The scores are mostly useless, I would not care if they disappeared, I do not look at them. I don't really understand why people get so upset about garbage scores though. If a high CVSS score creates a bunch of work for you then your vuln mag process is broken IMO. (Or alternatively, you are in the business of compliance rather than security. If you don't like working in compliance, CVSS scores aren't the root cause of your misery).
Having a central list of "here's a bunch of things with stable IDs that you might or might not care about" is very valuable.
So, most businesses. They all need their ISO/NIST/HIPAA/etc certs.
If you're working in compliance either
A) you're stuck in your compliance job, that sucks, CVSS scores aren't the reason why though.
B) you enjoy compliance.
C) you should change jobs.
a) If you are having to do busywork for compliance reasons, you are either disempowered to push back on bullshit work (case A above, unfortunate, but your job was gonna suck anyway), or it's not really a second order effect, you work in compliance in a meaningful way.
b) Compliance bullshit seems to expand into the space available to it. Nobody thinks CVSS scores are meaningful, the fact that they feed into compliance processes is not the CVSS scores' fault it's the compliance machine just globbing onto random bullshit as its expansion continues. If you took away CVSS scores it feels like it would just glob onto something else instead.
Anyway, in the end I think we aren't disagreeing about that much. I think they're silly, if someone wanted to get rid of them I wouldn't try to defend them at all. I just wouldn'e be the person to push for that.
I expect your field is probably teeming with AI proposals or offers on how to manage vulnerabilities, but that is doubtful the way, because again it is adding complexity, and no classifier is perfect, especially when scanners fail to understand scanned applications and their threat models or environment.
Stop selling external scanners, start simplifying code? This will never work, of course, because security vendors sell the promise of security to those willing to buy it, in the form of add-on products and capabilities.
Empower people to ignore scanner reports without so much red tape? That would never work either, because megacorp wants compliance and reduced liability.
Build secure systems as opposed to cataloging and scoring flaws? That would never work, because building secure systems is hard, nature tends to favor otherwise.
Charge people for adding complexity and credit them for removing complexity? Sadly, there is no way to do that, especially since products must ship and quality is hard to observe, since it is often invisible and only surfaces when things are broken.
Off the top of my head, would be nice to require proof of exploitation, by adding CTF-like capabilities to apps, such that only if the flag is captured do we consider the report real. This places more burden on scanners, in that it is no longer enough to report an outdated library. Requiring some proof of exploitability reduces noise and increases SNR, reducing false positives. Naturally, not all vulnerabilities have working exploits, and scanners can never fully simulate an adversary, so we may get more false negatives, but at least we would not have to waste so much time upgrading pointless modules and breaking applications to appease a false report. So the idea is "here is a dummy asset, show me how you leaked or compromised it". Adding the dummy asset should be cheap, but would force scanners to better simulate an attack.
At the very least, there ought to be a knob to decrease scanner sensitivity.
There are far too many bad actors for us to operate as an industry with no yardstick.
its all just surface-level box-checking. most companies required to get 'penetration tests' just get an overpriced Nessus scan sold as a pentest and that meets their reqs.
Maybe I have a dependency on Foo which has a critical vulnerability in a feature that I don't use. I suppress the warning and all is well. Then two weeks later someone on my team decides to use that feature, not knowing that there's a problem with it. Now we're fucked, and we'll never know because the vulnerability has been suppressed.
Trump must be receiving a lot of emails from companies wanting to fill the void, and I bet the Trumpiest of them all is going to be awarded a contract worth 10x the budget CVE had, and do a much worse job.
What a shame on this current gov. administration, if you can even call it that.
I think the question everyone in this thread should ask is: why is it the government's job to do this, especially given the prior widespread view that they're doing a bad job? Is the software industry so immiserated by poverty that it cannot organize its own distribution of security bulletins? Clearly not: GitHub already runs its own vuln tracking scheme that's better integrated with the tooling we use for open source software. The industry routinely sets up collaborations like standards bodies, information sharing groups and more. And there is as whole ecosystem of security companies to help you understand vulns in your stack.
So there seems nothing specific to CVEs that requires government involvement, but the existence of the tax funded scheme does discourage the creation of competitors that might function better.
But, to CVE or not to CVE ... that is not the question. US deficit spending is out of control. This sort of thing had to happen some day. It's what Europeans in the 2010s called "austerity" and it always makes some people scream but this graph:
https://fiscaldata.treasury.gov/americas-finance-guide/natio...
... is not sustainable. Up to 1984 overall US debt was stable. Since then its growth rate became dangerous. Debt/GDP ratio is now worse than just after WW2. The federal government is currently spending more on interest than on defense or Medicare:
https://www.crfb.org/blogs/interest-costs-have-nearly-triple...
