5 ms·
I just did some analysis on this last weekend, in 2024 there were roughly 100 CVEs published every day. In April we hit approximately 200 per day. Going backwa
by jcims 5mo ago
I just did some analysis on this last weekend, in 2024 there were roughly 100 CVEs published every day. In April we hit approximately 200 per day.
Going backwards from 2023, the doubling interval for published CVEs was approximately 4 to 4 1/2 years. Since then it’s approximately two years.
There has definitely been a rapid uptick.
- Vexs 5mo agoPublished CVEs seems a bad metric to use for this- unless we assume that the ratio of really nasty vulns/not-too-bad vulns is consistent.
- carlmr 5mo agoAlso the question remains if more CVE laden code was produced in the first place, instead of automated detection improvements. It's easier to find a needle in the haystack if the haystack is 50% needles.
- red-iron-pine 5mo agohave the AI vibe code crappy apps so the related AI vuln finder can fix them just doubled the value and use cases of your AI solution!
- marysol5 5mo agoThey've been doing that for a long while. Publish something to Github in a public repo? It pulls it, scans it, and reports! Especially if you accidentally put in keys
- om42 5mo agoAnother reason published CVEs isn't a great metric is that one of the largest contributors to the number of CVEs significantly increasing in the past couple years has been that the Linux kernel now submits almost all bugs as CVEs which wasn't the case before.
- jcims 5mo agoGood consideration but I still think there’s an uptick. This is all AI generated as I’m not in a spot to do anything more at the moment but this is a chart of ‘linux kernel’ CVEs rated as high/critical correlated with NVD. https://imgur.com/a/0DrJuLU https://imgur.com/a/0DrJuLU
- marysol5 5mo agoThere's been CVE's published for software that didn't even exist!
- adikso 5mo agoI wouldn't look at the numbers. There used to be a lot of "scam" CVEs before LLMs, that weren't actual vulns. Nowadays its more popular to collect CVEs, and there is a lot of people scanning with LLMs and reporting without checking (like it was in case of cURL). These CVEs are often not verified by anyone. There probably is more vulnerabilities found, but the amount of CVEs is not a good metric.
- Seattle3503 5mo agoThe rules around CVE reporting changed recently and it would be expected a lot more are accepted.
- ainch 5mo agoDid you publish this anywhere? Would love to read more.