National Vulnerability Database
Coverage of National Vulnerability Database in the Nexus archive.
- Inspector general finds NIST mistakes have made vulnerability database ineffective
An inspector general report found that NIST's National Vulnerability Database (NVD) backlog of unprocessed security vulnerabilities grew from 13,000 in February 2024 to over 27,000 by late 2025, undermining the database's utility and public trust.
- Federal audit reveals NIST’s NVD is plagued by poor planning and duplication
A federal audit found the National Institute of Standards and Technology (NIST) mismanaged its National Vulnerability Database (NVD) due to poor planning, inefficient operations, and duplication with the Cybersecurity and Infrastructure Security Agency (CISA)'s program. The backlog of unprocessed security flaws grew from 13,000 in June 2024 to over 27,000 by December 2025, with NIST failing to meet its self-imposed processing goals and wasting an estimated $200,000 on duplicated work between agencies.
- NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions
The National Institute of Standards and Technology (NIST) has adjusted its CVE enrichment process in the National Vulnerability Database (NVD) due to a 263% surge in vulnerability submissions. Only CVEs meeting specific criteria will now be enriched, while others will remain listed without additional details.
- NIST narrows scope of CVE analysis to keep up with rising tide of vulnerabilities
NIST has narrowed its focus for analyzing CVEs to prioritize those in CISA's catalog, federal government software, and critical software under Executive Order 14028 due to an overwhelming increase in vulnerabilities. The change aims to stabilize the NVD program amid backlogs and funding challenges, shifting away from automatically enriching non-priority CVEs.