Situation by the numbers
Citable statistics
Aggregated metrics across the NEOSEC Intel dataset. Each section ships source, dataset, formula and timestamp — ready to cite in reports, decks or posts.
Year-to-date CVE publications
Year-to-date CVE publications
Cumulative CVE publications per year, derived from the earliest publication date across our ingested sources (NVD, CVE.org, OSV, MSRC, Debian, Ubuntu). Note: our capture ratio against the MITRE CVE List is currently below 100% — NVD records with status "Received / Awaiting Analysis" are now counted (since 2026-06-07), a full cvelistV5 sync follows in a later wave. A 1 : 1 match with FIRST/first.org/epss/data_stats is the target but not yet reached.
Citable
- Source
- NIST NVD CVE API 2.0
- Dataset
- intel.vulnerability.published_at
- Computation
- SUM(COUNT(*)) OVER (PARTITION BY year ORDER BY day-of-year)
- Data as of
- 2026-07-28 12:10 UTC
- Attribution
- NEOSEC GmbH · intel.neosec.io
Yearly severity mix (with KEV overlay)
Citable
- Source
- NIST NVD CVE API 2.0 + CISA Known Exploited Vulnerabilities Catalog
- Dataset
- intel.advisory + intel.vulnerability
- Computation
- GROUP BY year(advisory.published_at), severity-bucket; KEV-Overlay aus vulnerability.is_kev
- Data as of
- 2026-07-28 12:10 UTC
- Attribution
- NEOSEC GmbH · intel.neosec.io
Ransomware-used CVEs (CISA-confirmed)
CISA maintains a "Known Ransomware Campaign Use" column in the KEV catalog. CVEs flagged "Known" were used in documented ransomware campaigns — they deserve the highest patch priority.
Recently added
- CVE-2026-35273Oracle PeopleSoft Enterprise PeopleTools — Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability2026-06-12 00:00 UTC
- CVE-2026-50751Check Point Security Gateway — Check Point Security Gateway Improper Authentication Vulnerability2026-06-08 00:00 UTC
- CVE-2026-02572026-05-29 00:00 UTC
Citable
- Source
- CISA Known Exploited Vulnerabilities Catalog — column `knownRansomwareCampaignUse`
- Dataset
- intel.vulnerability.kev_known_ransomware
- Computation
- COUNT(DISTINCT vulnerability.id WHERE kev_known_ransomware = true)
- Data as of
- 2026-07-28 12:10 UTC
- Attribution
- NEOSEC GmbH · intel.neosec.io
Time-to-KEV listing (Known Exploited Vulnerabilities — CISA's catalog of vulnerabilities confirmed exploited in the wild)
Median days between CVE publication and CISA-KEV listing. Lower = prioritized sooner.
2022 outlier: CISA only launched the KEV catalog in November 2021. The first full year (2022) therefore carried a large backfill of historically known and long-exploited vulnerabilities — the gap between publication date and KEV listing averaged several years. From 2023 onwards the median actually reflects the operational turnaround.
Citable
- Source
- CISA Known Exploited Vulnerabilities Catalog
- Dataset
- intel.vulnerability (KEV-flagged rows)
- Computation
- percentile_cont(0.5)/(0.9) WITHIN GROUP (ORDER BY kev_added_at - published_at), per kev-year
- Data as of
- 2026-07-28 12:10 UTC
- Attribution
- NEOSEC GmbH · intel.neosec.io
CPE Dictionary inventory (Common Platform Enumeration — the canonical registry of product/version identifiers)
Local aggregation of the canonical CPE 2.3 catalog (NIST). Mirrors the NVD statistics page at cpe/statistics, computed against our daily incremental snapshot.
