← Portfolio Working analysis

MedCVE

An analysis of 1,515 healthcare-tagged CVE records, from cleaning and metric definitions to nine JSON exports and a static dashboard.

Context
Personal analysis project on a public vulnerability dataset. It continues the earlier MedRadar work.
Stack
Python 3.12, pandas and Jupyter for analysis, pytest and ruff for checks, and a static HTML and JavaScript dashboard that reads the exported JSON.
Role
Sole author

At a glance

Working
Status: analysis and dashboard published
1,515
CVE records, none dropped
9
JSON exports behind the dashboard
19
Tests, all passing on 24 Sep 2026
01

Question

Which healthcare-related vulnerabilities are most severe and most reachable, and how should a small team decide what to look at first?

The data is a public CSV of CVE records from the NIST National Vulnerability Database, tagged with healthcare keywords. It is public vulnerability data, not patient records.

02

Cleaning

  • All 1,515 records are kept. Counts and shares use the full set, including rows with missing values.
  • Dates are parsed, the CVSS score is converted to a number, and a publication year is derived for the annual view.
  • An empty field and the string N/A are read as the same missing value.
  • Severity, CVSS score and attack vector are each missing in 18 records.
03

Definitions

  • Rates use the full dataset as the denominator, so missing values stay visible instead of quietly inflating a rate.
  • CVSS scores of exactly 0.0 and missing scores fall in no band, so band shares can add up to less than 100%.
  • The domain priority score and the triage score are ordering heuristics with hand-picked weights, not security scores.
  • The metric builders live in analysis/metrics.py as plain functions; the notebook imports them, adds plots and the write-up, and exports the JSON.
04

What the data shows

1,515
CVE records
151
Rated critical
42.4%
High or critical, missing severity included in the denominator
84.4%
Network attack vector, which suggests remote reachability
574
Both high or critical and network-reachable

The largest severity group is medium (720 records). The most common weaknesses are SQL injection, CWE-89 (308), and cross-site scripting, CWE-79 (247).

05

Dashboard

The MedCVE dashboard: the headline count of 1,515 known vulnerabilities, a one-sentence summary, and the annual trend chart.
The live dashboard opens on one number and a sentence instead of a row of KPI cards. Below it, each section leads with its point, computed from the data, and puts a chart or table beside it.
06

Verification

Checked on 24 Sep 2026 with Python 3.12: all 19 tests pass. They check the metric builders on a small synthetic CSV, and check that the committed exports still match what the raw data produces. CI runs ruff and pytest on every push.

07

Limitations

  • The trend chart and heatmap are plain HTML and CSS, with no filtering or drill-down.
  • The priority and triage scores use hand-picked weights.
  • This is an analysis of public vulnerability records, not a deployed security tool.
GitHubMedCVE: source and READMEOpen ↗GitHub PagesMedCVE: live dashboardOpen ↗