A live snapshot from the Safeguard Gold corpus — what's vulnerable, what's actually being exploited, and how the AI supply chain is reshaping dependency risk.
Volume isn't risk — exploitation is. Of the 33,984 CVEs tracked, 1,637 are confirmed exploited in the wild by CISA, and 20.1% of those (329) are tied to ransomware campaigns — the vulnerabilities that most warrant patching first.
Dependencies are no longer just packages. AI models and MCP servers are new, fast-growing links in the supply chain — each with its own provenance, licensing, and security questions.
Want this analysis for your own dependencies?
Scan your project free