Rank the vendors in your stack by how many actively-exploited (KEV) vulnerabilities they carry. Confirmed exploitation, not theoretical severity.