Application Security

Dependency Vulnerability Age Calculator

Enter CVE published date, patch available date, and CVSS score to compute exposure window, patch urgency SLA, and comparison against industry averages.

No data is transmitted โ€” everything runs locally

Example โ€” Representative default scenario โ€” days open 67 ยท severity high.

Exposure window
0 days
CVE published to patch
SLA for CVSS 5
30 days
Medium
SLA status
โœ“ Within SLA
Risk level
Medium
CVSS 5

Dependency Vulnerability Age Calculator

The Dependency Vulnerability Age Calculator computes CVE exposure window, patch SLA tier from CVSS score, and comparison against industry mean time to patch benchmarks.

โ€ข Calculate how long a production system has been exposed to a CVE

โ€ข Determine SLA urgency tier from CVSS score before scheduling a patch

โ€ข Compute exposure window for a security incident post-mortem

โ€ข Compare patch timeline against NIST mean time to patch benchmarks

Uptime, incident, and on-call management. Better Stack provides status pages, incident management, and on-call scheduling for engineering teams.
Alert on new vulnerability events in real time โ€” Better Stack security monitoring
External site ยท Independent provider ยท We may receive a commission ยท Not a recommendation
What does this tool tell you?
The Dependency Vulnerability Age Calculator computes CVE exposure window, patch SLA tier from CVSS score, and comparison against industry mean time to patch benchmarks.
What affects the result most?
Vulnerability exposure window: days from CVE published to patch applied. Mean time to patch (MTTP): industry average is 60-120 days โ€” high risk for critical CVEs. CVSS score to patch urgency: Critical (9.0+) = 24-72h SLA, High (7.0-8.9) = 7 days, Medium = 30 days.
How should I use the result?
The calculation is deterministic โ€” the same inputs always produce the same output โ€” so the most useful workflow is to vary one input at a time and see which factor moves the result most. That tells you where to focus your attention before committing to a decision.
Application security certification details. Practical DevSecOps certification โ€” CZTP and related courses for AppSec practitioners. Maps to OWASP, JWT, TLS, dependency security tools.
View AppSec certification details โ†’
External site ยท Independent provider ยท We may receive a commission ยท Not a recommendation