Methodology

All analyses are based on public data sources and recomputed daily. No exploit code is stored or linked — only metadata (identifier, title, date, reference). See the glossary for terms and abbreviations.

Data sources and licenses

Time to KEV (Kaplan-Meier)

The population is non-rejected CVEs from the start year onward. t is the number of days from publication to KEV addition; if t ≤ 0, then t = 0 (zero-day). Vulnerabilities without an addition are censored at their current age. The chart shows 1 − S(t). Strata with fewer than 20 events are not shown.

Coverage, efficiency, effort

For each monthly snapshot, candidates (published before the month, with an EPSS value) are considered. Y are those added to KEV within the following window. Coverage = |S ∩ Y|/|Y|, efficiency = |S ∩ Y|/|S|, effort = |S|.

EPSS calibration

Bins over log10(score). Per bin we report the mean score, the observed share of KEV additions within 30 days, and a Wilson interval.

Exploit race

For each KEV vulnerability we compare the days to the first public exploit with the days to KEV addition.