YES, IT'S VERMARCABLE
Cybersecurity: CVE, CVSS and Data-Breach Cost Benchmarks
A free, platform-curated benchmark set for cybersecurity — cumulative and yearly CVE publication counts, the CVSS v3.1 severity bands, the size of the CISA Known Exploited Vulnerabilities catalog, and widely cited data-breach cost and time-to-contain figures — drawn from the National Vulnerability Database, FIRST, CISA, and established industry reports. Period-tagged and sourced. Built for security teams, risk analysts, and CISOs.
{
"_type": "curated_open_data",
"as_of": "2024-08",
"links": {
"canonical": "https://verticalmarketplace.ai",
"docs_for_llms": "https://verticalmarketplace.ai/llms.txt",
"sell_your_own": "https://verticalmarketplace.ai/api/marketplace/listings",
"vertical_listings": "https://verticalmarketplace.ai/api/marketplace/listings?vertical=cybersecurity"
},
"records": [
{
"unit": "records",
"value": "240,000+",
"metric": "Total CVE records published (cumulative)",
"period": "as of 2024",
"source": "CVE Program / NVD"
},
{
"unit": "records",
"value": "~28,900",
"metric": "New CVEs published",
"period": "2023",
"source": "National Vulnerability Database"
},
{
"unit": "records",
"value": "~25,000",
"metric": "New CVEs published",
"period": "2022",
"source": "National Vulnerability Database"
},
{
"unit": "records",
"value": "~20,000",
"metric": "New CVEs published",
"period": "2021",
"source": "National Vulnerability Database"
},
{
"unit": "base score",
"value": "9.0-10.0",
"metric": "CVSS v3.1 severity - Critical",
"period": "v3.1",
"source": "FIRST"
},
{
"unit": "base score",
"value": "7.0-8.9",
"metric": "CVSS v3.1 severity - High",
"period": "v3.1",
"source": "FIRST"
},
{
"unit": "base score",
"value": "4.0-6.9",
"metric": "CVSS v3.1 severity - Medium",
"period": "v3.1",
"source": "FIRST"
},
{
"unit": "base score",
"value": "0.1-3.9",
"metric": "CVSS v3.1 severity - Low",
"period": "v3.1",
"source": "FIRST"
},
{
"unit": "vulnerabilities",
"value": "1,100+",
"metric": "CISA Known Exploited Vulnerabilities catalog",
"period": "2024",
"source": "CISA"
},
{
"unit": "USD",
"value": "4.45 million",
"metric": "Average cost of a data breach (global)",
"period": "2023",
"source": "IBM Cost of a Data Breach"
},
{
"unit": "USD",
"value": "4.88 million",
"metric": "Average cost of a data breach (global)",
"period": "2024",
"source": "IBM Cost of a Data Breach"
},
{
"unit": "days",
"value": "277",
"metric": "Mean time to identify and contain a breach",
"period": "2023",
"source": "IBM Cost of a Data Breach"
},
{
"unit": "percent",
"value": "68",
"metric": "Breaches involving a human element",
"period": "2024",
"source": "Verizon DBIR"
}
],
"sources": [
{
"url": "https://nvd.nist.gov",
"name": "National Vulnerability Database"
},
{
"url": "https://www.first.org/cvss",
"name": "FIRST CVSS"
},
{
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
"name": "CISA Known Exploited Vulnerabilities Catalog"
}
],
"category": "benchmarks",
"vertical": "cybersecurity",
"data_note": "All records are public-domain facts compiled from the cited sources as of the asOf date. This content is authored and served by the platform itself — it is not seller data, so the marketplace's zero-storage promise about seller datasets is unaffected.",
"record_count": 13,
"what_this_is": "A platform-published open-data listing curated by Open Data Desk, the marketplace's in-house public-data seller. It is real free inventory: it counts in marketplace statistics and is purchasable for $0 through the normal purchase flow, which delivers this payload with an Ed25519-signed receipt.",
"record_schema": {
"unit": "Unit of measurement",
"value": "Reported figure",
"metric": "The vulnerability, scoring, or breach measure",
"period": "Year or version the figure covers",
"source": "Public registry or established report"
},
"buyer_use_cases": [
"Prioritize remediation using CVSS bands and the CISA KEV catalog",
"Benchmark breach-cost exposure for risk and insurance planning",
"Contextualize an organization's CVE backlog against annual publication rates"
]
}The full dataset is delivered after purchase. Fingerprint: sha256:e84700e0e11fbb95d0c25b2009f8bd77fddc677f4ebe6dfaf6b3806ea690fb65
No answered questions yet — ask the seller anything about this listing.
Data is contributed by independent third-party sellers. Vertical Marketplace facilitates the transaction; sellers keep 95% on everyday sales from $20 to $49,999.99 under the year-one founding rate locked through 2027-06-30 (full schedule: GET /api/meta). Prohibited content (digital keys/licenses/game codes, and health data the seller does not own — e.g. patient records) is not permitted; individuals may sell their own personal health data only via the signed Health Data Consent Flow. See /terms.
- Use the purchased data for your own commercial and non-commercial work
- Create derivative analyses, models, and works from the data
- No reselling or re-listing the purchased data on this or any other marketplace
- No redistributing the raw dataset as-is to third parties
- Exclusive listings are sold to a single buyer and delisted on purchase
- Limited listings are sold to a capped number of buyers and delisted once sold out
No key? Register an agent — it's free.
For agents — buy by prompt
Bring your own agent. Open HTTP API + MCP — works with compatible agent runtimes that support the required API calls and authentication. Vermarco is not affiliated with, endorsed by, or partnered with Anthropic, OpenAI, Google, xAI, or Perplexity. One-click consumer-app connectors are not built yet; connect via API key or MCP from your agent runtime.