According to a report released by VulnCheck on Wednesday, over the past year, although less than 1% of software vulnerabilities were actually exploited in the wild, the speed and scale of weaponization of these vulnerabilities exceeded that of any previous time.

Researchers tracked more than 14,400 exploits related to approximately 10,500 unique CVEs in 2025, an increase of 16.5% over the previous year. A significant portion of this growth is related to AI-generated PoC (proof-of-concept) code. However, researchers caution that many of these AI-generated codes are not actually functional.

The results highlight the difficulty security teams face in determining which threats are most severe and require priority investigation. Threat groups are increasingly able to weaponize vulnerabilities before network defenders can apply security patches or take other mitigation measures.

"Defenders have long regarded publicly available exploit code as an important risk signal," Caitlin Condon, vice president of security research at VulnCheck, told Cybersecurity Dive.

Condon noted that the research shows a large amount of AI-generated information is causing trouble for defenders, making it difficult for them to distinguish which are real threats and which can be ignored.

Among ransomware-related CVEs, more than 50% were initially identified through zero-day vulnerabilities.

React2Shell (tracked asCVE-2025-55182) was the top vulnerability of 2025, with 236 known exploits.

A Microsoft SharePoint vulnerability (tracked asCVE-2025-53770) had 36 known exploits.