Dataset · CVE / NVD

The global CVE dataset — and why it's rising

Every CVE published, 2016 to 2026, from CVE.org / NVD cross-checked against Jerry Gamblin's annual reviews. Publication has gone near-vertical since 2023 — but the honest read is that the vulnerability-counting pipeline changed more than the vulnerability landscape did.

48,185
CVEs in 2025
the current record
+20.6%
year-over-year
2025 vs 2024
35,364
H1 2026 alone
already > any pre-2024 full year
6,449
CVEs in 2016
~7.5× growth in a decade

Annual CVE publication, 2016–2026

One line, a decade of disclosure. 2026 = H1 actuals (35,364), annualized ~59k–72k depending on method.

0 12.5k 25k 37.5k 50k 6.4k15k40k48k35k*20162017201820192020202120222023202420252026
2016: 6,449 → 2024: 39,962 (first ~40k) → 2025: 48,185. Jerry Gamblin CVE reviews / CVE.org / NVD

The dataset, year by year

YearCVEs publishedYoY growthNote
2016 6,449 single-source year
2017 14,643 +127.1% Step-change: CNA program expansion
2018 16,510 +12.8% single-source year
2019 17,305 +4.8% single-source year
2020 18,323 +5.9% single-source year
2021 20,153 +10% single-source year
2022 25,084 +24.5%
2023 28,902 +15.2%
2024 39,962 +38.3% First ~40K record year
2025 48,185 +20.6% New record; 308,920 cumulative since 1999
2026* 35,364 H1 only · annualized ~71k
* 2026 is first-half actuals through Jun 30. 2016–2021 rest on a single renderable source (counts by CVE-ID year); marked accordingly. full data: cve-macro.json

Three things inflate the count before AI enters the picture

263%

More issuers, mechanically

CVE submissions rose 263% from 2020–2025 as the number of CNAs (organizations allowed to assign CVEs) grew from ~346 to ~484. More issuers means more IDs, independent of how many bugs exist. The 2017 near-doubling was the earlier version of this same effect.

The Hacker News / NIST, Apr 2026
10.8%

The Linux-kernel firehose

The Linux kernel became a CNA in Feb 2024 and immediately became the single largest publisher — 4,325 CVEs in 2024, 10.8% of the entire year — by assigning IDs to routine bug fixes. That's a policy change, not a security regression.

Stingrai vulnerability stats 2026
7,007

The 'WordPress effect'

Patchstack alone published 7,007 CVEs in 2025 — more than Microsoft or Google — with Wordfence adding 3,451. Third-party plugin ecosystems, not core operating systems, now drive raw volume.

Jerry Gamblin 2025 review

And the data got less usable as it got bigger

On Feb 12, 2024, NIST's National Vulnerability Database abruptly stopped enriching most new CVEs — the CVSS severity scores, product mappings, and weakness classifications that let anyone prioritize. A contract lapsed, budgets were cut. By April 2026, facing a 263% surge, NIST formally stopped scheduling enrichment for most CVEs, restricting it to actively-exploited and federal 'critical' software.

~82%
of CVEs with public exploit PoCs
went un-enriched after Feb 2024
~29,000
CVEs formally written off
for enrichment by NIST
~32%
of 2025 CVEs enriched
~10,000 lacked CVSS scores

So the headline "record CVE counts" coincides with a collapse in the data needed to act on them. Any analysis that reads the rising line as "the world is getting more dangerous, and AI is why" is skipping this. VulnCheck / NIST NVD updates, 2024–2026

Microsoft's own numbers tell the same story — and 2026 broke the pattern

Across 24 months of Patch Tuesday, the monthly range held between 56 and 172 CVEs for eighteen months straight — then 2026 broke it: April 163, June 200, and July 2026's 569, the largest Patch Tuesday ever recorded. One record month isn't a trend, and the cause (AI-assisted research, more tooling, a reporting change) isn't separable from the public data. The full month-by-month dataset — every count, zero-day, and category split — is its own page.

See the complete Patch Tuesday dataset →