The European Union Agency for Cybersecurity (ENISA) launched the European Union Vulnerability Database (EUVD) in April 2025 as part of the operationalization of cybersecurity requirements established under the NIS2 Directive (Directive (EU) 2022/2555). The EUVD is designed to serve as the EU’s primary repository for aggregated vulnerability intelligence, vendor advisories, national CSIRT alerts, CVE and CVSS scores, EPSS exploitation probability metrics, and exploitation status derived from the CISA Known Exploited Vulnerabilities (KEV) catalogue.
The EUVD’s importance extends beyond its function as a technical database. It is intended to reduce dependency on non-EU vulnerability infrastructures and to support EU-wide regulatory and operational needs, including those emerging under the Cyber Resilience Act (CRA) for products with digital elements.
From a governance perspective, the EUVD is a NIS2-mandated capability intended to support coordinated vulnerability disclosure and strengthen information sharing across Member States, including via national CSIRTs. It is also related to the CRA: while the CRA foresees a Single Reporting Platform (SRP) for regulatory reporting, the EUVD provides broader vulnerability intelligence that can inform compliance, supervision, and risk management. As a Common Vulnerability and Exposure (CVE) Numbering Authority (CNA), ENISA is authorised to assign CVE Identifiers (CVE IDs) and to publish CVE Records for vulnerabilities discovered by or reported to EU CSIRTs, in line with their dedicated coordinator roles since January 2024. As Root CNA, ENISA is now expanding its role within the CVE program leveraging the EUVD.
The EUVD responds to two operational targets: resilience concerns created by reliance on US-based vulnerability infrastructure, and the shift toward automation in vulnerability management and software supply-chain assurance. In fact, both Cyber Threat Intelligence and SBOM-based dependency tracking and controls require stable, machine-readable APIs with sufficient metadata to match affected products and versions at scale.
The TELEMETRY’s Policy brief provides a short technical assessment of the EUVD’s public REST API, accessible at https://euvd.enisa.europa.eu/apidoc, with the dual aim of evaluating its current capabilities for programmatic integration and identifying developer-oriented improvements that could enhance its utility for security practitioners, tool developers, and regulated entities operating under EU cybersecurity law.
The availability of a robust, high-performance Application Programming Interface (API) is vital for the integration of the EUVD into modern cybersecurity and Cyber Threat Intelligence (CTI) ecosystems. To move beyond manual human-based processes, the database must provide seamless, machine-readable access to vulnerability data, enabling automation to ingest and correlate threat feeds in real-time, and facilitating the effective integration of this valuable asset into more advanced approaches, such as those based on agentic AI. A sound API architecture is a technical need for reducing the window of exposure between vulnerability discovery and remediation, ensuring that EU defence mechanisms can scale to meet the velocity of contemporary cyber threats.
Read the full policy brief here.
