It should be public, 100%.
The people that don't want it to be public say "Well if we tell users about exploits they are more likely to use them!". That is stupid, staff exist for a reason.
HUGE
EDIT: This list isn't even been sent to staff members, which causes even more confusions. It should at least be used as part of training staff.