Robot vulnerability explorer
395 robot vulnerabilities aggregated and de-duplicated across the Robot Vulnerability Database, NVD, EUVD, CISA ICS advisories and FDA surgical-robot cybersecurity recalls, cross-referenced against CISA KEV — plus curated research findings that never received a CVE. Each links to its source record. Want to score a flaw yourself? Try the interactive RVSS calculator →
No single database is enough
Robot vulnerabilities are scattered across disconnected registries that barely reference one another. Among the 386 records represented in the four primary registries below, 72% appear in just one — so relying on any single database leaves most of the field invisible. FDA recalls and cited research add findings outside those four sets.
And the sources aren't only fragmented — they're fragile. Through 2024 the NVD, the field's primary database, left roughly 93% of new CVEs un-enriched in a backlog it has since conceded it cannot clear; in April 2025 the CVE program itself came within a day of losing its funding. Aggregating and cross-referencing several sources isn't just thoroughness — it's the only resilient answer when any one of them can stall or go dark.
Overlap of RVD, NVD, EUVD and CISA ICS advisory records after de-duplication by CVE; CISA KEV cross-referenced. NVD backlog: NIST/VulnCheck; CVE funding lapse: Krebs on Security.Severity × year
Where robot vulnerabilities cluster — count by severity band and disclosure year.
All aggregated, source-attributed records — 395 after de-duplication.The window to patch is closing
Across all software, the median time from a vulnerability going public to its first exploitation has collapsed — the original US Zero Day Clock fell from 771 days in 2018 to same-day by 2025, and the EU's ENISA EUVD from roughly four years to days. A server can be patched inside that window; a fleet of certified, safety-critical robots — often offline for months, expensive to recertify — cannot. Meanwhile robot vulnerabilities keep arriving year after year (black bars). As exploitation turns instant, the machines that move inherit the sharpest end of it. Hover for values.
Median time-to-exploit: US Zero Day Clock (CISA KEV + Exploit-DB + Metasploit) and EU ENISA EUVD, 2018–2026, from the lab's Certifying Ghosts analysis; robot-vulnerability totals from the aggregated dataset above. Log scale; 0 shown as same-day.| ID | Vulnerability | Severity | Vendor | Year | Sources |
|---|
Sources: RVD (github.com/aliasrobotics/rvd) · NVD (nvd.nist.gov) · EUVD (euvd.enisa.europa.eu) · CISA ICS advisories (cisa.gov, CSAF) · FDA surgical-robot cybersecurity recalls (openFDA) · CISA KEV · curated Research (documented robot flaws with no assigned CVE). Rebuilt by build/update_data.py.