0–5457 | 15.4% | 0.2% | 1 | |
| 94 | 1280.5 | 0–6713 | 12.8% | 2.0% | 6 | |
| 45 | 1526 | 1–4958 | 0.0% | 0.4% | 13 | |
| 14 | 1574.5 | 2–2781 | 0.0% | 0.6% | 2 | |
| 80 | 2632 | 0–6063 | 3.8% | 0.5% | 10 |
Every column sorts; the table opens on median days ascending, so the fastest-exploited vendors are at the top. Click a vendor, or any headline number, to see the CVEs behind it — ID, product, both dates, and a link out to NVD. Vendors tagged edge are the hand-defined VPN, firewall and remote-access cohort. Medians drawn from fewer than 5 KEV entries are greyed and carry their sample size inline: a median of three data points is not the same claim as a median of ninety, and the table should not present them alike. Spread is the observed minimum and maximum for that vendor, so the range behind each median is visible. Zero-day is the share of a vendor's entries CISA catalogued at or before NVD published them.
Records
| CVE | Product | Published | Added to KEV | Days |
|---|
Method & limits
Sources: the CISA Known Exploited Vulnerabilities catalogue for exploitation dates, and NVD API 2.0 for CVE publication dates. Rebuilt nightly and committed to git, so every figure on this page has a dated, diffable snapshot behind it. Days-to-KEV is dateAdded − published in UTC calendar days.
Storage threshold for v1: a per-CVE record is kept only if the CVE has CISA KEV membership. Everything else exists as a monthly count per vendor and nothing more. Future versions plan to add CVSS >= 9.0 and EPSS >= 0.10 clauses, but neither is currently computed or evaluated, so the threshold is presently KEV membership alone.
KEV records exploitation CISA has confirmed, so it is a floor and not a census — real exploitation is higher. Disclosure counts measure disclosure, not security: a vendor with more CVEs may simply be looked at harder. Vendor attribution follows KEV's own vendor field with known synonyms merged, and is imperfect. The KEV ratio's denominator starts at 2021-01, so its numerator counts only KEV entries published in that window — which is why a vendor's KEV column and its ratio do not divide into each other.
CVEs added to KEV before NVD published them give a negative days-to-KEV. The record keeps the real number; every median clamps it to zero, because a defender's answer to “how long did you have” cannot be less than none. The “edge devices” cohort is derived, not hand-picked: each KEV entry's product name is classified as enterprise perimeter kit — VPN, firewall, gateway or WAN-edge appliance — and a vendor is tagged edge only when a strict majority of its own KEV entries clear that bar (with at least three entries, so one record can't decide it). The dashed lead-in on the chart marks months whose 12-month window reaches back past the start of the KEV catalogue.
Two limits worth stating plainly, because they both push in the same direction as the headline claim and a reader is right to ask about them. First: dateAdded is when CISA catalogued a CVE as exploited, not when exploitation actually began. CISA has gotten faster at adding entries since 2021, so some of the narrowing this page shows is CISA's own process speeding up, not attackers moving faster — the two are conflated here and a future data batch will try to measure the process-speed effect on its own, so it can be separated out rather than assumed away. Second: NVD's publication date is not the disclosure date either. Vendor security advisories often land days to weeks before NVD publishes its own record, and NVD's publication backlog — particularly bad through 2024 and 2025 — pushes some publication dates later still. So every “days since publication” figure on this page understates real exposure time, by an amount that varies CVE to CVE and can't be corrected for with the data in hand. A future data batch will add CNA-sourced publication dates, which route around the NVD backlog, as a more accurate alternative.
The rolling chart's most recent months are biased fast for a third, related reason: a CVE published recently that will eventually take years to reach KEV has, by definition, not been added yet — so the newest window is populated only by the fast movers, because the slow ones haven't had time to show up. A plain trailing median therefore reads the recent end of the line as faster than it will turn out to have been. The correction is to only count a CVE once it has had time to mature: exclude anything published fewer than 365 days before the point being measured, so the recent window is judging the same kind of population as the older ones rather than a survivorship-biased slice of it.