The vulnerability intelligence system is broken.
Here's how to fix it.
Open-source tools and research for security teams who need signal, not noise.
RogoLabs
RogoLabs builds open-source tools that make vulnerability intelligence actionable. The name comes from the Latin rogo — "I ask" — the root of "interrogate." The mission is to relentlessly question vulnerability data to reveal what actually requires attention.
The problem isn't a shortage of CVE data. It's that most security teams are drowning in it — CVSS scores without context, feeds without signal, patch lists without priority. Every tool in the RogoLabs toolkit is designed to cut through that noise: visualize what's happening, predict what's coming, and prioritize what matters.
All tools are free and open-source. No vendor lock-in, no hidden costs — because better security tooling should be available to everyone, not just organizations that can afford enterprise contracts.
— Jerry Gamblin
The RogoLabs Toolkit
One mission — make vulnerability intelligence actionable.
The CVE List
What is in it, what is missing, and what is coming.
-
CVE.ICU
DashboardReal-time CVE visualization dashboard updated every 4 hours from the NVD, with interactive charts revealing vulnerability patterns and trends.
-
RBP Tracker
MonitoringLists Reserved but Public CVE IDs: cited in a public advisory, still Reserved, no CVE Record yet. Reads 17 advisory feeds every six hours and publishes JSON and CSV.
-
CVE Updates
AnalyticsAutomated analysis of 300K+ CVE records revealing update frequencies, historical trends, and the most actively maintained vulnerabilities. Updated every 4 hours.
-
CVE Floodline
TrendsVulnerability weather for the AI era. Tracks daily CVE disclosure rates and uses EPSS and CISA KEV to separate raw volume spikes from genuinely dangerous vulnerabilities.
-
CVEforecast
PredictiveML-powered CVE volume forecasting using an ensemble of statistical, machine learning, and deep learning models to predict what's coming next.
CNAs and the Program
Who publishes CVE records, how well, and who enriches them.
-
CNA Scorecard
QualityData-driven quality ratings for all 512 CVE Numbering Authorities, based on completeness, accuracy, and timeliness of their CVE records.
-
CNAPulse
MonitoringMonitors all 512 CNAs, tracking publishing activity and comparing 30-day output against 12-month baselines. Updated every 3 hours.
-
SADP Tracker
MonitoringTracks Supplier ADP enrichment activity in CVE records with participation stats, data coverage metrics, and latest enrichment updates from the CVE Supplier ADP Pilot.
For Defenders
What to patch first and what to watch in your own stack.
-
PatchThis.app
PrioritizationRisk-based patch prioritization that ranks patches by actual exploitability and exposure, not just CVSS scores.
-
VulnRadar
GitHub ActionGitHub-native CVE monitoring for your stack. Matches CVEs against a watchlist, enriches with KEV, EPSS, NVD, and PatchThis, and posts issues. Runs on GitHub Actions.
Talks
Conference presentations on vulnerability intelligence, CVE ecosystem health, and data-driven security.
An open question-and-answer panel on how the CVE Program actually works — assignment, CNA operations, disclosure, and the pressures reshaping the ecosystem — taking questions directly from the room. Panel with Tod Beardsley, Lindsey Cerkovnik, Madison Ficorelli, and Katie Noble.
Rising CVE counts are a vocabulary problem, and AI-enabled discovery is about to make it worse. Drawing on overdiagnosis research in medicine, the talk shows that finding more is not the same as there being more: CVEs grew 7.5x from 2016 to 2025 while assigning CNAs grew nearly 10x, so what expanded was coverage, not risk. KEV and EPSS both put the actionable slice at a small fraction of published records. Argues for retiring "vulnpocalypse" and grading the ecosystem by the gap between exploitation and remediation rather than by the size of its catalog.
Introduces the Data Quality Assessment Framework (DQAF — pronounced "decaf"), a structured approach to measuring CVE data quality across completeness, accuracy, consistency, and machine-usability. The framework separates record design quality from record instance quality, enabling CNAs, NVD, and downstream consumers to benchmark their vulnerability data output. w/ Jay Jacobs (Empirical Security).
A builder session showing how to create a self-sustaining vulnerability radar using open-source tooling and the architecture patterns behind the RogoLabs toolkit.
Examining the critical need for CVE ecosystem decentralization in response to NVD challenges, exploring global alternatives and pathways toward a more resilient, distributed vulnerability intelligence infrastructure.
Analysis of strain in global vulnerability disclosure — CVE funding challenges and NVD backlog — and strategies for resilient, diversified vulnerability intelligence using emerging alternative sources.
Introduces CVEforecast.org and an ensemble approach — statistical, ML, deep learning, and CNA-specific forecasting — to shift vulnerability management from reactive response to predictive planning.
State-of-the-landscape analysis covering NVD backlog dynamics, CVE program funding stress, assignment consistency, and the emergence of alternative global vulnerability data sources and their operational impact.
Exploration of transparency gaps in CVE processes and their impact on vulnerability ecosystem trust and efficiency.
Empirical analysis of CNA performance gaps and methods to raise vulnerability reporting quality across the ecosystem.
Case studies on operationalizing EPSS to reduce patch workload while preserving risk coverage.