diff --git a/src/assets/data/CNAsList.json b/src/assets/data/CNAsList.json index 8a2febbdc..f5cf64ec8 100644 --- a/src/assets/data/CNAsList.json +++ b/src/assets/data/CNAsList.json @@ -3648,7 +3648,7 @@ "shortName": "hpe", "cnaID": "CNA-2016-0003", "organizationName": "Hewlett Packard Enterprise (HPE)", - "scope": "HPE issues only.", + "scope": "HPE and acquisitions issues only.", "contact": [ { "email": [ @@ -8120,7 +8120,7 @@ "shortName": "suse", "cnaID": "CNA-2014-0003", "organizationName": "SUSE", - "scope": "SUSE and Rancher issues only.", + "scope": "SUSE and Rancher specific security issues, and vulnerabilities discovered by SUSE that are not covered by the scope of another CNA.", "contact": [ { "email": [ @@ -8158,7 +8158,8 @@ }, "type": [ "Vendor", - "Open Source" + "Open Source", + "Researcher" ], "TLR": { "shortName": "mitre", @@ -8319,7 +8320,7 @@ "url": "https://www.synaptics.com/products/touchpad-family" }, { - "label": "Biomentrics Advisories", + "label": "Biometrics Advisories", "url": "https://www.synaptics.com/products/biometrics" }, { @@ -14284,7 +14285,7 @@ { "label": "Policy", "language": "", - "url": "https://onekey.com/resposible-disclosure-policy/" + "url": "https://www.onekey.com/responsible-disclosure-policy" } ], "securityAdvisories": { @@ -25527,8 +25528,8 @@ "CNA": { "isRoot": false, "root": { - "shortName": "n/a", - "organizationName": "n/a" + "shortName": "redhat", + "organizationName": "Red Hat, Inc." }, "roles": [ { diff --git a/src/assets/data/NotificationBanner.json b/src/assets/data/NotificationBanner.json index 5740c5655..7de424ba9 100644 --- a/src/assets/data/NotificationBanner.json +++ b/src/assets/data/NotificationBanner.json @@ -19,6 +19,32 @@ { "contentType": "paragraph", "content": "." + }, + { + "contentType": "paragraph", + "content": "

" + }, + { + "contentType": "paragraph", + "content": "NOTICE —" + }, + + { + "contentType": "paragraph", + "content": "Due to routine maintenance, the " + }, + { + "contentType": "internalLink", + "link": "/", + "linkText": "CVE List on the CVE.ORG website" + }, + { + "contentType": "paragraph", + "content": "will be unavailable on April 2, 2025 between 1:00 PM and 5:00 PM EDT. As a result, searching CVE IDs and CVE Records on the CVE.ORG website will be unavailable during this time. We apologize for the inconvenience and thank you for your understanding." + }, + { + "contentType": "paragraph", + "content": "

" } ] } \ No newline at end of file diff --git a/src/assets/data/events.json b/src/assets/data/events.json index e8d106329..fc073e7c2 100644 --- a/src/assets/data/events.json +++ b/src/assets/data/events.json @@ -34,7 +34,7 @@ "displayOnHomepageOrder": 1, "title": "CVE/FIRST VulnCon 2025", "location": "Raleigh, North Carolina, USA & Virtual", - "description": "VulnCon 2025 is co-sponsored by the CVE Program and FIRST and is open to the public.

SPECIAL MESSAGE FOR CVE NUMBERING AUTHORITIES (CNAs):
VulnCon 2025 takes the place of this year’s Spring CVE Global Summit.

Agenda:
Available here.

Registration:
Open. Details here.
Registration fees include four days of coffee breaks and buffet lunches, one networking reception hosted at the McKimmon Center, and applicable meeting materials. Note that discounted rates are not being offered for this event regardless of membership or speaking status.

An offsite social event is planned for Tuesday, April 8, from 19:00-21:00 in downtown Raleigh. Location to be announced in January. You may purchase a ticket during your main registration or access a separate purchase form link found in your registration email confirmation. Tickets are US $30.00 per person.

Program Overview:
* Day 1: Monday, April 7 — Plenary, Vendor Tables, Welcome Reception
* Day 2: Tuesday, April 8 — Plenary, Vendor Tables, Off-site Social Event
* Day 3: Wednesday, April 9 — Plenary, Breakouts, Vendor Tables
* Day 4: Thursday, April 10 — Plenary, Breakouts, Vendor Tables

Venue:
McKimmon Center,
North Carolina State University
,
1101 Gorman St.,
Raleigh, North Carolina 27606
USA

Call for Papers:
Closed on January 31, 2025. Details here.

