The NVD is the National Vulnerability Database, run by NIST, and it is where a published CVE goes to be analyzed: a CVSS severity score, the product identifiers a scanner matches on, weakness classification and references.
The CVE itself is a different organization's job, since MITRE assigns the identifier so that a vulnerability has one stable name everywhere. That split matters now because the second half has a backlog.
NIST says it has been unable to clear it since early 2024, and in April 2026 it published criteria under which most records are marked lowest priority and not scheduled for enrichment at all.
- A CVE is an identifier from MITRE, the NVD is analysis from NIST
- The NVD adds the CVSS score and the product identifiers scanners use
- The backlog of unenriched CVEs dates to early 2024 and is uncleared
- CISA KEV entries have a goal of one business day
- Everything else is lowest priority, not scheduled
On this page
Two systemsThe CVE and the NVD are two different things
Almost every page treats these as one security system with two names. The short version of CVE vs NVD is that they are two organizations doing two jobs, and the difference has become operationally important.
A CVE, a Common Vulnerabilities and Exposures record, is an identifier. MITRE, and a network of numbering authorities including vendors, assigns a number so that a vulnerability has one stable name everywhere: in a scanner report, in a vendor bulletin, in a news article and in your ticket. That is the entire job, and it is the part that works.
The NVD is analysis. NIST takes the published CVE record and enriches it with the information a tool needs: a CVSS score with its vector string, CPE identifiers naming the affected products and versions, weakness classification and links. Everything a security scanner uses to tell you that this CVE applies to that system comes from this step.
So a CVE without NVD enrichment is a real vulnerability with a real name and no score, no product mapping, and nothing for a security tool to match against. The vulnerability exists on your systems and your scanner may not see it.
The dataWhat the NVD provides and who uses the data
The plain answer to what is NVD: a free, public cybersecurity database of known vulnerabilities, open to anyone.
NIST describes the NVD as the U.S. government repository of standards based vulnerability management data, represented using the Security Content Automation Protocol (SCAP), and says the data enables automation of vulnerability management, security measurement and compliance.
For each publicly disclosed CVE, the NVD provides one record that holds:
- The description and references, carried over from the CVE record, with links to vendor advisories, patches and tools.
- CVSS scores, the severity scores with their vector strings, sometimes from more than one source.
- A CWE entry, from the Common Weakness Enumeration, naming the type of flaw, such as an injection or a buffer overflow.
- CPE data, from the Common Platform Enumeration, listing the vendors, products and versions affected.
- An analysis status, such as Analyzed, which shows whether NIST has finished its work on the record.
There are three ways to reach that data. The NVD website offers a search by CVE ID, product or keyword. The NVD API, at version 2.0, returns the same records as JSON, so tools can pull NVD CVE data on a schedule.
Most organizations use the third way without noticing: vulnerability scanners, threat intelligence platforms and software composition analysis tools provide NVD data inside their own reports.
Two limits follow from the design. The NVD lists only publicly known vulnerabilities that already have a CVE ID, so it says nothing about a zero-day before disclosure. It is also a database, not a threat feed: it describes common software flaws and scores their severity, and it does not track which attackers are active.
The backlogWhat actually happened to the NVD
Worth stating precisely, because it is recent and most writing on the subject predates it.
NIST says the National Vulnerability Database developed a significant backlog of unenriched CVEs starting in early 2024, and that it has been unable to clear that backlog as submission rates keep rising. On 15 April 2026 NIST published the criteria it now uses to decide what gets analyzed.
| Priority | What qualifies |
|---|---|
| Highest | A CVE in CISA's Known Exploited Vulnerabilities catalog |
| High | Software used within the federal government |
| High | Critical software, as defined by Executive Order 14028 |
| Lowest | Everything else, not scheduled for immediate enrichment |
For KEV entries NIST states the goal plainly: enrich them within one business day of receipt, and notes that these vulnerabilities have always been prioritized in keeping with a long-standing risk management approach.
Read the bottom row as an operating instruction rather than as news. A vulnerability management program that waits for an NVD score before deciding what to do is, for most CVEs published now, waiting for information that is not scheduled to arrive.
The argumentWhy the score was never the priority anyway
The backlog made this urgent. It was already true.
