kbrain

KBrain Concepts

What is the EU Vulnerability Database (EUVD)?

The EUVD is the European Union vulnerability database, run by ENISA. It assigns EUVD ids, cross-references CVEs, and aggregates vulnerability data. Here is what it is and how to query it via AI.

Add the CVE brain to your AI assistant

The EU Vulnerability Database (EUVD) is the European Union's vulnerability database, operated by ENISA, the EU Agency for Cybersecurity. It was launched in 2025 in the context of the NIS2 Directive. The EUVD aggregates vulnerability information relevant to the EU, assigns its own identifiers, and cross-references the CVE ids that most people already know.

EUVD ids and how they relate to CVEs

Each EUVD entry has an id in the form EUVD-YYYY-NNNNN. Crucially, an entry lists the CVE id it corresponds to among its aliases, so an EUVD id and a CVE id usually point to the same underlying vulnerability. That cross-reference is what lets tools move between the two.

  • CVE id: the global identifier, e.g. CVE-2021-44228.
  • EUVD id: the EU identifier, e.g. EUVD-2025-12345, cross-referencing the CVE.
  • The EUVD also carries a description, a base score, references, and exploitation information.

What the EUVD adds

For a lot of vulnerabilities, the core facts match what you find in NVD, because the EUVD aggregates from shared sources. Its value is the EU perspective and identifier: a single place that reflects how the EU tracks a vulnerability, which is useful for teams operating under EU frameworks or referencing EU advisories.

How to query the EUVD with AI

The KBrain CVE brain joins the EUVD cross-reference onto each CVE, so when you look up a CVE in Claude or ChatGPT you also see its EUVD id and ENISA status. You can also resolve an EUVD id straight to its CVE, so an advisory that only cites an EUVD id is still answerable.

You do not query a separate EUVD tool for the common case. A normal CVE lookup already includes the EUVD id and ENISA exploited flag when one exists.

Add the CVE brain to your AI assistant

Look up CVEs, CISA KEV exploited status, and EPSS scores from Claude, ChatGPT, or any MCP compatible assistant. Hosted and refreshed daily, with no self-hosting and no API keys to manage.

Frequently asked questions

Who runs the EUVD?

ENISA, the EU Agency for Cybersecurity, operates the EU Vulnerability Database. It was launched in 2025 in the context of the NIS2 Directive.

Is an EUVD id the same as a CVE id?

They are different identifiers, but an EUVD entry cross-references the CVE id it corresponds to, so they usually point to the same vulnerability. An EUVD id looks like EUVD-2025-12345; a CVE id looks like CVE-2021-44228.

Does the EUVD replace the CVE program or NVD?

No. It is the EU's own database that aggregates and cross-references existing sources, adding an EU identifier and perspective. It sits alongside the CVE program, NVD, and CISA KEV.

How do I look up an EUVD entry?

With the KBrain CVE brain connected to Claude or ChatGPT, look up the CVE and you will see its EUVD cross-reference, or provide an EUVD id and the brain resolves it to the CVE detail.