Blog
May 2, 2016
A Decade of Exploit Database Data
Managing the Exploit Database is one of those ongoing tasks that ends up taking a significant amount of time and often, we don’t take the time to step back and look at the trends as they occur over time. Have there been more exploits over the years? Perhaps fewer? Is there a shift in platforms being targeted? Has the bar for exploits indeed been raised with the increase in more secure operating system protections?
1 min read

Managing the Exploit Database is one of those ongoing tasks that ends up taking a significant amount of time and often, we don’t take the time to step back and look at the trends as they occur over time. Have there been more exploits over the years? Perhaps fewer? Is there a shift in platforms being targeted? Has the bar for exploits indeed been raised with the increase in more secure operating system protections?
Recently, one of our users reached out to us and showed us a great dashboard he created with Tableau using the publicly available CSV file we publish in our Exploit Database GitHub repository. We really liked this idea a lot and decided to run with it and see what kind of questions we could ask and answer with the available data. What makes these dashboards particularly useful is that they are not simply static displays; you can interact with them like the one below.
We find these glimpses into our data fascinating and we hope you will, too. A new statistics page has been created over at the Exploit Database that we will update on a monthly basis at minimum so please feel free to check it out regularly, interact with the dashboard, and join us in seeing how the world of exploitation changes over time.
Stay in the know: Become an OffSec Insider
Get the latest updates about resources, events & promotions from OffSec!
Latest from OffSec

Research & Tutorials
CVE-2025-23211: Tandoor Recipes Jinja2 SSTI to Remote Code Execution
A critical SSTI vulnerability was discovered in the open-source meal planning application Tandoor Recipes leading to a full system compromise.
May 8, 2025
2 min read

Research & Tutorials
CVE-2025-29927: Next.js Middleware Authorization Bypass
In this CVE blog, we explore a vulnerability in Next.js stemming from the improper trust of the x-middleware-subrequest header.
May 1, 2025
3 min read

Enterprise Security
When AI Becomes the Weak Link: Rethinking Supply Chain Security
AI is becoming a hidden entry point in supply chain attacks. Here’s why it matters and what organizations must do to stay protected.
Apr 30, 2025
7 min read