CVSS, the Common Vulnerability Scoring System, answers one question: how bad would this be if it were exploited against you. It is a severity model built from metrics describing the vulnerability itself, and it knows nothing about whether anybody is exploiting it, whether your version is affected, whether the vulnerable component is reachable, or whether you even run the software.
It is also three models, not one, and only the first is normally used. CVSS is published by FIRST, first appeared in February 2005 and is now at version 4.0, and it carries three groups of metrics.
| Metric group | What it covers | Who fills it in |
|---|---|---|
| Base | The vulnerability itself: the access it needs, described by an attack vector, and its impact on confidentiality, integrity and availability | The analyst, once |
| Temporal | What has changed since: whether exploit code exists and whether a fix is available | Rarely anybody |
| Environmental | How much the affected system matters to you, and what your own security controls change about the impact | Rarely anybody |
A score is generated for each group and a vector string records every metric as a block of text, so a full CVSS entry shows its working rather than just a number.
Base is where the access and impact metrics live, and it is the only group the National Vulnerability Database normally publishes. The Temporal group is empty on almost every record you will read.
Read the third column. The two groups of metrics that exist specifically to adjust a score for your environment and for the current state of exploitation are the two nobody fills in, so the number that reaches a security report is the context-free one. Sorting by it is sorting by the model with the context deliberately removed.
Two other signals answer the question a patching queue is actually asking.
CISA KEV is a catalog of security vulnerabilities known to have been exploited in the wild. It is a fact about the world rather than a model, and NIST puts that catalog at the front of its own queue, which is the strongest endorsement available.
EPSS, the Exploit Prediction Scoring System from FIRST, estimates the probability that a vulnerability will be exploited in the near term. It is a forecast rather than an observation, and it exists because severity and exploitation correlate badly, which makes it a better risk signal than the score.
| Signal | Answers | Comes from |
|---|---|---|
| CVE | What is this flaw called | MITRE and its numbering authorities |
| CVSS | How bad if exploited, by access and impact | Scored by NIST in the NVD |
| CPE | Which products and versions | The NVD, and it is what scanners match on |
| KEV | Is it being exploited now | CISA, from observed activity |
| EPSS | How likely soon | FIRST, as a probability |
The common failure is a security team that patches everything scored 9 or above and considers the job done. That queue is ordered by a number that does not know what is happening, and it will step over an actively exploited vulnerability scored 7.5 to reach a theoretical one scored 9.8.
In practiceHow to use this in a real patch process
Start from KEV, not from the score. Any vulnerability in the catalog goes to the top, whatever CVSS says about it, because somebody is already using it against real systems.
Use the vendor advisory when the NVD has not scored it. Microsoft, Cisco, Red Hat and the rest publish their own severity and their own affected version lists, and they do not wait in the NVD queue.
Treat an unenriched CVE as unknown rather than as harmless. No score means nobody has assessed the vulnerability yet, and lowest priority at NIST is a statement about their queue, not about your risk.
Know what your scanner is matching on. Most match CPE strings from the National Vulnerability Database. A CVE with no CPE information is invisible to that matching, which is the practical shape of the backlog inside your own security tooling.
Keep the score, drop the ranking. CVSS is still the right way to describe the severity of a vulnerability to somebody who asks how bad it is, and the vector string is a compact description of why. It is the wrong way to decide what Tuesday looks like.
Close the loop with patch management. Prioritization only matters if something downstream actually deploys, on a schedule somebody owns.
PitfallsWhere people go wrong
Treating CVE and NVD as one thing. The number always arrives. The security analysis may not, and since April 2026 there is a published rule saying which records will not get one.
Ranking by CVSS alone. Severity is not exploitation, and impact in the abstract is not risk to your systems. A queue built on the score will reach the wrong things first, and it will feel rigorous while doing it.
Assuming no score means low risk. It means nobody at NIST has been assigned to that vulnerability. Your scanner's silence is a gap in coverage rather than a clean security result.
Waiting for enrichment before acting. For most CVEs published now, that wait has no end date. The vendor advisory is available immediately.
Ignoring KEV because it is short. Short is the point. It is the list of vulnerabilities known to be in use against real networks and real systems.
