Published CVEs seems a bad metric to use for this- unless we assume that the ratio of really nasty vulns/not-too-bad vulns is consistent.
It's easier to find a needle in the haystack if the haystack is 50% needles.
just doubled the value and use cases of your AI solution!
Publish something to Github in a public repo? It pulls it, scans it, and reports!
Especially if you accidentally put in keys