Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

EU Cybersecurity Agency ENISA Launches European Vulnerability Database

Experts say the European Vulnerability Database, or EUVD, should be a good resource, but only if ENISA manages to maintain it properly.

ENISA launches EUVD

The EU cybersecurity agency ENISA on Tuesday announced the official launch of the European Vulnerability Database, or EUVD. Industry professionals believe the EUVD can be a useful resource, but the agency needs to ensure it stays relevant.

The EUVD is mandated by the NIS2 Directive, the EU baseline framework for cybersecurity risk management and incident reporting. The database aims to provide “aggregated, reliable, and actionable information”, including exploitation status and mitigation measures, on vulnerabilities affecting IT, OT and IoT products.

The database is accessible for free to anyone. It includes information sourced from vendors, incident response teams, and other vulnerability databases, such as CISA’s Known Exploited Vulnerabilities (KEV) catalog and MITRE’s CVE Program. It’s also worth noting that ENISA has been a CVE Numbering Authority (CNA) since 2024 and it can also assign CVE identifiers to vulnerabilities. 

SecurityWeek has reached out to several experts to get their thoughts on the new EUVD, particularly in light of the recent issues plaguing the CVE Program and the National Vulnerability Database (NVD).  

“There’s a long history of vulnerability databases, so it’s not uncommon to see new vulnerability and exploit database sources emerge. In the case of ENISA, it makes sense that the EU would want a regional database—even if it’s largely redundant with the CVE Program—because it allows for greater control and customization tailored to regional stakeholders,” said Patrick Garrity, security researcher at vulnerability management firm VulnCheck.

“The ENISA initiative was not intended to replace the CVE Program; in fact, it was developed in close coordination with it. That said, its launch does come at a time when concerns about NIST NVD and the CVE Program’s funding crisis have been widely voiced,” Garrity added.

VulnCheck maintains its own KEV catalog for customers, and it currently stores data on nearly three times more vulnerabilities compared to CISA’s KEV and the EUVD, based on an analysis by SecurityWeek.  

Nathaniel Jones, VP of Security & AI Strategy and Field CISO at Darktrace, described the EU Vulnerability Database as “a win for the global cybersecurity community”. 

Advertisement. Scroll to continue reading.

“While there will be operational kinks to work out, the basics of maintaining information from MITRE’s CVE Program and CISA’s KEV are encouraging,” Jones said. “It’s sound risk management to avoid single points of failure in global vulnerability reporting and can help reduce lags in reporting time.”

On the other hand, Julian Brownlow Davies, VP of Advanced Services at bug bounty platform Bugcrowd, pointed out that there are certain challenges that ENISA needs to overcome in order for the database to stay operationally relevant. 

“Unlike KEV or private sources like VulnDB, which offer enriched context and exploit prioritization, the EUVD will need tight integration and real-time rigor to be more than just a parallel record. There is a risk of fragmentation here. Security teams don’t need more databases; they need better signal,” Davies told SecurityWeek.

Related: CVE and NVD – A Weak and Fractured Source of Vulnerability Truth

Related: White House Proposal Slashes Half-Billion From CISA Budget

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how the LOtL threat landscape has evolved, why traditional endpoint hardening methods fall short, and how adaptive, user-aware approaches can reduce risk.

Watch Now

Join the summit to explore critical threats to public cloud infrastructure, APIs, and identity systems through discussions, case studies, and insights into emerging technologies like AI and LLMs.

Register

People on the Move

Cloud security startup Upwind has appointed Rinki Sethi as Chief Security Officer.

SAP security firm SecurityBridge announced the appointment of Roman Schubiger as the company’s new CRO.

Cybersecurity training and simulations provider SimSpace has appointed Peter Lee as Chief Executive Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.