An average would hide the story here. The distribution is heavily bimodal: a cluster of vulnerabilities that reach KEV within days of publication, and a long tail of much older CVEs that are added years later because someone finally found them being exploited.
Those two populations mean different things. The fast cluster is exploitation racing disclosure. The long tail is mostly discovery lag on our side, not attacker behaviour — a vulnerability added seven years after publication was very likely exploited long before it was listed.
Where the NVD fetcher has run, publication dates come from NVD; otherwise the CVE year is used, which is coarser but never wrong in the direction that would flatter the chart.