Confusing the acronym. NVD is also a medical abbreviation, and a search for the bare three letters returns both. In security it is the NIST database.
ComparisonThe NVD, a vendor advisory and CISA KEV, side by side
| Criterion | NVD | Vendor advisory | CISA KEV |
|---|---|---|---|
| What it gives you | Score, products, references | Severity and fixed versions | Confirmed exploitation |
| Covers everything | In principle, with a backlog | That vendor only | No, by design |
| Timeliness | Uncertain since 2024 | Fast, it is their product | Fast, and dated |
| Machine readable | Yes, and scanners use it | Varies | Yes |
| Tells you to act | No | Sometimes | Yes, explicitly |
| Free | Yes | Yes | Yes |
The row that matters is the last but one. Only one of these three is designed to tell you that something needs doing, and it is the shortest list.
FAQFrequently asked questions
What is the NVD?
The National Vulnerability Database, run by NIST. It takes published CVE records and enriches them with a CVSS severity score, identifiers for the affected products and versions, weakness classification and reference information.
What is the difference between CVE and NVD?
A CVE is an identifier assigned by MITRE so a vulnerability has one name everywhere. The NVD is the analysis NIST adds on top of that record. Different organizations, different jobs.
Who runs the NVD?
NIST, the National Institute of Standards and Technology. The CVE program itself is run by MITRE with a network of numbering authorities that includes many vendors.
Why is the NVD behind?
NIST says a significant backlog of unenriched CVEs developed in early 2024 and that it has been unable to clear it, because the rate of submissions keeps increasing.
What gets analyzed first now?
Since 15 April 2026, CVEs in CISA's Known Exploited Vulnerabilities catalog, software used within the federal government, and critical software as defined by Executive Order 14028. Everything else is marked lowest priority.
How quickly are KEV vulnerabilities enriched?
NIST states a goal of one business day from receipt, and says KEV entries have always been prioritized under its risk management approach.
What does lowest priority mean for a CVE?
That it is not scheduled for immediate enrichment. The identifier still exists and the flaw is still real; what is missing is the score and the product mapping a tool would use.
What is CVSS?
The Common Vulnerability Scoring System, a model that expresses how severe a vulnerability would be if exploited, from metrics covering how it is reached and its impact on confidentiality, integrity and availability. It says nothing about whether anybody is exploiting it or whether you are exposed.
What is CISA KEV?
A catalog of security vulnerabilities that have been observed being exploited. It is an observation rather than a prediction, which is why it belongs at the top of a patching queue.
What is EPSS?
The Exploit Prediction Scoring System from FIRST, which estimates the probability that a given CVE will be exploited in the near term. A forecast, where KEV is a report.
Should I patch by CVSS score?
Not as the primary order. Start with KEV, then exploitation likelihood, then severity. A queue sorted by CVSS alone steps over exploited vulnerabilities to reach theoretical ones.
Why does my scanner miss some CVEs?
Most scanners match on CPE product identifiers, which come from NVD enrichment. A CVE that has not been enriched has no CPE information, so there is nothing for the scanner to match against your systems.
Where do I look when the NVD has no score?
The vendor advisory. Microsoft, Cisco, Red Hat and others publish severity and fixed versions themselves and do not depend on the NVD queue.
Does NVD mean anything else?
Yes, it is also a medical abbreviation, which is why the bare three letters return unrelated results. In security it always means the NIST database.
What is the NVD backlog?
In February 2024 NIST sharply slowed its analysis of new CVEs, and a large NVD backlog of records without severity scores or product data built up. Scanners that depend on NVD enrichment can therefore miss or underrate recent vulnerabilities. CISA's Vulnrichment project and vendor advisories fill part of the gap.
Keep readingRelated concepts
Read next · Managed IT What RMM Is, and What the Agent Can Actually Do The tooling that deploys the patch once something has decided which one matters, and reports what is still missing. Open this next9 min- Operations · 13 min Patch Management, and Why the Hard Part Is Not the Patching What happens after the prioritizing, and the part that actually closes a vulnerability rather than describing it.
- Operations · 9 min Windows Server End of Life, Version by Version What a CVE means on software that will not get a fix at all, which is the version of this problem with no queue to wait in.