How CVE records distribute across canonical vendor names. This is record volume and severity mix — not a supplier quality verdict.
Public CVE records only. Nothing here is evidence that the vulnerability exists on your assets.
Powered by: public.cves via fetchCves · canonical vendor names via src/lib/vendor-aliases.ts
Rule: Rows are grouped by canonical vendor name. Mean priority = Σ Priority ÷ record count; critical density = critical records ÷ records; recurrence = records ÷ distinct CWEs. Raw localized vendor strings are kept for drill-down and never split a vendor total.
Rows are grouped by canonical vendor name, so a vendor written differently in different records still counts once. Raw strings stay available on the underlying records.
Not a supplier verdict. Asset footprint per vendor is Unknown — not collected in catalogue mode, and supplier remediation performance and contract context are unknown — not collected. CVE volume alone is not a basis for procurement, consolidation or SLA decisions.