How many are realisically actionable vulnerabilities. The statistics have indicated so far that AI isn't really finding many non-minor bugs.
Seems to be a bit of selection bias baked into what AI is being asked to do. Tried AI (GLM-5.3) on new code that has never been executed. Also ran it against code that has been in production use for many years.
The types of bugs tended to be in obscure features, buggy error paths, parsing / protocol pedantry, cut and paste errors especially in various lookup tables, algorithm accuracy, inconsistencies, poor and obscure concurrency bugs. Can't really expect it to have found anything too important as it would have tripped up code and runtime analyzers or angry customers because all of that would have already been discovered and dealt with.
In the new code it found a couple of show stoppers that would be immediately obvious the second anyone tried it in addition to some more obscure things.
While I've not yet seen it discover any magical exploits it did get us to reconsider some questionable security related decisions and make improvements. Unfortunately tends to focus mostly on nuts and bolts rather than higher level machinery.
Been trying to get LLMs to do bug hunting for years and it has never worked. The AI just never had the depth to understand enough of what is going on to say anything useful. They still output quite a bit of crap... some of it isn't the models fault... for example tend to feed it source files one at a time to keep from blowing through too much context. This requires the models to make all kinds of inferences about dependencies it has no real knowledge of... sometimes it doesn't make the right assumptions. Sometimes it says nonsensical things or doesn't seem to "see" its own context perfectly misreading the code and complaining about something that isn't real... still well worth the effort. Amazing this shit works at all.