Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
72 changes: 68 additions & 4 deletions src/assets/data/CNAsList.json
Original file line number Diff line number Diff line change
Expand Up @@ -7318,19 +7318,27 @@
"shortName": "schneider",
"cnaID": "CNA-2017-0009",
"organizationName": "Schneider Electric",
"scope": "All Schneider Electric products, including Proface, APC, and ProLeiT.",
"scope": "Products supported by Schneider Electric and its affiliates, including products branded Schneider Electric or any other brands owned or controlled by Schneider Electric (such as but not limited to APC, Eliwell, Proface, ProLeit, Lauritz Knudsen Electrical & Automation, etc.), excluding Aveva and RIB products.",
"contact": [
{
"email": [
{
"label": "Email",
"label": "Email – Schneider Electric & Affiliates",
"emailAddr": "cpcert@se.com"
},
{
"label": "Email – Lauritz Knudsen Electrical & Automation",
"emailAddr": "LK-EA-CERT@LK-EA.com"
}
],
"contact": [
{
"label": "Schneider Electric security contact page",
"url": "https://www.se.com/ww/en/work/support/cybersecurity/report-a-vulnerability.jsp"
"label": "Report Vulnerability – Schneider Electric",
"url": "https://www.se.com/ww/en/work/support/cybersecurity/report-a-vulnerability/"
},
{
"label": "Report Vulnerability – Lauritz Knudsen Electrical & Automation",
"url": "https://www.lk-ea.com/services/cybersecurity/support-portal"
}
],
"form": []
Expand Down Expand Up @@ -31469,5 +31477,61 @@
]
},
"country": "USA"
},
{
"shortName": "RES",
"cnaID": "CNA-2026-0067",
"organizationName": "RedEye Security",
"scope": "Vulnerabilities in RedEye Security’s own products: software that RedEye develops and distributes for customers to deploy and operate in their own environments. Caver, RedEye’s self-hosted, Splunk-compatible SIEM and OCSF data-lake platform, including its server components, collectors and agents, command-line tooling, and officially distributed installers and container images. Out of scope: vulnerabilities in third-party components and dependencies that RedEye redistributes but does not maintain; vulnerabilities in RedEye-operated hosted services and web properties that RedEye remediates server-side with no customer action required; and the content of RedEye’s threat-intelligence and CVE detection feeds.",
"contact": [
{
"email": [
{
"label": "Email",
"emailAddr": "security@redeyesecurity.com"
}
],
"contact": [],
"form": []
}
],
"disclosurePolicy": [
{
"label": "Policy",
"language": "",
"url": "https://redeyesecurity.com/security"
}
],
"securityAdvisories": {
"alerts": [],
"advisories": [
{
"label": "Advisories",
"url": "https://redeyesecurity.com/security/advisories"
}
]
},
"resources": [],
"CNA": {
"isRoot": false,
"root": {
"shortName": "icscert",
"organizationName": "Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS)"
},
"type": [
"Vendor"
],
"TLR": {
"shortName": "CISA",
"organizationName": "Cybersecurity and Infrastructure Security Agency (CISA)"
},
"roles": [
{
"helpText": "",
"role": "CNA"
}
]
},
"country": "USA"
}
]
4 changes: 4 additions & 0 deletions src/assets/data/boardMeetings.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
{
"2026": [
{
"name": "Augst 19, 2026 - teleconference",
"path": "msg00352.html"
},
{
"name": "Augst 5, 2026 - teleconference",
"path": "msg00349.html"
Expand Down
2 changes: 1 addition & 1 deletion src/assets/data/metrics.json
Original file line number Diff line number Diff line change
Expand Up @@ -1247,7 +1247,7 @@
},
{
"month": "September",
"value": "5"
"value": "6"
},
{
"month": "October",
Expand Down
24 changes: 22 additions & 2 deletions src/assets/data/navigation.json
Original file line number Diff line number Diff line change
Expand Up @@ -241,8 +241,28 @@
}
}
},
"CVE Numbering Authorities": {
"Council of Roots": {
"id": "3.4",
"label": "Council of Roots (CoR)",
"path": "CouncilOfRoots",
"primaryNavPath": "/ProgramOrganization/CouncilOfRoots",
"items": {
"Responsibilities": {
"anchorId": "CoR-responsibilities",
"label": "Responsibilities"
},
"Roots": {
"anchorId": "CoR-roots",
"label": "Organizations Currently Participating as Roots"
},
"Partner": {
"anchorId": "CoR-partner",
"label": "How to Become a Root Partner"
}
}
},
"CVE Numbering Authorities": {
"id": "3.5",
"label": "CVE Numbering Authorities (CNAs)",
"path": "CNAs",
"primaryNavPath": "/ProgramOrganization/CNAs",
Expand All @@ -254,7 +274,7 @@
}
},
"Authorized Data Publishers": {
"id": "3.5",
"id": "3.6",
"label": "Authorized Data Publishers (ADPs)",
"path": "ADPs",
"items": {
Expand Down
48 changes: 46 additions & 2 deletions src/assets/data/news.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,41 @@
{
"currentNews": [
{
"newsType": "news",
"title": "RedEye Security Added as CVE Numbering Authority (CNA)",
"urlKeywords": "RedEye Security Added as CNA",
"date": "2026-09-15",
"description": [
{
"contentnewsType": "paragraph",
"content": "<a href='/PartnerInformation/ListofPartners/partner/RES'>RedEye Security</a> is now a <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCNA'>CVE Numbering Authority (CNA)</a> for vulnerabilities in RedEye Security’s own products: software that RedEye develops and distributes for customers to deploy and operate in their own environments. Caver, RedEye’s self-hosted, Splunk-compatible SIEM and OCSF data-lake platform, including its server components, collectors and agents, command-line tooling, and officially distributed installers and container images. Out of scope: vulnerabilities in third-party components and dependencies that RedEye redistributes but does not maintain; vulnerabilities in RedEye-operated hosted services and web properties that RedEye remediates server-side with no customer action required; and the content of RedEye’s threat-intelligence and CVE detection feeds."
