Definition · Known Vulnerabilities (CVEs)
What is NVD?
The National Vulnerability Database is run by NIST, the US National Institute of Standards and Technology. It does not assign CVE identifiers — that is the CVE Program’s job, administered by MITRE and its CVE Numbering Authorities — but it ingests published CVE records and adds the structured analysis that most tooling relies on.
What the NVD adds
- CVSS scores and vector strings for severity
- CPE applicability statements describing which products and version ranges are affected
- CWE identifiers classifying the type of weakness, such as SQL injection or path traversal
- References to advisories, patches, and third-party analysis
Why the NVD matters for external exposure
Version-based vulnerability matching is essentially a join between what you are running and what the NVD says is affected. When service fingerprinting identifies a product and version on an internet-facing host, NVD applicability data is what turns that into a list of candidate vulnerabilities.
Data quality caveats
NVD enrichment is not instantaneous or universal. A CVE can be published with a vendor-supplied score but no CPE data, or sit unanalysed for a period, which leaves inventory-matching tools with nothing to join against. Enrichment backlogs have been a visible problem for the database in recent years, and practical vulnerability work uses vendor advisories, the KEV catalogue, and EPSS alongside it rather than treating the NVD as the single source of truth.
Related concepts
The NVD is the reference data behind most vulnerability management tooling, including the CVE feeds used for CVE detection on internet-facing assets.