CISA created the KEV catalog in part because of challenges
that organizations have historically faced in prioritizing
vulnerabilities. In any given year, there are tens of thousands of new vulnerabilities. But according to CISA, a study of historical vulnerability data dating back to 2019 shows that less than 4% of all known vulnerabilities were being used by attackers in the wild.
(more available)