},
{
"contentnewsType": "paragraph",
"content": "To date, <a href='/PartnerInformation/ListofPartners'>549 CNAs</a> (546 CNAs and 3 CNA-LRs) from <a href='/ProgramOrganization/CNAs'>43 countries</a> and 1 no country affiliation have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCVEID'>CVE Identifiers (CVE IDs)</a> and publish <a href='/ResourcesSupport/Glossary?activeTerm=glossaryRecord'>CVE Records</a> for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities. RedEye Security is the 287th CNA from USA."
},
{
"contentnewsType": "paragraph",
"content": "RedEye Security’s Root is the <a href='/PartnerInformation/ListofPartners/partner/icscert'>CISA ICS Root</a>."
}
]
},
{
"newsType": "news",
"title": "Minutes from CVE Board Teleconference Meeting on August 19 Now Available",
"urlKeywords": "CVE Board Minutes from August 19",
"date": "2026-09-15",
"description": [
{
"contentnewsType": "paragraph",
"content": "The <a href='/ProgramOrganization/Board'>CVE Board</a> held a teleconference meeting on August 19, 2026. Read the <a href='https://www.mail-archive.com/cve-editorial-board-list@mitre.org/msg00352.html' target='_blank'>meeting minutes summary</a>."
},
{
"contentnewsType": "paragraph",
"content": "The CVE Board is the organization responsible for the strategic direction, governance, operational structure, policies, and rules of the CVE Program. The Board includes members from numerous cybersecurity-related organizations including commercial security tool vendors, academia, research institutions, government departments and agencies, and other prominent security experts, as well as end-users of vulnerability information."
}
]
},
{
"newsType": "news",
"title": "Honeywell Aerospace Added as CVE Numbering Authority (CNA)",
Expand Down Expand Up @@ -82,10 +118,19 @@
},
{
"displayOnHomepageOrder": 1,
"newsType": "news",
"newsType": "blog",
"title": "CNAs &mdash; Call for Topics for “CVE Program Fall Technical Workshop: Advancing CVE Record Quality” on October 29, 2026",
"urlKeywords": "Topics Register for CVE Technical Workshop 2026",
"date": "2026-09-09",
"author": {
"name": "CVE Program",
"organization": {
"name": "CVE Program",
"url": ""
},
"title": "",
"bio": ""
},
"description": [
{
"contentnewsType": "paragraph",
Expand Down Expand Up @@ -193,7 +238,6 @@
]
},
{
"displayOnHomepageOrder": 0,
"newsType": "news",
"title": "Minutes from CVE Board Teleconference Meeting on August 5 Now Available",
"urlKeywords": "CVE Board Minutes from August 5",
Expand Down
9 changes: 9 additions & 0 deletions src/router/index.js
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ import Board from '@/views/ProgramOrganization/Board.vue';
import BoardArchives from '@/views/ProgramOrganization/Archives.vue';
import WorkingGroups from '@/views/ProgramOrganization/WorkingGroups.vue';
import CNAs from '@/views/ProgramOrganization/CNAs.vue';
import CouncilOfRoots from '@/views/ProgramOrganization/CouncilOfRoots.vue';
import ADPs from '@/views/ProgramOrganization/ADPs.vue';
import Downloads from '@/views/Downloads.vue';
import ReportRequestForNonCNAs from '@/views/ReportRequest/ReportRequestForNonCNAs.vue';
Expand Down Expand Up @@ -176,6 +177,14 @@ const router = createRouter({
title: 'CNAs | CVE',
},
},
{
path: '/ProgramOrganization/CouncilOfRoots',
name: 'CouncilOfRoots',
component: CouncilOfRoots,
meta: {
title: 'Council of Roots | CVE',
},
},
{
path: '/ProgramOrganization/ADPs',
name: 'ADPs',
Expand Down
2 changes: 1 addition & 1 deletion src/views/ProgramOrganization/CNAs.vue
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
<template>
<div id="cve-secondary-page-main-container">
<div id="cve-secondary-page-main-container" class="container">
<div class="columns is-centered">
<div class="column is-8-desktop cve-main-column-content-width is-12-tablet">
<main id="cve-main-page-content" role="main">
Expand Down
Loading