# What is the National Vulnerability Database (NVD)?

> The National Vulnerability Database (NVD) is a National Institute of Standards and Technology (NIST) repository that ingests published Common Vulnerabilities and Exposures (CVE) Records and adds structured vulnerability-management data.

- Canonical URL: https://yellowcube.eu/glossary/national-vulnerability-database/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

NVD enrichment can add severity metrics, weakness classifications, product applicability, and reference labels; search and machine-readable feeds distribute the data. The NVD builds on the CVE List; it does not assign CVE identifiers or operate the CVE Program.

Enrichment uses the Common Vulnerability Scoring System (CVSS), Common Weakness Enumeration (CWE), and Common Platform Enumeration (CPE). Under NVD’s current scope-of-coverage policy, some records may remain unanalyzed; data can change as evidence improves.

### Key points

- **Data flow:** A CVE Numbering Authority (CNA) publishes a CVE Record to the CVE List; the NVD imports it and, when possible, adds analysis that supports searching, correlation, automation, and prioritization workflows.
- **Applicability checks:** CPE-based configurations describe modeled product applicability, but organizations should compare versions, platforms, configurations, and supplier information with their actual inventory.
- **Operational use:** Consumers can use the website, feeds, and application programming interfaces to monitor changes and connect standardized records to internal assets, while retaining source dates and identifiers.
- **Important limitation:** NVD data is not the result of active testing and may be incomplete, delayed, disputed, or revised; an NVD score or product match does not prove exploitability, exposure, or business risk in a particular environment.

### Related terms

[Common Vulnerabilities and Exposures (CVE)](<https://yellowcube.eu/glossary/common-vulnerabilities-and-exposures/>) · [Common Vulnerability Scoring System (CVSS)](<https://yellowcube.eu/glossary/common-vulnerability-scoring-system/>) · [Vulnerability management](<https://yellowcube.eu/glossary/vulnerability-management/>) · [Vulnerability scanning](<https://yellowcube.eu/glossary/vulnerability-scanning/>) · [Software bill of materials (SBOM)](<https://yellowcube.eu/glossary/software-bill-of-materials/>)

### Sources

[NIST: National Vulnerability Database](https://nvd.nist.gov/General) · [NVD: CVE and NVD process](https://nvd.nist.gov/general/cve-process) · [NVD: General FAQs](https://nvd.nist.gov/general/FAQ-Sections/General-FAQs)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