The US is currently getting its first taste of what parts of Europe started going through in 2008, and unfortunately there's bad news: the cuts you're seeing now are mostly cosmetic. They're what can be done within the current framework of laws, sort of, with lots of bending of the rules and creative interpretations of them and maybe some oversteps. But it's just the start of what's needed. Large scale reform of the laws themselves will be required regardless of whoever wins the next elections.
This is like, exactly the sort of thing that the public sector should be doing. There's no profit incentive for this to happen in the private sector.
I don't disagree with your overall sentiment re: unsustainable debt. But the answer must be reform and taking hard looks at the military budget, not just randomly cutting programs that you disagree with politically.
More like the Clinton approach.
Note that many of these entries start with GHSA not CVE.
Agree that the military budget should face large cuts too, unless I guess a major war breaks out.
The public sector is exactly where you need things that are important to society but don't make money.
At any rate, even if they give it away for altruistic reasons, Microsoft is a sustainable going concern that brings in more than it spends. It can afford charity. The US government isn't and can't.
Because the private sector can't see past their profit motive to the national defense motive.
I suppose more people would be more amenable to these wholesale cuts if the current administration weren't blowing through even more money than before [0]:
> The new Treasury Department data shows a deficit of $1.307 trillion for October through March, the first six months of the fiscal year 2025. And spending is $139 billion more in the first three months of 2025 compared to the same period last year, with borrowing over that period $41 billion higher.
We're currently fighting no wars and yet Trump is proposing a record $1 trillion defense budget [1]:
> “We’re going to be approving a budget, and I’m proud to say, actually, the biggest one we’ve ever done for the military,” he said. “$1 trillion. Nobody has seen anything like it.
And that's before proposed cuts to tax revenue [2]:
> Extending the expiring 2017 Tax Cuts and Jobs Act (TCJA) would decrease federal tax revenue by $4.5 trillion from 2025 through 2034. Long-run GDP would be 1.1 percent higher, offsetting $710 billion, or 16 percent, of the revenue losses.
So this whole "we're just imposing much needed austerity" to justify penny-wise-pound-foolish policies is kind of laughable when the proposed increase to our peacetime defense budget alone wipes out Elon's most recent estimate of DOGE's total savings [3].
[0] https://apnews.com/article/trump-biden-budget-deficit-spendi...
[1] https://www.militarytimes.com/news/pentagon-congress/2025/04...
[2] https://taxfoundation.org/research/all/federal/trump-tax-cut...
[3] https://www.nytimes.com/2025/04/14/us/politics/elon-musk-dog...
Elon is a libertarian and has been allowed to go do some spending cuts around the edges. This gets support from Republican members of Congress partly because the USG turns out to be spending a lot of money on highly partisan Democrat projects, but mostly because it's someone else doing the cutting and not them. Even if they know they should be doing it themselves they don't want the crazies trashing their cars, so if some outsider does it for them that's a deal they'll happily take whilst it lasts.
All that said, it's inevitable that the administration would be blowing through more money than before even with DOGE. It's the nature of debt that it compounds. The level of cuts required to even keep the deficit stable would be huge because interest payments are accelerating, and the cuts DOGE are allowed to make are small (even when they go further than they might technically be allowed).
Right now there's just no mainstream support in US politics for serious austerity. There never is in any country, but sometimes the public can be convinced to agree to some amount if politicians do a good job of communicating the deficit problem. The UK in 2010 is an example of that, where the Conservative/Lib Dem alliance was able to convince the public to vote for spending cuts (albeit not as deep as were actually required... but it tided the UK over until the economy started growing again).
Absolutely. And if the headline was "DHS proposes improvements and streamlining to the CVE program" we'd all probably be cheering.
Leaping from "This is Flawed" to "Let's kill This" is a logical fallacy. A flawed security registry is clearly better than no security registry.
In honesty to say "logical fallacy" is spoddy, I advise against for aesthetic reason.
CVE is simply identification of a flaw, not a scoring system.
It's the way it is because there isn't a good alternative. They cannot possibly know every environment that we operate in.
To this day we still have large corporations down playing their issues, and it was way worse 20 years ago.
Why do people do this, to down play all the destruction of the last few months? Seems to be some type of coping mechanism.
All this does is help Putin and other rich grifters.
It's because it's like if someone had forgotten to validate the user's role in an endpoint in a Django app, and someone said that they should have used Rails because it's easier to understand. In reality both are easy enough to understand to be able to do an authorization check, and the framework isn't the issue. So the person suggesting Rails is bikeshedding.
Likewise, if someone made another vulnerability database it would likely have the same issue, and this isn't really the place to solve it. If somehow this does trigger the realization to solve it, then it will be by luck.