Jerry Gamblin
jgamblin.bsky.social
Jerry Gamblin
@jgamblin.bsky.social
Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.
2025 CVE Stats Update (October 31st, 2025)
Total Number of CVEs: 39,681
Average CVEs Per Day: 130.53
Average CVSS Score: 6.61
YOY Growth: 22.42% or +7,267 (32,414 CVEs in 2024)
November 1, 2025 at 5:33 PM
Forget cryptocurrency—let's talk real cryptography! If you're into ciphers and code-breaking, this special on the hidden messages of Mary, Queen of Scots, is a must-watch. www.pbs.org/video/cracki...
Secrets of the Dead | Cracking the Queen's Code | Season 22 | Episode 9
See how secret letters written by Mary, Queen of Scots, were finally decoded.
www.pbs.org
October 23, 2025 at 1:14 PM
Spent Sunday watching football & analyzing 314,705 CVEs to track update velocity.

Key takeaway: Some issues require constant attention—the top CVE, CVE-2023-4255, has been updated 220 times! See the full analysis and charts:
rogolabs.github.io/CVE-Updates/
October 20, 2025 at 3:55 PM
📢 New Open-Source Tool: CNAPulse.org

Getting a quick, transparent overview of CNA activity was nearly impossible. It required manual processing of raw CVE data.

I built CNAPulse.org to automate and bring transparency to publishing in the CVE ecosystem.
CNAPulse
CNAPulse.org
October 16, 2025 at 4:04 PM
2025 CVE Stats Update (September 30th, 2025)
Total Number of CVEs: 35,404
Average CVEs Per Day: 129.68
Average CVSS Score: 6.62
YOY Growth: 22.72% or +6,555 (28,849 CVEs in 2024)
October 1, 2025 at 8:49 AM
I've added a new page to CVEForecast.org: a CNA Forecast. It's a fun project to track the growth and decline trends.

Hopefully, it provides some interesting insights for anyone in the vuln space.

Check it out here: cveforecast.org/cna_forecast...

#infosec #cybersecurity #vulnerability #cve
CVEForecast
CVEForecast.org
September 17, 2025 at 2:13 PM
The CVE Program is stepping into its Quality Era, and I couldn't be happier.

CISA's vision prioritizes trust, quality, and responsiveness in vulnerability management. This is a fantastic step to ensure CVE data remains a public good for everyone

www.cisa.gov/sites/defaul...
www.cisa.gov
September 11, 2025 at 11:54 PM
2025 CVE Stats Update (August 31st, 2025)

Total Number of CVEs: 31,077
Average CVEs Per Day: 127.89
Average CVSS Score: 6.63
YOY Growth: 17.81% or +4,699 (26,378 CVEs in 2024)
September 1, 2025 at 5:14 PM
Here are my slides from #BSidesLV on "The Art of Concealment."

TLDR: Many CVEs are published without the four pillars (CWE, CPE, CVSS, Fix) needed for security teams to remediate the vulnerabilities successfully.

rogolabs.net/Talks/The%20...
rogolabs.net
August 12, 2025 at 5:45 PM
At DEF CON? I'm speaking today at 1PM in the AppSec Village. Stop by to hear me talk about the post NVD era of vulnerability data.
August 8, 2025 at 6:02 PM
Just announced after my talk: CNAScorecard.org is LIVE! 🚀

Did you know only 2% of CVEs have CPE data and just 4.8% have patch info? This cripples automation & leaves us blind.
CNA Scorecard
CNAScorecard.org
August 5, 2025 at 10:18 PM
2025 CVE Stats Update (July 31st, 2025)
Total Number of CVEs: 27,447
Average CVEs Per Day: 129.47
Average CVSS Score: 6.62
YOY Growth: 17.32% or +4,053 (23,394 CVEs in 2024)
August 1, 2025 at 5:57 PM
Relaunched my open-source project, cve.icu! It's been completely rewritten in pure HTML—making it blazing fast & fully interactive.

Designed to cut through the noise of 40k+ new vulns a year. Explore vulnerability data faster. 🚀

cve.icu
CVE.ICU - CVE Analysis Dashboard
Comprehensive CVE analysis and visualization from 1999 to present
cve.icu
July 30, 2025 at 1:31 PM
Vegas-bound! ✈️ I'm giving two talks next week on CVEs and vulnerability disclosure.

