boxscore/security

Methodology

What this page is

boxscore/security is a daily page of record for published software vulnerabilities. It reports, in tabular form, everything that happened in the public vulnerability record during the previous UTC day: what was disclosed, what got weaponized, what got patched, and how the running totals moved. It reports; it does not analyze, rank by opinion, or editorialize.

Ranking

Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Day boundary

A day is a UTC calendar day, 00:00:00–23:59:59 UTC. The edition covering a day is published at 06:00 UTC the following morning, after CISA KEV and FIRST EPSS publish their daily updates. All timestamps on every page are UTC. Editions are immutable once published: late-arriving information appears as a transaction on a later day and never rewrites history.

Transactions

ADDED TO KEV (CISA catalog diff) · PATCH SHIPPED (fixed versions or patch references appearing) · RESCORED (NVD CVSS base score change) · EXPLOIT PUBLISHED (public exploit reference appearing) · REJECTED / DISPUTED (CVE record state change) · ENRICHED (a previously unscored CVE receiving CVSS/CPE data) · DUE DATE PASSED (KEV remediation deadline elapsed).

Sources and attribution

CVE records from the CVE Program (cvelistV5, the authoritative publication record). Enrichment — CVSS, CPE, CWE — from the National Vulnerability Database, courtesy of NIST. Known-exploited status and remediation deadlines from the CISA Known Exploited Vulnerabilities catalog. Exploit probability scores from FIRST EPSS — see EPSS at FIRST.org. Open-source ecosystem advisories from OSV.dev. This site is not affiliated with or endorsed by NIST, CISA, FIRST, MITRE, or the CVE Program.

Standings and rate stats

Vendor tables exclude records whose vendor attribution is a placeholder (n/a, unknown, unspecified); each edition states how many disclosures were excluded. Column legend: C/H/M/L are year-to-date disclosure counts by severity band; KEV and KEV YTD are catalog entries all-time and year-to-date; Δ is the month-to-date count minus the same day-span of the prior month (a like-for-like pace comparison). Rate stats are arithmetic over published figures, never opinion: KEV/100 = KEV additions year-to-date ÷ CVEs year-to-date × 100. Med CVSS and Med EPSS are medians over a vendor's year-to-date disclosures that carry a score. Raw disclosure counts are not directly comparable across vendors — disclosure practices and product surfaces differ; the rate columns exist for exactly that reason.

Honesty rules

Missing scores are shown as — and labeled AWAITING ENRICHMENT, never imputed. Counts are never truncated silently. When a source is unreachable, the edition ships from what is available and says so in its feed-status footer. A degraded page is correct; a missing page is not.