Skip to content

project

National Vulnerability Database

U.S. government repository, run by NIST, that aggregates CVE vulnerability records and adds severity scores (CVSS) and affected product details.

Known aliases

  • NVD

Relationships

No evidence-backed relationships are recorded.

Current stories

security3 publishers

NIST concedes manual NVD enrichment no longer scales, and gives 62 days to argue about the fix

A Federal Register RFI calls periodic scanning, static prioritization and manual remediation increasingly inadequate. Comments on redesigning the feed close October 13.

Perspective Coverage

3 publishers
Builder
Builder 35%
Operator
Operator 55%
Investor
Investor 10%

Reality

Evidence72
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence70
security4 publishers

NASA's AIT-GUI Ground Console Shipped Without Auth: CVSS 9.4, Fixed in 2.5.2

A flaw in NASA's open-source AIT-GUI lets unauthenticated requests reach spacecraft command routes, and Cycode says a malicious web page can deliver them through an operator's browser.

Perspective Coverage

4 publishers
Builder
Builder 43%
Operator
Operator 50%
Investor
Investor 7%

Reality

Evidence70
Adoption
Insufficient
Hype gap+30
Incentives45
Confidence65
security3 publishers

CISA reframes the CVE program around data quality as 2026 heads for 96,000 records

Disclosure volume is climbing faster than the process around it. CISA's answer is a framework that describes what a good CVE record is and how the program should be judged on producing one.

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 50%
Investor
Investor 17%

Reality

Evidence68
Adoption
Insufficient
Hype gap+30
Incentives55
Confidence66