Share of published vulnerabilities NVD has rated
This chart tracks how much of the published vulnerability flood the National Vulnerability Database has actually rated. NVD assigns severity scores to a roughly constant number of records each month, so as publications tripled its coverage fell from over 90 percent in early 2024 to around an eighth. Most records still carry a score from whoever reported them; what has thinned is the independent analysis layer on top. This measures analysis throughput against reporting volume, not severity: among rated records, the high-or-critical share sits near half throughout and shows no trend.
What does it show?
NVD rated over 90% of published CVEs in early 2024 and about an eighth by mid-2026: its throughput held roughly flat while publications tripled.
Methodology
CVE records published in each month that carry a CVSS v3 base severity assigned by the National Vulnerability Database, as a percentage of all CVE records published that month. The numerator is the sum of NVD's own critical, high, medium and low counts for that publication window; the denominator is the count behind cve-volume, for the same window. NVD's severity filter matches ratings NVD assigned, not ratings supplied by the organization that reported the flaw, so most published records still carry a CVSS score from their reporter even when NVD has not rated them. Coverage falling is a statement about analysis throughput against reporting volume, not about how severe vulnerabilities are: among the records NVD has rated, the share that is high or critical sits near half across this whole period and shows no trend. The current month is excluded, because a part-month is a smaller number for a mechanical reason.