A live snapshot from the Safeguard Gold corpus — what's vulnerable, what's actually being exploited, and how the AI supply chain is reshaping dependency risk.
Volume isn't risk — exploitation is. Of the 12,185 CVEs tracked, 1,695 are confirmed exploited in the wild by CISA, and 20.9% of those (354) are tied to ransomware campaigns — the vulnerabilities that most warrant patching first.
Dependencies are no longer just packages. AI models and MCP servers are new, fast-growing links in the supply chain — each with its own provenance, licensing, and security questions.
Want this analysis for your own dependencies?
Scan your project free