We asked Cloudflare's Clef decision models, running locally, many questions about each CVE record. Two held up: whether the description says why the bug matters to security, and how clear the description is for a defender. Everything else on this page comes from rule checks that need no model.
Share of each CNA's descriptions.
Average level, 0 Unusable to 4 Excellent.