First up is @bsideslv.org on Tues, 2:30pm: "The Art of Concealment: CVE's Challenge with Transparency"(thread 👇)
July 29, 2025 at 9:36 PM
CVEScoreCard v.06 is live. 🤖

My open-source CVE forecast now auto-tunes itself daily, learning from past runs to get more accurate. Today, it's predicting 46,796 CVEs for the year.

See the live forecast: cveforecast.org #cybersecurity #cve #opensource #infosec
CVEForecast
cveforecast.org
July 19, 2025 at 8:43 AM
Inspired by the excellent work from the folks at vuln4cast & @firstdotorg on vulnerability forecasting, I spent the weekend building a little tool.

Announcing cveforecast.org! 🚀

A simple site to forecast the growth of CVEs. Hope it's useful to the community!
CVEForecast
cveforecast.org
July 7, 2025 at 1:32 AM
2025 CVE Stats Update (June 30th, 2025)
Total Number of CVEs: 23,668
Average CVEs Per Day: 130.76
Average CVSS Score: 6.59
YOY Growth: 16.22% or +3303 (20365 CVEs in 2024)
July 1, 2025 at 1:50 PM
An AI BBQ Grill? No thanks. I learned from my grandpa, and his only algorithm was clicking the tongs twice and saying, "Yep, 'bout done."
briskitgrills.com/collections/...
Brisk It Zelos-450 Smart, A.I. Powered and WiFi Grill
The smart grill for everyone - make wood-smoked grilling easy and accessible through advanced wifi and automation technology. Push a single button and our grilling intelligence will take care of every...
briskitgrills.com
June 28, 2025 at 12:27 AM
I built (vibecoded) a small game to see how fast you can sort 100 team logos. Test your sports knowledge and see how fast you can sort 100 logos! 🏈⚾️🏀

Play it here: jgamblin.github.io/logosort/
Logo Sort Challenge
jgamblin.github.io
June 27, 2025 at 1:21 AM
Thrilled my talk "The Art of Concealment: CVE's Challenge with Transparency” was accepted at #BSidesLV this summer! Excited to discuss CVE transparency in Vegas. See you there!
June 4, 2025 at 1:41 PM
2025 CVE Stats Update (May 31st, 2025)
Total Number of CVEs: 19998
Average CVEs Per Day: 132.44
Average CVSS Score: 6.59
YOY Growth: 16.04% or +2765 (17233 CVEs in 2024)
June 3, 2025 at 3:12 PM
Excited to share CVE-MCP, my new project for direct access to official MITRE/CVE Program data! Leverages MCP to bring CVE info into developer workflows.
Check it out: github.com/jgamblin/CVE...
#CyberSecurity #CVE #OpenSource #MCP #DevTools
GitHub - jgamblin/CVE-MCP: A CVE Data MCP using the CVE.ORG API
A CVE Data MCP using the CVE.ORG API. Contribute to jgamblin/CVE-MCP development by creating an account on GitHub.
github.com
May 16, 2025 at 11:16 PM
2025 CVE Stats Update (May 01, 2025)
Total Number of CVEs: 16,053
Average CVEs Per Day: 132.67
Average CVSS Score: 6.89
YOY Growth: 30.45% or +3,747 (12,306 CVEs in 2024)
May 1, 2025 at 2:28 PM
The LLM Security Leaderboard shows that most models are not ready for prime time. huggingface.co/spaces/stack...
LLM Security Leaderboard - a Hugging Face Space by stacklok
This application allows you to compare the performance of open-source Large Language Models across several benchmarks. You can filter results in real-time and see comprehensive model analysis.
huggingface.co
April 30, 2025 at 2:10 AM
Wrapped up a fantastic workshop today at #Vulncon25! Thanks to everyone who joined. You can find the code and materials here: github.com/jgamblin/Vul...
GitHub - jgamblin/VulnconWorkshop: Using Jupyter Notebooks To Explore Public CVE Data Workshop
Using Jupyter Notebooks To Explore Public CVE Data Workshop - jgamblin/VulnconWorkshop
github.com
April 7, 2025 at 11:20 PM