#nvd

Mathieu GittonGitton
2025-05-15

EUROSCOPE — FAUT-IL UNE BASE EUROPÉENNE DES FAILLES ?

Face à l’essoufflement du NVD américain, l’Europe lance l’EUVD. L’inventaire des vulnérabilités devient enjeu stratégique. Le silence d’une base peut faire grandir le risque.

whatsapp.com/channel/0029VaE5W

The global vulnerability intelligence platform project is moving forward. Many organisations are joining the efforts.
Our first open community meeting is Tuesday May 20 at 16:00 Central european time. Ping me for a zoom invite or join the #cve-wg slack channel in OWASP slack.

#CVE #NVD #ALLVD #OWASP

2025-05-14

The global vulnerability intelligence project is making progress. We’re inviting to our first open meeting Tuesday May 20 at 16:00 CET. DM me to get a zoom invite or join the #CVE-wg slack channel in OWASP slack. #CVE #NVD #ALLVD

Benjamin Carr, Ph.D. 👨🏻‍💻🧬BenjaminHCCarr@hachyderm.io
2025-05-13

As #US #vulnerability-tracking falters, #EU enters with its own #security bug database
The European Vulnerability Database (#EUVD) is now fully operational, offering a streamlined platform to monitor critical and actively exploited security flaws amid the US struggles with budget cuts, delayed disclosures, and confusion around the future of its own tracking systems. The EUVD is similar to the US government's National Vulnerability Database (#NVD).
theregister.com/2025/05/13/eu_ #CISA

VulDB :verified:vuldb@infosec.exchange
2025-05-06

You have discovered a new vulnerability? Submit it here and we will assign a CVE in no time. vuldb.com/?id.add #vuldb #cna #cve #mitre #nvd

For a while, I've been collecting thoughts on a global vulnerability management platform, funded by many sources and governments. This Monday, we had a webinar in Eclipse ORCWG and it's now available on YouTube. If you want to join the work, there's a mailing list on google groups "cve@owasp.org" as well as a work group in OpenSSF - Vulnerability disclosures wg.

youtu.be/zSsGLJTgWvU?si=ph69Ko

#CVE #NVD #CWD #SBOM

Changes to the CVE program signal a critical moment for AppSec strategies. It's time to modernize your approach to risk management. jpmellojr.blogspot.com/2025/04 #CVE #NVD #AppSec #BinaryAnalysis #RiskManagement #SoftwareSecurity

Matthias Schulzepercepticon@ioc.exchange
2025-04-16

Quick writeup on the alleged cut of funding for the #CVE and #NVD. As with everything Trump destroys, tomorrow the situation might be different. But this is my current take on the story:

open.substack.com/pub/internat

2025-04-16

Die Cybersecurity and Infrastructure Security Agency (CISA) arbeitet dringend daran, die Auswirkungen zu mildern und CVE zu erhalten, ist jedoch selbst von erheblichen Kürzungen und Chaos dank Elon Musks DOGE betroffen.

Zum Artikel: heise.de/-10353326?wt_mc=sm.re

#CVE #ITsicherheit #MITRE #NVD #CISA

Im Bild steht: "US-Kürzungen
CVE-Datenbank vor dem unmittelbaren Aus" dadrunter steht: "Die Mutter aller Schwachstellendatenbanken, 
die Common Vulnerabilities and Exposures (CVEs) der MITRE Corporation, könnte in den nächsten Stunden offline gehen. Denn die US-Regierung verlängert die Finanzierung nicht."
Manuel 'HonkHase' AtugHonkHase@chaos.social
2025-04-16

US-Kürzungen: #CVE-Liste könnte sofort stoppen

"Die CVE-Liste ist zentral für koordinierte Maßnahmen gegen gefährliche Bugs. Die US-Regierung entzieht die Finanzierung. Per sofort.

Offen bleibt, wie es konkret weitergeht. Eine Liste der bisher zugeteilten CVE-Nummern steht bis auf Weiteres bei Github online...Von Dritten gemeldete Sicherheitslücken wird MITRE ab Donnerstag aber wohl nicht mehr in die Liste aufnehmen."
#MITRE #NVD
heise.de/news/US-Kuerzungen-CV

2025-04-16

NVD's vulnerability enrichment crisis continues with no end in sight. @anchore @joshbressers explains how we're filling the gap with our own public database, helping security teams detect vulnerabilities despite NVD's backlog.

🔗 anchore.com/blog/nvd-crisis-on

#NVD

VulDB :verified:vuldb@infosec.exchange
2025-04-06

We are a CNA. Submit your vulnerabilities and we will assign a CVE in no time. vuldb.com/?id.add #vuldb #cna #cve #mitre #nvd

Rihards Olupsrichlv
2025-04-02

So that's it, USA is giving up on all fronts?

Man, they really are just gonna kill off MIST aren't they? Sheesh, what a kick in the nuts right now, with everything else going on

nist.gov/itl/nvd

#nvd #doge

2025-03-14

@jean_dupont to answer the original question:

#zsh
#lazygit
#bat
#zellij
#starship

for #nix :
#nh, #nix-output-monitor, #nvd

#hashtagGalore

VulDB :verified:vuldb@infosec.exchange
2025-03-05

You want to publish a new vulnerability? Just submit and we will handle your CVE assignment in no time. vuldb.com/?id.add #vuldb #cna #cve #mitre #nvd

2025-03-05

It's getting more and more urgent to build a global system for managing vulnerabilities in software. With new regulation, more vulnerabilities will have to be published and the pressure on the system will be much higher than today. We need to share the cost. #CyberSecurity #CVE #NVD

2025-02-20

So here's some first answer. #NVD is still out there, but the trouble with #NIST has already begun.
cyberplace.social/@GossiTheDog

VulDB :verified:vuldb@infosec.exchange
2025-02-06

You want to publish a new vulnerability? Just submit and we will handle your CVE assignment in no time. vuldb.com/?id.add #vuldb #cna #cve #mitre #nvd

2025-02-06

#wired The NVD publishes a comprehensive JSON Schema for their API (e.g. csrc.nist.gov/schema/nvd/api/2)

#tired The NVD JSON API returns CVE records that don't comply with it (e.g. services.nvd.nist.gov/rest/jso)

github.com/google/osv.dev/pull

🤦‍♂️

#nvd #cve #vulnerabilitymanagement #facepalm

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst