EUVD

European Union Vulnerability Database

Schwachstellendatenbank der Europäischen Union

The EUVD is the European Union's vulnerability database operated by European Union Agency for Cybersecurity (ENISA). It consolidates publicly available information on vulnerabilities from many sources — including the Common Vulnerabilities and Exposures (CVE) programme and the Known Exploited Vulnerabilities Catalog (KEV) catalogue — and assigns its own EUVD identifiers. It is conceived as a European, sovereign complement to the established sources, not as their replacement.

History & facts. The EUVD went into operation on 13 May 2025 — mandated by Network and Information Security Directive 2 (NIS2) and against the backdrop of the funding uncertainties around the United States of America (US) Common Vulnerabilities and Exposures (CVE) programme. It enriches CVE data, assigns parallel EUVD identifiers, uses the machine-readable Common Security Advisory Framework (CSAF) format and offers its own views, for instance on critical and on actively exploited vulnerabilities. European Union Agency for Cybersecurity (ENISA) has itself been a CVE Numbering Authority (CNA) since early 2024 and can register vulnerabilities coordinated by European Union (EU) CSIRTs.

Outlook & recommendation. The EUVD is a visible step towards European technological sovereignty — a concern that also fits NEOSEC's open-source and data-sovereignty stance (neosec.eu). In its young form it is not yet as complete and enriched as the established sources; its value initially lies in the additional, independent perspective. For robust vulnerability management, the multi-source approach is advisable rather than betting on a single database.

EUVD — European Union Vulnerability Database