Glossary

Terms and abbreviations used across the site.

Censoring
When the event (KEV addition) has not occurred yet; the observation ends at the current age.
CISA
Cybersecurity and Infrastructure Security Agency (USA) — maintains the KEV catalog.
Coverage
Of the vulnerabilities later added to KEV, the share a rule selects (|S ∩ Y| / |Y|).
CPE
Common Platform Enumeration — a structured naming scheme for products (vendor, product, version).
CVE
Common Vulnerabilities and Exposures — a unique identifier for a publicly disclosed security vulnerability.
CVSS
Common Vulnerability Scoring System — a 0–10 severity score for a vulnerability.
CWE
Common Weakness Enumeration — a category of software weakness (e.g. CWE-79 = cross-site scripting).
Efficiency
Of the vulnerabilities a rule selects, the share later added to KEV (|S ∩ Y| / |S|).
Effort
The number of vulnerabilities a rule selects — i.e. the patches it would require (|S|).
ENISA
European Union Agency for Cybersecurity — runs the EUVD.
EPSS
Exploit Prediction Scoring System — the estimated probability (0–1) that a vulnerability is exploited in the wild within 30 days.
EPSS percentile
The rank of an EPSS score: the share of CVEs with an equal or lower score.
EUVD
European Vulnerability Database — ENISA's vulnerability database, including a KEV list.
Exploit-DB
A public archive of exploits; only its index metadata (no exploit code) is used here.
FIRST
Forum of Incident Response and Security Teams — the organization behind EPSS.
Kaplan-Meier
A statistical estimator of the time until an event that accounts for censoring.
KEV
Known Exploited Vulnerabilities — CISA's catalog of vulnerabilities known to be actively exploited.
Metasploit
A penetration-testing framework; only module metadata is used here.
Nuclei
A vulnerability scanner; the presence of a CVE template is used here as a yes/no signal.
NVD
National Vulnerability Database (USA) — source of CVE master data, CVSS, CWE and CPE.
Ransomware flag
CISA's "knownRansomwareCampaignUse" marker on a KEV entry (Known / Unknown).
Survival curve
1 − S(t): the cumulative share of vulnerabilities added to KEV within t days of publication.
Wilson interval
A confidence interval for a proportion, used for the observed share in the calibration.
Zero-day
Here: a vulnerability added to the KEV catalog on or before its publication date (t ≤ 0).