Why a CVE count is not a security score
11 min
It is tempting to rank vendors by how many CVEs they have. Resist it. The count measures three things, and product quality is not reliably one of them.
What the number actually tracks
- Disclosure practice. A vendor who runs a real advisory process, issues CVEs for their own findings and credits external researchers will out-count a vendor who quietly fixes things in a point release. Counting CVEs punishes the first behaviour and rewards the second.
- Portfolio breadth. A vendor with forty products will out-count a vendor with one. That is arithmetic, not risk.
- Researcher attention. Widely deployed products attract more scrutiny. Popularity raises the count.
And a zero means "not catalogued", which is not the same as "no vulnerabilities" and is often the opposite of reassuring.
What to read instead
Read the advisories themselves, and ask different questions. How quickly did a fix ship after disclosure? Was the advisory clear about affected versions and workarounds, or was it written to be technically true and practically useless? Is there a named security contact and a published policy? Were external researchers credited, or fought?
A vendor who publishes clearly and fixes quickly is a better bet than a vendor with a quiet CVE page. DBSE shows CVE counts on the vendor page and scores them into nothing, for exactly these reasons.