NVD

National Vulnerability Database (USA)

US-amerikanische Schwachstellendatenbank

The NVD is the vulnerability database operated by the US NIST, which enriches CVE records with assessments, product mappings (CPE) and classifications (CWE). For years it was the global standard reference for enriched vulnerability data. Since 2024, however, it has been struggling with a substantial processing backlog.

History & facts. The NVD was established in 2005 and supplied the machine-usable enrichment to CVE records — CVSS values, affected configurations, weakness classes. From early 2024 a growing backlog arose, triggered by a change of processing contractor and a temporary funding gap; by the end of 2025 the backlog grew to more than 27,000 unprocessed entries. In April 2026 NIST switched to a risk-based model: only vulnerabilities from the KEV catalogue, in federal software or in software classified as critical are still enriched as a priority; older unprocessed entries are deemed „not scheduled“. Outlook & recommendation. The NVD crisis marks a turning point: those who based their prioritisation solely on NVD enrichment now have a gap. Increasingly the CNAs supply their CVSS values themselves, and complementary sources such as the EUVD or EPSS gain importance. The practical consequence: vulnerability management must not depend on a single, state-funded source — multi-source enrichment and one's own context assessment become mandatory.
NVD — National Vulnerability Database (USA)