Data Explorer · AI-exploitation dataset
Every vulnerability VRL has driven to a verified AI exploit.
Every row represents an actual CVE that was run through a fully automated build-and-verify pipeline: a reproducible lab, an agent-generated proof-of-concept, and a negative + sham control to prove the signal is exploit-specific. Cost, token usage, and generation time are measured from the actual agent runs.
Where each CVE ranks
Plot the dataset across any two measured parameters: cost, build time, tokens, EPSS probability, or the AI exploitability index (1 easy · 5 hard). Click any dot to inspect the CVE. Dots are coloured by exploitability index.
Distribution of AI exploit cost (USD)
Distribution of AI build-and-verify time
CVEs by exploit difficulty (report-graded)
EPSS score of AI-exploitable CVEs
The vulnerabilities AI weaponizes are the ones the industry’s risk signals overlook.
Every CVE is cross-referenced against its risk signals: EPSS exploitation-probability, CVSS severity, CISA KEV membership, public-exploit availability, and real-world exploitation. The signals defenders rank by consistently fail to flag what AI can weaponize.
Building from scratch vs. from a public exploit
Among verified AI-exploitable CVEs, a pre-existing public exploit or PoC lets the agent reach a working exploit slightly faster and cheaper, though the gap is small. Even with no public exploit to work from, the median build still lands near $3.00 and about 11 minutes.
Median AI time to create exploit
Median cost to create exploit
The software AI weaponizes, by class, ecosystem, and package.
Every CVE carries LoVi enrichment from Loginsoft: its weakness class, the package and ecosystem it lives in, the vendor product it ships in, and whether that software is open source or enterprise. The breakdowns below cover all 3,029 CVEs in the dataset.
CVEs by weakness class (CWE)
Open source dominates the dataset, but AI exploits enterprise software just as readily.
85% of the dataset is open-source packages, yet the harness reaches a verified exploit at nearly the same rate whether the target is open source or closed enterprise software. The only limiting factor was having access to the enterprise software in the lab to run the exploit against.
Looking for more enterprise coverage? Partner with us.
Open source vs enterprise software
The 12 undetermined CVEs are recently disclosed and not yet classified by LoVi.
What AI does with the vulnerabilities already known to be exploited.
371 CVEs in the dataset are on the CISA Known Exploited Vulnerabilities catalog. The harness drove 250 of them to a verified exploit (67%). Notably that is lower than the 73% rate on non-KEV CVEs: the known-exploited set skews toward memory-safety and native-code bugs that are harder to automate. KEV also skews enterprise, the mirror image of the open-source-heavy full dataset.
Exploited KEV CVEs: open source vs enterprise
Exploited KEV CVEs by weakness class
Top vendor products in the KEV set
Of 3,029 CVEs, 2,183 have a fully verified agent run with measured cost, timing, and token usage. Each CVE also carries its risk signals, so its AI-exploitability can be read against EPSS, CVSS, CISA KEV status, public-exploit availability, and real-world exploitation. EPSS is CVE-level exploitation probability from FIRST; cost, time, and tokens are medians over verified exploits.