In today's episode of "CVE is a disaster":
Anthropic has published a cordinated vulnerability disclosure dashboard for their findings.
Vulnerabilities disclosed: 1596
Vulnerabilities patched: 97
Assigned a CVE or a GHSA: 88
...
CVE COUNT for 1596 disclosed vulnerabilities: 14
If something has an adoption rate of less than 1%, what do you call it?
Edit: Apparently Anthropic doesn't know what the word "disclosed" means. In their article about Coordinated Vulnerability Disclosure, Anthropic uses "disclosed" to mean "reported" (to the maintainer). In which case we'd have a 14% success rate for CVE.


