// Cyber Threat

CYBORA OpenCVE Statistics

A reference view of how many vulnerabilities the world is publishing right now, and how severe they are — inspired by app.opencve.io/statistics.

// activity

CVE publication activity

Snapshot captured 2026-07-10 — this is a point-in-time reference, not a live feed; view current figures directly on OpenCVE.

253Last 24 hours▼ 16.5%
1,544Last 7 days▼ 13.45%
7,435Last 30 days▲ 1.27%
20,745Last 90 days▲ 23.6%
▼ 16.5%▼ 13.45%▲ 1.27%▲ 23.6%Last 24 hoursLast 7 daysLast 30 daysLast 90 days05,00010,00015,00020,000
// severity

Global CVSS distribution

Every published CVE, grouped by its CVSS score band — the same reference dataset used on the Cyber Malware Map, since it's one global CVE population viewed from two angles.

109.5–9.99–9.48.5–8.98–8.47.5–7.97–7.46.5–6.96–6.45.5–5.95–5.44.5–4.94–4.43.5–3.93–3.42.5–2.92–2.41.5–1.91–1.40.5–0.9010,00020,00030,00040,000
CriticalHighMediumLow
// top vendors & products

Which vendors and products carry the most CVEs

These rankings shift too often to snapshot meaningfully on a static page — a vendor can jump the list after a single disclosure batch. For the current, live ranking of top vendors and top products, see OpenCVE directly:

View live rankings on OpenCVE →
// what this means

Reading these numbers correctly

A rising CVE count isn't necessarily a sign the world is getting less secure — it's mostly a sign that more software is being written, more researchers are looking for flaws, and disclosure has become the industry norm rather than the exception. What matters far more than the raw volume is where a given vulnerability sits: whether it's in something your organisation actually runs, whether it's being actively exploited (see the CISA KEV catalog on the Cyber Malware Map), and how quickly it can realistically be remediated once found. The CVSS distribution above tells a similar story — most published vulnerabilities cluster in the High and Medium bands, which is exactly why triage matters: a security team that patches everything in score order, ignoring real-world exploitation, will always be behind. CYBORA's Agentic GRC continuously maps this kind of external vulnerability data against your own live systems, so the question stops being "how many CVEs exist today" and becomes the one that actually matters: "which of these apply to us, and what do we do about it first."

← Atpakaļ uz Kibernētisko pasauli