What is the NVD?
The National Vulnerability Database run by NIST, which republishes CVE records and adds analysis such as CVSS scores, CWE types and CPE product names.
NVD is where many scanners get affected-product matching: it maps each CVE to CPE names so a tool can tell whether the software version you run is affected. Its analysts also add CVSS vectors and CWE weakness types when the CNA did not.
NVD analysis can lag behind CVE publication, so a fresh CVE may show up with no score or CPE data yet; checking the vendor advisory directly closes that gap.
Sources
Related terms
- CPECommon Platform Enumeration: a structured name for a product and version, used to match CVEs to the software you run.
- CWECommon Weakness Enumeration: the catalogue of software and hardware weakness types, such as CWE-79 (cross-site scripting) or CWE-787 (out-of-bounds write).
- CVSSCommon Vulnerability Scoring System: FIRST's standard 0.0–10.0 score for how severe a vulnerability is, based on how it can be exploited and what it affects.
- CVECommon Vulnerabilities and Exposures: the public ID system for disclosed security flaws, written as CVE-YEAR-NUMBER, for example CVE-2021-44228.