I wish people cared less about this particular issue, though, because we'd do fine with a non-government-sponsored CVE.
I wish people cared less about this particular issue, though, because we'd do fine with a non-government-sponsored CVE.
> The European Union Agency for Cybersecurity (ENISA) first announced the project in June 2024 under a mandate from the EU's Network and Information Security 2 Directive, and quietly rolled out a limited-access beta version last month during a period of uncertainty surrounding the United States' Common Vulnerabilities and Exposures (CVE) program.
It's more of a "break fast and move things" approach.
There's no particular reason a vulnerability database needs to be government-sponsored, and some compelling reasons why it shouldn't be "owned" by one government or another (one being guaranteed continuity even during seasons of change).