I don't have any data on exploitability, but 19 of the last 22 vulnerabilities (since 2018) have C-induced memory unsafety as a cause: https://curl.haxx.se/docs/security.html
Which it sounds like the answer is nonzero. But significantly smaller than "every C bug since 1988".