CVE-2018-10195 is 'reserved' at MITRE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10195 However Red Has has lots of details: https://access.redhat.com/security/cve/cve-2018-10195 This means that the CVE doesn't appear in triage, and can't be searched. It's like a ghost CVE that you'll never know about. Could srtool know that CVEs are incrementing and if there are any gaps in the data then put them in triage so the user can see if its still reserved (and leave it pending), or discover that e.g. Red Hat has more data and triage appropriately.
In the latest update: 1. After the NIST CVEs are scanned, the MITRE database is scanned for any CVEs that have not been created from the NIST data. This data is the missing "reserved" CVEs. 2. When the "New" CVEs are scanned and scored, the CVE data from the alternate CVE sources are automatically registered (except for sources that are without bulk downloads and are REST accessed only). This provides the comparison CVE sources automatically for the triage process.
Implemented