NVD collapsed, the Linux kernel is generating a huge number of CVE IDs, CISA is maybe enriching the CVE data, and the growth rate of CVE is higher than its ever been. There are a lot of people working on this data, just not a lot of people working together on this data. If we go back to the complaint that the Linux kernel has too many low quality vulnerabilities that are just bugs, we should also keep in mind that there hundreds of thousands, maybe even millions of untriaged vulnerabilities in open source projects (remember those GitHub searches).