The openscap project is a set of open source libraries that support the SCAP (Security Content Automation Protocol) set of standards from NIST. It supports CPE, CCE, CVE, and CVSS.
Changes: OVAL now has textfilecontent probe and can now use variables in findfiles, process, and password probes. Semantic validation was added for the syschar and result models. Many memory leaks were cleaned up.