First one is finding, reporting and getting vulnerabilities.
Most people don't perform security audits. Most vendors take forever to reply back to security reports. Infuriatingly, many vendors will roll security fixes into the next major release instead of backporting patches and minor versions.
The second one is about finding out about disclosed and patched vulnerabilities.
Outside of larger institutions where you have someone whose job it is to worry over configuration management and subscribe to every mailing list, the ecosystem for disseminating this information is broken. That's why we've started the https://github.com/rubysec/ruby-advisory-db, at least for the Ruby ecosystem.
That doesn't even mean an exploit btw. Some of those gems might be in the Gemfile but never actually used (deprecated but not removed, hence not updated), or the vulnerable component might never be used. The gem might only be used on internal data, not user-manipulateable data.
Furthermore, you can't extrapolate 13% of the examined gemfiles containing such an issue to all gemfiles, which you did.
The fact that it's reported certainly doesn't mean it will be fixed in all downstreams (what this article refers to). Do you read every CVE? Every single one? Didn't think so. Most gems are relatively unpopular and any issues in them won't be widely publicized. Sure, Rails issues are shouted far and wide, but most of the rest are easy to miss.
Hell, some CVEs don't even get fixed in the gem itself, let alone all the consumers of that gem; the gem just remains vulnerable because there's no maintainer or the maintainer insists that it's "not an issue".
Please don't make such misinformed comments without even reading the article with sufficient attention to detail to get the statistic right.
The data used in the article contains a list of the versions being used in production by real app, not the latest versions released by the gem developers.
If it's a bug in a YAML parser but you're not loading YAML from untrusted sources, then it would be a false positive.
The should be able to calculate what percentage of these would still be vulnerable if fully updated - now that would be an interesting stat!