Skip to main content
ToolPotion

CVE-Bench Leaderboard

CVE-Bench Leaderboard evaluates AI agents' ability to autonomously exploit web vulnerabilities using a dataset of 40 critical CVEs. It offers two evaluation settings: one-day with vulnerability descriptions and zero-day without descriptions.

CVE-Bench Leaderboard screenshot

Description

CVE-Bench Leaderboard is a platform designed to assess the capability of AI agents in autonomously exploiting web vulnerabilities. The evaluation is based on a dataset of 40 critical Common Vulnerabilities and Exposures (CVEs) announced by NIST between May 1, 2024, and June 14, 2024. These CVEs cover a wide range of high-stakes exploits, including remote code execution, SQL injection, and privilege escalation.

The platform provides two realistic settings for evaluation: the one-day setting, where vulnerability descriptions are provided, and the zero-day setting, where descriptions are not available. This allows for a comprehensive assessment of an AI agent's ability to handle both known and unknown vulnerabilities.

The leaderboard features various agents, such as the Default Agent combined with Claude Opus 4.6, achieving a Pass@1 rate of 32.5% at an average cost of $0.31 per task. Another example is the T-Agent combined with GPT-4o, which has a Pass@1 rate of 8.0% with an average cost of $1.70 per task.

CVE-Bench is particularly useful for organizations and researchers interested in understanding the effectiveness of AI in cybersecurity. It provides insights into the strengths and weaknesses of different AI agents in handling web vulnerabilities, making it a valuable tool for improving AI-driven security solutions.

CVE-Bench Leaderboard's Core Features

  • Evaluates AI agents on web vulnerabilities

  • Dataset of 40 critical CVEs

  • Covers remote code execution, SQL injection

  • One-day evaluation setting

  • Zero-day evaluation setting

  • Pass@1 performance metric

  • Cost per task analysis

  • Benchmark version tracking

How to use CVE-Bench Leaderboard?

  1. Select evaluation setting: choose one-day or zero-day

  2. Run AI agent: execute the agent on selected CVEs

  3. Analyze results: review Pass@1 and cost metrics

  4. Optimize agent: improve based on performance data

CVE-Bench Leaderboard's Use Cases

  • AI vulnerability assessment
  • Cybersecurity research
  • AI agent optimization
  • Security solution development
  • Benchmarking AI tools

FAQ from CVE-Bench Leaderboard

CVE-Bench Leaderboard Reviews

Loading...

Popular AI Tools Like CVE-Bench Leaderboard

AI Apps

Online website vulnerability scanner with a built-in AI Analyst that orchestrates industry tools like OWASP ZAP, Nuclei, Nmap, WPScan and sqlmap, then turns raw findings into one…

AI Cybersecurity Tools

AI Apps

Horizon3 provides autonomous penetration testing to help organizations identify and remediate vulnerabilities before attackers can exploit them. With real-world attack…

AI Cybersecurity Tools

Equixly offers continuous API penetration testing with an Agentic AI Hacker. It autonomously discovers and tests APIs 24/7, identifying exploitable risks before attackers. This…

AI Cybersecurity Tools

Aptori is an AI-native application security platform that continuously validates runtime behavior, proves exploitability, and prioritizes real risk. It accelerates remediation,…

AI Cybersecurity Tools

AI Apps

Adversa AI offers an autonomous platform for continuous AI red teaming, specifically designed for AI agents, LLMs, and GenAI applications. It identifies and remediates security…

AI Cybersecurity Tools

Mindgard offers automated AI red teaming and security testing to discover, assess, and defend AI models, agents, and applications. It acts as an autonomous red teamer, mapping the…

AI Cybersecurity Tools

CyberSanctus is a cybersecurity company offering threat-driven penetration testing, red teaming, and vulnerability assessments, along with CodeHound, an AI-powered smart contract…

AI Cybersecurity Tools

AI Apps

White Hat is an AI-powered cybersecurity chatbot designed for ethical hackers. It provides intelligent, personalized, and real-time strategies and resources to help users fortify…

AI Cybersecurity Tools