NVD enrichment can add severity metrics, weakness classifications, product applicability, and reference labels; search and machine-readable feeds distribute the data. The NVD builds on the CVE List; it does not assign CVE identifiers or operate the CVE Program.
Enrichment uses the Common Vulnerability Scoring System (CVSS), Common Weakness Enumeration (CWE), and Common Platform Enumeration (CPE). Under NVD’s current scope-of-coverage policy, some records may remain unanalyzed; data can change as evidence improves.
Key points
Data flowA CVE Numbering Authority (CNA) publishes a CVE Record to the CVE List; the NVD imports it and, when possible, adds analysis that supports searching, correlation, automation, and prioritization workflows.
Applicability checksCPE-based configurations describe modeled product applicability, but organizations should compare versions, platforms, configurations, and supplier information with their actual inventory.
Operational useConsumers can use the website, feeds, and application programming interfaces to monitor changes and connect standardized records to internal assets, while retaining source dates and identifiers.
Important limitationNVD data is not the result of active testing and may be incomplete, delayed, disputed, or revised; an NVD score or product match does not prove exploitability, exposure, or business risk in a particular environment.