What percentage of those will actually be exploited in the hands of typical users? There's not exactly worm grade exploits flying around for these devices.
Most of the vulnerabilities require you to be loading sketchy apps, many of these are checked on Play Store by scanners, so unless you get very unlucky or sideload sketchy apps, probably not a concern. Web view and most other network exposed components are updated from play store, since stagefright they sandboxed all codecs, etc.
It's really not that bad for a typical user to just run an unpatched phone, certainly better than a Windows machine with local admin where downloading and running one executable is all it takes. At least on an unpatched Android device they get some level of sandboxing.