CVE Records by CNA

Two questions a small model answers well

We asked Cloudflare's Clef decision models, running locally, many questions about each CVE record. Two held up: whether the description says why the bug matters to security, and how clear the description is for a defender. Everything else on this page comes from rule checks that need no model.

How descriptions support a security impact

Rule checks and Clef's read, by CNA

Which CNAs say why it matters

No security impact stated

Share of each CNA's descriptions.

Description clarity

Average level, 0 Unusable to 4 Excellent.

Least clear descriptions outside the Linux kernel

Can the small model be trusted? Mostly, with a second look

How this was made

Data, rule checks, models, and caveats