Purpose:
The purpose of VulnCon is to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken back to individual programs for action to benefit the vulnerability management ecosystem.

A key goal of the conference is to understand what important stakeholders and programs are doing within the vulnerability management ecosystem and best determine how to benefit the ecosystem broadly.", + "description": "VulnCon 2025 is co-sponsored by the CVE Program and FIRST and is open to the public.

SPECIAL MESSAGE FOR CVE NUMBERING AUTHORITIES (CNAs):
VulnCon 2025 takes the place of this year’s Spring CVE Global Summit.

Agenda:
Available here.

Registration:
Virtual registration available until April 4, 2025. Details here.
Registration fees include four days of coffee breaks and buffet lunches, one networking reception hosted at the McKimmon Center, and applicable meeting materials. Note that discounted rates are not being offered for this event regardless of membership or speaking status.

An offsite social event is planned for Tuesday, April 8, from 19:00-21:00 in downtown Raleigh. Location to be announced in January. You may purchase a ticket during your main registration or access a separate purchase form link found in your registration email confirmation. Tickets are US $30.00 per person.

Program Overview:
* Day 1: Monday, April 7 — Plenary, Vendor Tables, Welcome Reception
* Day 2: Tuesday, April 8 — Plenary, Vendor Tables, Off-site Social Event
* Day 3: Wednesday, April 9 — Plenary, Breakouts, Vendor Tables
* Day 4: Thursday, April 10 — Plenary, Breakouts, Vendor Tables

Venue:
McKimmon Center,
North Carolina State University
,
1101 Gorman St.,
Raleigh, North Carolina 27606
USA

Call for Papers:
Closed on January 31, 2025. Details here.

Purpose:
The purpose of VulnCon is to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken back to individual programs for action to benefit the vulnerability management ecosystem.

A key goal of the conference is to understand what important stakeholders and programs are doing within the vulnerability management ecosystem and best determine how to benefit the ecosystem broadly.", "permission": "public", "url": "https://www.first.org/conference/vulncon2025/", "date": { diff --git a/src/assets/data/metrics.json b/src/assets/data/metrics.json index 26ac95f79..ce3469142 100644 --- a/src/assets/data/metrics.json +++ b/src/assets/data/metrics.json @@ -1137,7 +1137,7 @@ }, { "month": "March", - "value": "3" + "value": "4" }, { "month": "April", diff --git a/src/assets/data/news.json b/src/assets/data/news.json index 7cb8a12ca..a6e7059c0 100644 --- a/src/assets/data/news.json +++ b/src/assets/data/news.json @@ -1,7 +1,126 @@ { "currentNews": [ + { + "id": 503, + "displayOnHomepageOrder": 1, + "newsType": "blog", + "title": "LAST CHANCE — Virtual Registration for CVE/FIRST VulnCon 2025 Closes April 4", + "urlKeywords": "VulnCon 2025 Registration Closes April 4", + "date": "2025-04-01", + "author": { + "name": "CVE Program", + "organization": { + "name": "CVE Program", + "url": "" + }, + "title": "", + "bio": "" + }, + "description": [ + { + "contentnewsType": "paragraph", + "content": "Registration for virtual attendance to CVE/FIRST VulnCon 2025 is open through April 4, 2025, on the FIRST conference website. Virtual admission registration is US $100.00. Discounted rates are not offered for this event regardless of membership or speaking status. This is your last chance, so register today!" + }, + { + "contentnewsType": "paragraph", + "content": "The CVE Program and FIRST are co-hosting VulnCon 2025 at the McKimmon Center in Raleigh, North Carolina, USA, on April 7-10, 2025. CVE Numbering Authorities (CNAs) — VulnCon 2025 takes the place of the 2025 Spring CVE Global Summit." + }, + { + "contentnewsType": "image", + "imageWidth": "", + "href": "/news/VulnCon2025.png", + "altText": "CVE/FIRST VulnCon 2025, April 7-10, 2025", + "captionText": "VulnCon 2025" + }, + { + "contentnewsType": "paragraph", + "content": "

Agenda

" + }, + { + "contentnewsType": "paragraph", + "content": "View the
full agenda on the conference web page or view the schedule by day:" + }, + { + "contentnewsType": "paragraph", + "content": "Monday, April 7View day 1 schedule
Tuesday, April 8View day 2 schedule
Wednesday, April 9View day 3 schedule
Thursday, April 10View day 4 schedule" + }, + { + "contentnewsType": "paragraph", + "content": "

