absolutely losing my fucking mind at this video from the wikipedia page for the physics engine "phyz"

@Lyude on top of that, while an application having lots of CVEs could mean it is insecure, it also could mean literally a ton of people use this application so it's tested for security holes almost constantly and thus the existence of more CVEs is more representative of security issues being found and fixed in a timely manner

Just gonna put this out here: it may be very tempting to look at a bunch of CVE numbers and think to yourself "wow, this application has so many numbers! It must be insecure" but lemme point out some things I've learned from handling CVEs:
CVEs are valuable, but read them also because oh boy I've seen plenty of nonsense CVEs that were not actually reproducible, were filed about unrelated components, etc.

