"CopyFail" root access bug (CVE-2026-31431) had a severity score of 7.8 and they made a big deal out of it.So I downloaded all the CVEs, dropped all except 2025-2026, put them in severity score version bins, dropped ones below median from both, and put them in weekly stacks.Median ended up being near 7.0 in both so these are all more serious than level 7.There is no peak around Mythos and Project Glasswing, just slow and steady rising from 300-400 weeklies of 2025 to current 800-900 weeklies over the course of 6 months.Is this like Richter scale so that there's a huge difference between 7.0 and 7.8 or have they actually started making software safe and cozy like for real, in 2026?
So basically CVE just means it's a flaw in software. It doesn't even have to be security related.There's no standard with this shit and it's all muddied, but .gov is generally what you want
people report cves to pad their cvs or to get paid. meaning, it's either famous free/open source software (ffmpeg, sqlite, firefox etc) or stuff that pays "well" (microsoft products, google etc). a software having 0 cves doesn't mean it's secure, it just means there's no reward to reporting vulnerabilities in itcves got attention mostly because it's a way for it department to say "you can't use x software" or to try to get developers (and sometimes ops) to update their shit