boxscore/security

Methodology

What this page is

boxscore/security is a daily page of record for published software vulnerabilities. It reports, in tabular form, everything that happened in the public vulnerability record during the previous UTC day: what was disclosed, what got weaponized, what got patched, and how the running totals moved. It reports; it does not analyze, rank by opinion, or editorialize.

Ranking

Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Day boundary

A day is a UTC calendar day, 00:00:00–23:59:59 UTC. The edition covering a day is published at 06:00 UTC the following morning, after CISA KEV and FIRST EPSS publish their daily updates. All timestamps on every page are UTC. Editions are immutable once published: late-arriving information appears as a transaction on a later day and never rewrites history.

Transactions

ADDED TO KEV (CISA catalog diff) · PATCH SHIPPED (fixed versions or patch references appearing) · RESCORED (NVD CVSS base score change) · EXPLOIT PUBLISHED (public exploit reference appearing) · REJECTED / DISPUTED (CVE record state change) · ENRICHED (a previously unscored CVE receiving CVSS/CPE data) · DUE DATE PASSED (KEV remediation deadline elapsed).

Sources and attribution

CVE records from the CVE Program (cvelistV5, the authoritative publication record). Enrichment — CVSS, CPE, CWE — from the National Vulnerability Database, courtesy of NIST. Known-exploited status and remediation deadlines from the CISA Known Exploited Vulnerabilities catalog. Exploit probability scores from FIRST EPSS — see EPSS at FIRST.org. Open-source ecosystem advisories from OSV.dev. This site is not affiliated with or endorsed by NIST, CISA, FIRST, MITRE, or the CVE Program.

Standings and rate stats

Vendor tables exclude records whose vendor attribution is a placeholder (n/a, unknown, unspecified); each edition states how many disclosures were excluded. Column legend: C/H/M/L are year-to-date disclosure counts by severity band; KEV and KEV YTD are catalog entries all-time and year-to-date; Δ is the month-to-date count minus the same day-span of the prior month (a like-for-like pace comparison). Rate stats are arithmetic over published figures, never opinion: KEV/100 = KEV additions year-to-date ÷ CVEs year-to-date × 100. Med CVSS and Med EPSS are medians over a vendor's year-to-date disclosures that carry a score. Raw disclosure counts are not directly comparable across vendors — disclosure practices and product surfaces differ; the rate columns exist for exactly that reason.

Honesty rules

Missing scores are shown as — and labeled AWAITING ENRICHMENT, never imputed. Counts are never truncated silently. When a source is unreachable, the edition ships from what is available and says so in its feed-status footer. A degraded page is correct; a missing page is not.

Glossary

CVSS
Common Vulnerability Scoring System — a 0–10 base score published by the CNA or NVD. Severity bands: Critical ≥ 9.0, High 7.0–8.9, Medium 4.0–6.9, Low 0.1–3.9. Each box score's footer states the vector version (v3.1 or v4.0).
EPSS
Exploit Prediction Scoring System, published daily by FIRST — the estimated probability that the CVE will be exploited in the wild within the next 30 days. The %ile column is that score's rank among all scored CVEs.
KEV
CISA's Known Exploited Vulnerabilities catalog — CVEs with observed in-the-wild exploitation. Entries carry a remediation due date binding on US federal agencies.
CWE
Common Weakness Enumeration — the class of flaw (for example, CWE-79 is cross-site scripting).
AWAITING ENRICHMENT
Published, but no CVSS/CPE analysis yet. Sorts below scored CVEs; a default score is never assigned.

How to read a box score

The letter row is the line score: the metrics of the published CVSS vector (v3.1: AV AC PR UI S C I A; v4.0: AV AC AT PR UI VC VI VA), followed by the CVSS base score, the EPSS probability and percentile, and KEV membership. AFFECTED lists products with introduced and fixed versions. TIMELINE is the record's lifecycle: reservation, publication, advisories, KEV addition. The footer line carries the weakness (CWE), the CNA that published the record, the CVSS version, the reference count, and NVD analysis status.