EVOLUTION OF SOFTWARE SECURITY VULNERABILITIES: A LARGE-SCALE EMPIRICAL ANALYSIS OF CVE SEVERITY, ATTACK VECTORS, EXPLOITABILITY, AND VULNERABILITY TRENDS

Authors

  • Asim Ismail Author
  • Aqeel Hassan Author
  • Shah Zaib Sajid Author
  • Nazia Azim Author
  • Hameed Hussain Author

Keywords:

CVE; CVSS; NVD; CISA KEV; CWE; software vulnerabilities; vulnerability management; exploitability; cybersecurity; empirical analysis.

Abstract

Software vulnerability disclosure has become a high-volume global security process, yet raw CVE counts, technical severity, and real-world exploitation are often conflated. This study analyzes 366,873 unique published CVE records spanning 1999–1 September 2026 and performs a focused longitudinal analysis for the complete years 2016–2025. The snapshot contains 195,907 records with CVSS scores, 182,710 with CWE mappings, and 1,687 CISA Known Exploited Vulnerabilities (KEV). Among scored records, Medium severity accounted for 46.85%, High for 38.21%, Critical for 10.51%, Low for 4.38%, and 108 records (0.06%) had a base score of 0.0 and were classified as None. Severity distributions changed across 2016–2025 (χ²(36)=1296.4, p<0.001; Cramér’s V=0.048); a CVSS v3.x-only sensitivity analysis of 124,082 records yielded a similarly small association (χ²(36)=1046.0, p<0.001; V=0.046). Metadata completeness increased sharply over time, with CVSS coverage rising from 1.50% in 2016 to 93.86% in 2025. KEV-listed vulnerabilities had higher CVSS scores than non-KEV-listed records (median 8.8 vs 6.9). In the adjusted logistic model (n=195,784; 1,686 KEV-listed), each one-point increase in CVSS score was associated with 1.99-fold higher odds of KEV listing (95% CI 1.90–2.08; p<0.001). Publication-to-KEV catalog-addition lag shortened markedly across publication eras, while normalized CWE trends showed persistent web weaknesses and recent growth in authorization-related categories. These findings support vulnerability prioritization that combines technical severity with exploitation evidence, attack conditions, asset exposure, and data-quality context.

Downloads

Published

2026-09-18