Software law is compounding

Security's catalog of known software flaws grew year after year, and the industry answered with a shared catalog, severity scores, checks where code is written, and a list of the flaws attackers actually use. Software law is on a similar curve now, and the same answers are arriving in years rather than decades. This chart sets the two side by side. This page always carries its latest version.

Two charts side by side, both from 1999. Left: CVEs published, running total, rising to more than 300,000 by the end of 2025, with four numbered milestones: the CVE list in 1999, NVD and CVSS scores in 2005, GitHub alerts on vulnerable dependencies in 2017, and CISA's list of exploited flaws in 2021. Under it, a dotted line of flaws on CISA's list, by CVE year, to the end of 2025. Right: provisions of software law still in force today in the LexLint law library, by the date each began to bind, rising slowly until a jump when GDPR applied in 2018 and compounding since, with AI law the newest layer, a band of starts already scheduled and a dotted trend. Under it, a dotted line of GDPR fines imposed, running total in euros. Below both, a four-step ladder pairing each step security took with where software law stands today.
Data as of . Download the chart (an image, 3,200 by 2,000 pixels).

How to read it

Sources

Use and credit

The chart is © 2026 UnGovr, which makes LexLint, and is licensed under Creative Commons Attribution 4.0 (CC BY 4.0): share and adapt it, including commercially, with credit to UnGovr and a link to this page. The license covers the chart. The sources above keep their own terms, and logos and wordmarks belong to their owners.