Aggregate analytics across the full CVE landscape.

Sometimes the question isn't about a specific CVE. It's about patterns at landscape scale: how a CWE category has trended over the last decade, how CISA KEV additions distribute across vendors, how EPSS scores evolve for a class of vulnerabilities. Vulnerability Intelligence is the aggregate analytics layer over the CVE corpus.

WHAT THIS DOES

Statistical views across every CVE published.

Vulnerability Intelligence aggregates analytics across the full CVE corpus enriched with EPSS exploit-prediction history and CISA KEV actively-exploited status. CVE statistics by year, CWE category timelines, CISA KEV addition trends, EPSS distribution analyses, vulnerability statistics by CVSS severity. The structural view of the vulnerability landscape with real-world exploitation signal built in.

Use cases include vulnerability research (how is a specific CWE class trending), vendor due diligence (what does a vendor's CVE history look like across their product lines), policy and threat-modeling (how is the CISA KEV catalog evolving), and academic research (the kind of question you'd want to ask a CVE database directly without a heavy aggregation pipeline).

HOW IT WORKS

Three analytics dimensions, across the CVE corpus.

Time-series analytics for trend research. Categorical breakdowns for structural questions. Per-CVE EPSS history for understanding which criticals turned into actual exploitation.

Time-series analytics.

CVE counts by year, CISA KEV additions by month, EPSS distribution shifts over time. Useful for trend research and policy modeling.

Categorical breakdowns.

By CWE class (every CVE labeled with a weakness category), by vendor and product, by CVSS severity, by KEV status. Useful for structural research questions.

EPSS history per CVE.

EPSS scores evolve over time as exploit data accumulates. Per-CVE EPSS history shows how the prediction has shifted, useful for understanding which criticals actually got exploited and which stayed theoretical.

WHAT IT SURFACES

Examples of analytics queries Vulnerability Intelligence runs.

CVE counts by year and severity

Volume of CVE publications across years, broken down by CVSS severity tier.

CWE timelines

Weakness-category trends across years, useful for vulnerability-class research.

CISA KEV additions

Additions to the actively-exploited catalog by date and by vendor.

EPSS distribution

Distribution of EPSS percentiles across the full corpus and within categorical filters.

Per-CVE EPSS history

Time-series EPSS scores for individual CVEs, showing how prediction shifted as exploit data accumulated.

Vendor CVE profiles

Aggregate CVE counts and severity distributions across a vendor's product lines.

CVSS distribution

CVSS-score distribution across the corpus and within filtered subsets.

PART OF DSI

Aggregate intelligence complements specific search.

Vulnerability Intelligence answers structural questions ("how is this category trending"). Vulnerability Search answers specific questions ("which CVEs match these criteria"). The pattern mirrors Domain Intelligence and Domain Search. Together they cover the full search-and-research surface for the CVE corpus.

← Back to DSI

“For strategic reports on the CVE landscape, having decade-scale aggregate data on CWE categories and KEV additions changes what we can put in board materials. The patterns are visible because the data is queryable.”

— Director of Security Research, Defense Contractor
EXPLORE THE LANDSCAPE

Run aggregate queries against the CVE corpus.

Book a demo. We'll run sample analytics queries scoped to your research question.

Request a demo