The European Vulnerability Database (EUVD) is a repository of cybersecurity vulnerability information. It was launched in May 2025 by the European Union (EU) Agency for Cybersecurity (ENISA), which is also responsible for maintaining the database.
The EUVD is similar to the U.S. National Vulnerability Database (NVD). It works alongside MITRE’s Common Vulnerabilities and Exposures (CVE) program, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog, and other cybersecurity data sources.
Read More about the European Vulnerability Database (EUVD)
Compared with NVD, EUVD is quite new, so some people are still learning about it. We provided some of the important information you need to know about EUVD.
Why Did ENISA Launch EUVD?
ENISA launched EUVD as a mandate of the Network and Information Systems 2 (NIS2) Directive and the EU Cyber Resilience Act (CRA). The primary goal is to help bolster Europe’s cybersecurity resilience and reduce its reliance on non-EU-based databases, promoting digital sovereignty.
Its launch came at a time of uncertainty surrounding the funding and stability of the U.S.-based CVE program. The program has been funded year after year by the U.S. Department of Homeland Security (DHS), but this funding expired on 16 April 2025. As a result, the CVE board decided to create a nonprofit organization called “The CVE Foundation.”
What Role Does EUVD Play in Cybersecurity?
The launch of EUVD aims to improve coordinated vulnerability disclosure and provide a central point for information, especially for organizations in the European region. It aggregates data from computer security incident response teams (CSIRTs), security vendors, existing vulnerability databases (e.g., the CVE program and the KEV Catalog), and many other sources.
Consolidating all these vulnerability information allows for more effective vulnerability management, enabling organizations to better manage their attack surfaces. Specifically, EUVD helps security teams:
- Identify risks: Pinpoint which assets in their attack surfaces are exposed to exploitable vulnerabilities.
- Prioritize remediation: Since EUVD focuses on the most dangerous vulnerabilities attackers are exploiting, security teams can see which issues are most urgent.
- Gain regional cybersecurity awareness: EUVD provides organizations with insights about the latest threats affecting the European digital environment.
What Are the Features of EUVD?
We can categorize the features of the EUVD into three—a variety of available vulnerability data, a machine-readable format, and dashboards. Learn more about each feature below.
Available Vulnerability Information
Since ENISA itself is a CVE numbering authority (CNA), it can register vulnerabilities and coordinate with MITRE about vulnerability disclosures. That said, EUVD incorporates a lot of information about vulnerabilities, including:
- The Common Vulnerability Scoring System (CVSS) Base score, which measures severity
- The Exploit Prediction Scoring System (EPSS) score, which estimates how likely an attacker will exploit the vulnerability in the next 30 days
- CISA KEV Catalog to provide data on exploited vulnerabilities
- Alternative IDs, if available, such as the CVE ID and Government Securities Division (GSD) ID
- A short description of the vulnerability
- Affected vendor, product, and version
- Publication date and last update
- Advisories
- References
Ready-to-Automate Format
EUVD supports machine-readable formats, such as the Common Security Advisory Framework (CSAF), which makes vulnerability data readily ingestible into existing security tools and workflows. This automation speeds up triage and remediation.
Dashboards
EUVD offers three main dashboard views to help users prioritize information:
- Critical vulnerabilities: Highlights severe security issues.
- Exploited vulnerabilities: Focuses on vulnerabilities currently under active attack.
- EU CSIRT-coordinated vulnerabilities: Shows vulnerabilities that are being managed by European CSIRTs.
How to Access EUVD
EUVD is publicly accessible and can be found at the official ENISA website. You can search vulnerabilities by ID or text string.
You can also view the complete list of vulnerabilities by clicking Full vulnerability list. This will take you to a more advanced search portal, where you can filter by CVSS score, EPSS score, product, vendor, assigner, and even publication date.
Is EUVD Supported by Cybersecurity Solutions?
While EUVD is relatively new, it is designed to be compatible with existing cybersecurity systems. It helps that the database is interoperable with the existing CVE ecosystem and can be accessed in machine-readable format. In fact, many attack surface management (ASM) platforms and vulnerability management solutions are already taking EUVD into account in their workflows and analyses.
—
It’s worth mentioning that EUVD is not a replacement for other databases, such as NVD. It serves as a complementary resource, with ENISA aiming to prevent duplicated efforts in vulnerability reporting. It continues to work with MITRE, CISA, and other maintainers of vulnerability databases worldwide.
Key Takeaways
- EUVD is Europe’s official vulnerability database, launched to enhance regional cybersecurity.
- It was created under the NIS2 Directive and is maintained by ENISA.
- Its key features include a unique ID system, cross-referencing with CVEs, support for machine-readable formats, and multiple dashboards to prioritize threats.
- EUVD helps improve vulnerability management and ASM, among other cybersecurity processes.
- EUVD is publicly accessible and is intended to be a complementary resource, not a replacement for NVD.
Sources
- https://euvd.enisa.europa.eu/
- https://www.infoq.com/news/2025/06/cve-european-vulnerability-euvd/
- https://www.helpnetsecurity.com/2025/05/14/enisa-european-vulnerability-database-euvd/
- https://www.computerweekly.com/news/366623995/Enisa-launches-European-vulnerability-database








