Data Explorer · AI-exploitation dataset

Every vulnerability VRL has driven to a verified AI exploit.

Every row represents an actual CVE that was run through a fully automated build-and-verify pipeline: a reproducible lab, an agent-generated proof-of-concept, and a negative + sham control to prove the signal is exploit-specific. Cost, token usage, and generation time are measured from the actual agent runs.

3,029
CVEs in the dataset
2,183
verified AI-exploitable
$2.83
median cost to build an exploit
11 min
median AI build-and-verify time
308k
median tokens to build a verified PoC
Interactive · every CVE, any two axes

Where each CVE ranks

Plot the dataset across any two measured parameters: cost, build time, tokens, EPSS probability, or the AI exploitability index (1 easy · 5 hard). Click any dot to inspect the CVE. Dots are coloured by exploitability index.

Y axis
X axis
1 Easy2 Low3 Moderate4 High5 Hard
2,533 CVEs plotted · 496 hidden (no value on one axis) · click a dot to inspect
0.0%20.0%40.0%60.0%80.0%100.0%$0.00$3.00$6.00$9.00$12.00$15.00avg 16.3%AI cost to create exploit (USD)EPSS exploitation probability (%)
Figure 1

Distribution of AI exploit cost (USD)

$0–1
124
$1–2
289
$2–3
687
$3–4
445
$4–5
206
$5–6
104
$6–7
49
$7–8
22
$8+
13
Figure 2

Distribution of AI build-and-verify time

0–5m
33
5–10m
723
10–15m
478
15–20m
208
20–30m
196
30m+
187
Figure 3

CVEs by exploit difficulty (report-graded)

Easy (first-try)
497
Medium
846
Hard
582
Unsolved
846
Unknown
258
Figure 4

EPSS score of AI-exploitable CVEs

< 1%
814
1–10%
660
10–50%
217
50–90%
177
90%+
304

The vulnerabilities AI weaponizes are the ones the industry’s risk signals overlook.

Every CVE is cross-referenced against its risk signals: EPSS exploitation-probability, CVSS severity, CISA KEV membership, public-exploit availability, and real-world exploitation. The signals defenders rank by consistently fail to flag what AI can weaponize.

37%
of AI-exploitable CVEs are rated <1% by EPSS
450
AI-exploitable with no public exploit available
193
AI-exploitable already seen exploited in the wild
Does a public PoC make the AI faster?

Building from scratch vs. from a public exploit

Among verified AI-exploitable CVEs, a pre-existing public exploit or PoC lets the agent reach a working exploit slightly faster and cheaper, though the gap is small. Even with no public exploit to work from, the median build still lands near $3.00 and about 11 minutes.

Figure 5

Median AI time to create exploit

Public exploit available
11.3 min
No public exploit
10.8 min
Figure 6

Median cost to create exploit

Public exploit available
$2.76
No public exploit
$3.00
Visualizations · what the dataset is made of

The software AI weaponizes, by class, ecosystem, and package.

Every CVE carries LoVi enrichment from Loginsoft: its weakness class, the package and ecosystem it lives in, the vendor product it ships in, and whether that software is open source or enterprise. The breakdowns below cover all 3,029 CVEs in the dataset.

Figure 7

CVEs by weakness class (CWE)

Path Traversal
299
Code Injection
247
Cross-site Scripting
181
OS Command Injection
181
Improper Input Validation
157
Deserialization of Untrusted Data
124
Command Injection
121
Server-Side Request Forgery
112
Uncontrolled Resource Consumption
99
SQL Injection
91
Exposure of Sensitive Information to an Unauthorized Actor
76
Improper Authentication
74

Open source dominates the dataset, but AI exploits enterprise software just as readily.

85% of the dataset is open-source packages, yet the harness reaches a verified exploit at nearly the same rate whether the target is open source or closed enterprise software. The only limiting factor was having access to the enterprise software in the lab to run the exploit against.

Looking for more enterprise coverage? Partner with us.

Figure 8

Open source vs enterprise software

Open source
2,555
Enterprise / closed
462
Undetermined
12

The 12 undetermined CVEs are recently disclosed and not yet classified by LoVi.

CISA KEV · the known-exploited catalog

What AI does with the vulnerabilities already known to be exploited.

371 CVEs in the dataset are on the CISA Known Exploited Vulnerabilities catalog. The harness drove 250 of them to a verified exploit (67%). Notably that is lower than the 73% rate on non-KEV CVEs: the known-exploited set skews toward memory-safety and native-code bugs that are harder to automate. KEV also skews enterprise, the mirror image of the open-source-heavy full dataset.

371
KEV CVEs in the dataset
250
KEV CVEs driven to a verified exploit
67%
KEV exploit success rate
73%
non-KEV exploit success rate
Figure 9

Exploited KEV CVEs: open source vs enterprise

Open source
101
Enterprise / closed
149
Figure 10

Exploited KEV CVEs by weakness class

Code Injection
37
Path Traversal
29
OS Command Injection
25
Improper Input Validation
16
Deserialization of Untrusted Data
16
Improper Access Control
11
Cross-site Scripting
10
Injection
9
Figure 11

Top vendor products in the KEV set

adobe:coldfusion
11
oracle:weblogic_server
10
apache:struts
8
synacor:zimbra_collaboration_suite
8
debian:roundcube
6
apache:tomcat
5
jenkins:jenkins
4
gnu:bash
3
imagemagick:imagemagick
3
dnnsoftware:dotnetnuke
3
On this data

Of 3,029 CVEs, 2,183 have a fully verified agent run with measured cost, timing, and token usage. Each CVE also carries its risk signals, so its AI-exploitability can be read against EPSS, CVSS, CISA KEV status, public-exploit availability, and real-world exploitation. EPSS is CVE-level exploitation probability from FIRST; cost, time, and tokens are medians over verified exploits.

Get research & product updates

No spam. Unsubscribe anytime. See our privacy policy.

Vulnerability Research Labs
Vulnerability Research Labs (VRL) is a research unit of Quantro Security, in partnership with Loginsoft.
Updated 17 Jul 2026 · n=3,029 · vulnerabilityresearchlabs.ai
© 2026 Vulnerability Research Labs (VRL). All rights reserved.