2025-05-13
European Union Vulnerability Database Launches
The European Union Agency for Cybersecurity's (ENISA's) European Vulnerability Database (EUVD) launched officially on Tuesday, May 13, after its announcement in June, 2024 as part of the EU's Network and Information Systems Directive 2 (NIS2). The dashboard provides three lists: critical vulnerabilities, exploited vulnerabilities, and vulnerabilities coordinated by the EU's CSIRTs network. The EUVD is an analog to the US Department of Homeland Security's Common Vulnerabilities and Exposures (CVE) program, and is itself a CVE Numbering Authority (CNA). Just under a month prior to the launch of the EUVD, the CVE program received an 11-month extension to its funding from the US Cybersecurity and Infrastructure Security Agency (CISA), when supporting research non-profit MITRE announced that funding would expire within 24 hours, leaving the fate of the program uncertain. ENISA has stated that it is "in contact with MITRE to understand the impact and next steps following the announcement on the funding to the Common Vulnerabilities and Exposures Program."
Editor's Note
We may have a fragmentation of the vulnerability enumeration space coming up. At this point, CVE still 'rules' and EUVD does map to CVE. However, additional possible competitors have already announced their intent to introduce similar systems, further diluting the value of CVEs. Until now, the only CVE competition came from China's vulnerability registry, which was largely ignored outside China. Let's hope that the competition will lead to an improved vulnerability enumeration solution.

Johannes Ullrich
Its unfortunate that the US seems to have abandoned its leadership position in cybersecurity. Thank you, ENISA, and the EU in general, for offering an alternative vulnerability database for the cybersecurity community.

Curtis Dukes
Read more in
EUVD: European Union Vulnerability Database
ENISA: Consult the European Vulnerability Database to enhance your digital security!
DarkReading: What Does EU's Bug Database Mean for Vulnerability Tracking?
The Record: EU launches vulnerability database to tackle cybersecurity threats The Register: As US vuln-tracking falters, EU enters with its own security bug database