In the case of any list, if you're actually doing it right, things should be dropping off the list
I'm not sure anything has ever really come off any security list because an effort was made to get rid of it
Maybe if CISAs push to stop using memory unsafe languages, in 200 years, we can remove buffer overflows :P