Methodology
All analyses are based on public data sources and recomputed daily. No exploit code is stored or linked — only metadata (identifier, title, date, reference). See the glossary for terms and abbreviations.
Data sources and licenses
- CISA KEV — known exploited vulnerabilities (CC0).
- ENISA EUVD — the European KEV list.
- FIRST EPSS — exploitation probability (free with attribution).
- NVD — CVE master data and CVSS. This product uses data from the NVD API but is not endorsed or certified by the NVD.
- Exploit-DB — index only (GPL-2.0).
- Metasploit — module metadata (BSD-3).
- Nuclei templates — presence per CVE.
Time to KEV (Kaplan-Meier)
The population is non-rejected CVEs from the start year onward. t is the number of days from publication to KEV addition; if t ≤ 0, then t = 0 (zero-day). Vulnerabilities without an addition are censored at their current age. The chart shows 1 − S(t). Strata with fewer than 20 events are not shown.
Coverage, efficiency, effort
For each monthly snapshot, candidates (published before the month, with an EPSS value) are considered. Y are those added to KEV within the following window. Coverage = |S ∩ Y|/|Y|, efficiency = |S ∩ Y|/|S|, effort = |S|.
EPSS calibration
Bins over log10(score). Per bin we report the mean score, the observed share of KEV additions within 30 days, and a Wilson interval.
Exploit race
For each KEV vulnerability we compare the days to the first public exploit with the days to KEV addition.