CPE entries total
504,703
Anwendung (a)
441,979
Betriebssystem (o)
43,287
Hardware (h)
19,437
Top vendors by CPE count
- 1.cisco™18,106
- 2.ibm™11,043
- 3.jenkins™8,606
- 4.hp™8,079
- 5.vim™7,796
- 6.apache™7,491
- 7.google™6,974
- 8.redhat™6,777
- 9.pivotal_software™5,269
- 10.gnome™5,100
- 11.oracle™5,013
- 12.microsoft™4,108
Show 188 more vendors
- 13.intel™4,094
- 14.horde™3,770
- 15.linux™3,648
- 16.atlassian™3,129
- 17.adobe™2,946
- 18.vmware™2,366
- 19.chef™2,278
- 20.gnu™2,276
- 21.lenovo™2,208
- 22.apple™2,019
- 23.mozilla™2,014
- 24.huawei™1,976
- 25.signal™1,968
- 26.cloudfoundry™1,935
- 27.f5™1,880
- 28.gitlab™1,841
- 29.openstack™1,773
- 30.debian™1,633
- 31.digium™1,406
- 32.siemens™1,403
- 33.symantec™1,403
- 34.facebook™1,402
- 35.freebsd™1,395
- 36.php™1,379
- 37.dell™1,337
- 38.juniper™1,329
- 39.python™1,327
- 40.frappe™1,282
- 41.opensuse™1,211
- 42.isc™1,202
- 43.eclipse™1,183
- 44.ovirt™1,167
- 45.suse™1,161
- 46.imagemagick™1,148
- 47.freepbx™1,144
- 48.phpunit_project™1,139
- 49.puppet™1,135
- 50.sap™1,109
- 51.kde™1,095
- 52.synology™1,067
- 53.sun™1,055
- 54.elastic™1,039
- 55.strapi™1,029
- 56.ruby-lang™1,027
- 57.libpng™1,012
- 58.jetbrains™976
- 59.sangoma™969
- 60.iij™969
- 61.kubernetes™965
- 62.codepeople™956
- 63.cpanel™937
- 64.libguestfs™917
- 65.schneider-electric™908
- 66.tibco™893
- 67.emc™881
- 68.zohocorp™874
- 69.supermicro™867
- 70.bestwebsoft™863
- 71.erlang™851
- 72.ntp™830
- 73.laravel™826
- 74.angularjs™824
- 75.nextcloud™817
- 76.broadcom™791
- 77.lexmark™774
- 78.exiftool_project™772
- 79.remotion™764
- 80.contao™747
- 81.wordpress™735
- 82.theforeman™732
- 83.mcafee™727
- 84.fortinet™723
- 85.phoenixcontact™722
- 86.git-scm™710
- 87.zoom™710
- 88.kentico™709
- 89.microfocus™706
- 90.sickrage™695
- 91.slf4j™694
- 92.ca™687
- 93.nodejs™678
- 94.paloaltonetworks™666
- 95.rubyonrails™659
- 96.droppy_project™659
- 97.citrix™659
- 98.docker™651
- 99.mikrotik™633
- 100.yamaha™626
- 101.freedesktop™624
- 102.yahama™619
- 103.craftcms™616
- 104.home-assistant™615
- 105.pulsesecure™609
- 106.percona™598
- 107.wp-livechat™598
- 108.aufs_project™594
- 109.mailenable™591
- 110.dlink™587
- 111.webkitgtk™587
- 112.10web™586
- 113.nvidia™583
- 114.tryton™574
- 115.mortbay™573
- 116.ponsoftware™572
- 117.postgresql™571
- 118.octopus™570
- 119.limesurvey™568
- 120.rocomotion™560
- 121.nginx™553
- 122.hitachi™553
- 123.samba™551
- 124.hashicorp™549
- 125.mongoosejs™545
- 126.arm™541
- 127.web-dorado™540
- 128.tp-link™537
- 129.axis™536
- 130.elasticsearch™525
- 131.hapijs™525
- 132.github™524
- 133.scapy™519
- 134.live555™518
- 135.codesys™515
- 136.reaper™515
- 137.torproject™513
- 138.drupal™513
- 139.clusterlabs™510
- 140.ez™509
- 141.canonical™507
- 142.otrs™507
- 143.angular™504
- 144.zabbix™504
- 145.nasm™500
- 146.misskey™500
- 147.sensiolabs™499
- 148.samsung™491
- 149.arubanetworks™491
- 150.cloud_foundry™486
- 151.rsyslog™485
- 152.sequelizejs™483
- 153.telegram™481
- 154.rockwellautomation™476
- 155.rapid7™475
- 156.linuxfoundation™475
- 157.noscript™472
- 158.wekan_project™465
- 159.novell™464
- 160.bundler™463
- 161.katello_project™462
- 162.phusion™457
- 163.electronjs™452
- 164.ultimatemember™452
- 165.netapp™450
- 166.amazon™450
- 167.mysql™449
- 168.ui™449
- 169.brave™448
- 170.inedo™448
- 171.misp-project™447
- 172.phore™445
- 173.zend™442
- 174.vaadin™442
- 175.yandex™437
- 176.tableau™435
- 177.schedmd™433
- 178.moinejf™431
- 179.x™431
- 180.splunk™430
- 181.thephpfactory™429
- 182.pivx™428
- 183.progress™427
- 184.sony™424
- 185.misp™424
- 186.frostwire™423
- 187.ffmpeg™422
- 188.d-link™422
- 189.auth0™421
- 190.miniupnp_project™418
- 191.avaya™417
- 192.grafana™416
- 193.gchq™415
- 194.whatsapp™415
- 195.webtorrent™414
- 196.nlnetlabs™414
- 197.mediawiki™413
- 198.qualcomm™413
- 199.zemana™411
- 200.trustedfirmware™410
Vendor and product names are trademarks or registered trademarks of their respective owners. The vendor slugs shown here are taken verbatim from the public NVD CPE Dictionary (NIST) and used solely to identify advisories — no trademark infringement is intended and no commercial affiliation is implied.
Citable
- Source
- NIST NVD CPE API 2.0 — cf. nvd.nist.gov/products/cpe/statistics
- Dataset
- intel.cpe_dictionary
- Computation
- COUNT(*) GROUP BY part / vendor — lokal aggregiert aus intel.cpe_dictionary
- Data as of
- 2026-07-17 01:53 UTC
- Attribution
- NEOSEC GmbH · intel.neosec.io