Tools

CVE data is public but it is not usable. The raw feeds are enormous, unevenly populated, and hard to reason about until you build something to look at them with.

So I built three things. They run under RogoLabs, they update themselves, and they are free.

CVE.ICU

The whole public CVE record from 1999 to today, broken out by year, CNA, CPE, CWE, CVSS, EPSS and KEV, plus a publication growth calendar.

This is for the shape of the record, not for looking up one vulnerability.

CNA Scorecard

Scores how completely each active CVE Numbering Authority fills in the records it publishes, across five weighted categories, on a rolling six month window.

The ranking is not the interesting part. The spread between categories is: across 300+ authorities the foundational fields are close to universal, while software identification and patch references are missing from most records. Those two gaps are the reason a CVE can be perfectly valid and still tell you nothing about whether you are affected.

CVE Forecast

Predicts CVE publication volume with a panel of machine learning and statistical time series models, updated daily, with every model scored against what actually happened.

Useful if you plan capacity around vulnerability volume, or if you want to check whether “CVE growth is accelerating” is true this quarter.


The annual CVE analyses come from the same data these three run on.