Cybersecurity RoboticsRobot cybersecurity research lab

Robot vulnerability explorer

395 robot vulnerabilities aggregated and de-duplicated across the Robot Vulnerability Database, NVD, EUVD, CISA ICS advisories and FDA surgical-robot cybersecurity recalls, cross-referenced against CISA KEV — plus curated research findings that never received a CVE. Each links to its source record. Want to score a flaw yourself? Try the interactive RVSS calculator →

395
robot vulnerabilities aggregated
RVD · NVD · EUVD · CISA-ICS · FDA · Research
239
rated high or critical severity
CVSS / RVSS
311
with an assigned CVE identifier
cve.org
51
robot-security milestones (2009–2026)
see Milestones

No single database is enough

Robot vulnerabilities are scattered across disconnected registries that barely reference one another. Among the 386 records represented in the four primary registries below, 72% appear in just one — so relying on any single database leaves most of the field invisible. FDA recalls and cited research add findings outside those four sets.

And the sources aren't only fragmented — they're fragile. Through 2024 the NVD, the field's primary database, left roughly 93% of new CVEs un-enriched in a backlog it has since conceded it cannot clear; in April 2025 the CVE program itself came within a day of losing its funding. Aggregating and cross-referencing several sources isn't just thoroughness — it's the only resilient answer when any one of them can stall or go dark.

EUVD147NVD173RVD162CISA-ICS349691172%appear in a single databaseof 386 primary-registry records
Overlap of RVD, NVD, EUVD and CISA ICS advisory records after de-duplication by CVE; CISA KEV cross-referenced. NVD backlog: NIST/VulnCheck; CVE funding lapse: Krebs on Security.

Severity × year

Where robot vulnerabilities cluster — count by severity band and disclosure year.

2017201820192020202120222023202420252026critical263355112268high2103447111218319medium392259510161low1142
All aggregated, source-attributed records — 395 after de-duplication.

The window to patch is closing

Across all software, the median time from a vulnerability going public to its first exploitation has collapsed — the original US Zero Day Clock fell from 771 days in 2018 to same-day by 2025, and the EU's ENISA EUVD from roughly four years to days. A server can be patched inside that window; a fleet of certified, safety-critical robots — often offline for months, expensive to recertify — cannot. Meanwhile robot vulnerabilities keep arriving year after year (black bars). As exploitation turns instant, the machines that move inherit the sharpest end of it. Hover for values.

Median time-to-exploit: US Zero Day Clock (CISA KEV + Exploit-DB + Metasploit) and EU ENISA EUVD, 2018–2026, from the lab's Certifying Ghosts analysis; robot-vulnerability totals from the aggregated dataset above. Log scale; 0 shown as same-day.
IDVulnerabilitySeverityVendorYearSources

Sources: RVD (github.com/aliasrobotics/rvd) · NVD (nvd.nist.gov) · EUVD (euvd.enisa.europa.eu) · CISA ICS advisories (cisa.gov, CSAF) · FDA surgical-robot cybersecurity recalls (openFDA) · CISA KEV · curated Research (documented robot flaws with no assigned CVE). Rebuilt by build/update_data.py.