Venue

" + }, + { + "contentnewsType": "paragraph", + "content": "McKimmon Center
North Carolina State University
1101 Gorman St.
Raleigh, North Carolina 27606
USA" + }, + { + "contentnewsType": "paragraph", + "content": "

Learn More About VulnCon 2025

" + }, + { + "contentnewsType": "paragraph", + "content": "The purpose of the VulnCon — which is open to the public — is to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken back to individual programs for action to benefit the vulnerability management ecosystem. A key goal of the conference is to understand what important stakeholders and programs are doing within the vulnerability management ecosystem and best determine how to benefit the ecosystem broadly." + }, + { + "contentnewsType": "paragraph", + "content": "For the most up-to-date information, visit the CVE/FIRST VulnCon 2025 conference page hosted on the FIRST website." + }, + { + "contentnewsType": "paragraph", + "content": "We look forward to seeing you at this exciting community event and encourage you to register today!" + } + ] + }, + { + "id": 502, + "displayOnHomepageOrder": 2, + "newsType": "blog", + "title": "FINAL REMINDER — Please Complete Our “CVE Data Usage and Satisfaction Survey” by April 4", + "urlKeywords": "CVE Data Usage Satisfaction Survey Final Reminder", + "date": "2025-04-01", + "author": { + "name": "CVE Program", + "organization": { + "name": "CVE Program", + "url": "" + }, + "title": "", + "bio": "" + }, + "description": [ + { + "contentnewsType": "paragraph", + "content": "The “CVE Data Usage and Satisfaction Survey,” which opened on March 4, 2025, will close at 11:59 PM ET on April 4, 2025. If you are a consumer of CVE Records, or a defender, the CVE Program would like to hear from you about such topics as:To participate in the survey, please click here." + }, + { + "contentnewsType": "paragraph", + "content": "Your feedback will play a crucial role in enhancing the CVE Program and its service offerings. Your responses, which will be anonymous unless you provide your contact information in the final optional question, will be used solely for research and improvement purposes." + }, + { + "contentnewsType": "paragraph", + "content": "If you have any questions or need assistance, please use the CVE Request Web Form and select “Other” from the dropdown menu." + } + ] + }, + { + "id": 501, + "newsType": "news", + "title": "Minutes from CVE Board Teleconference Meeting on March 5 Now Available", + "urlKeywords": "CVE Board Minutes from March 5", + "date": "2025-04-01", + "description": [ + { + "contentnewsType": "paragraph", + "content": "The CVE Board held a teleconference meeting on March 5, 2025. Read the meeting minutes summary." + }, + { + "contentnewsType": "paragraph", + "content": "The CVE Board is the organization responsible for the strategic direction, governance, operational structure, policies, and rules of the CVE Program. The Board includes members from numerous cybersecurity-related organizations including commercial security tool vendors, academia, research institutions, government departments and agencies, and other prominent security experts, as well as end-users of vulnerability information." + } + ] + }, { "id": 500, + "displayOnHomepageOrder": 4, "newsType": "news", "title": "Digi Added as CVE Numbering Authority (CNA)", "urlKeywords": "Digi Added as CNA", @@ -23,6 +142,7 @@ }, { "id": 499, + "displayOnHomepageOrder": 3, "newsType": "blog", "title": "Vulnerability Data Enrichment for CVE Records: 250 CNAs on the Enrichment Recognition List for March 25, 2025", "urlKeywords": "CNA Enrichment Recognition List Update", @@ -59,7 +179,6 @@ }, { "id": 498, - "displayOnHomepageOrder": 1, "newsType": "blog", "title": "Reminder for CVE Consumers — Please Complete the “CVE Data Usage and Satisfaction Survey” Before April 4, 2025", "urlKeywords": "CVE Data Usage and Satisfaction Survey Reminder", @@ -210,7 +329,6 @@ }, { "id": 492, - "displayOnHomepageOrder": 2, "newsType": "blog", "title": "Full Agenda Now Available for CVE/FIRST VulnCon 2025 on April 7-10, 2025!", "urlKeywords": "Full Agenda for CVE FIRST VulnCon 2025", diff --git a/src/views/Home.vue b/src/views/Home.vue index 0c958ff20..d525f90e9 100644 --- a/src/views/Home.vue +++ b/src/views/Home.vue @@ -12,9 +12,9 @@ Identify, define, and catalog publicly disclosed cybersecurity vulnerabilities.

- Currently, there are {{cveRecordsTotal}} CVE Records accessible via - Download - or Keyword Search above + There are currently over {{cveRecordsTotal}} + CVE Records accessible via Download + or Keyword Search above.