Micron Document
<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>National Vulnerability Database</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/National_Vulnerability_Database"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-National_Vulnerability_Database rootpage-National_Vulnerability_Database skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">National Vulnerability Database</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<p>The <b>National Vulnerability Database</b> (<b>NVD</b>) is the U.S. government repository of standards-based vulnerability management data represented using the <a href="Security_Content_Automation_Protocol" title="Security Content Automation Protocol">Security Content Automation Protocol</a> (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. NVD includes databases of security checklists, security related software flaws, misconfigurations, product names, and impact metrics. NVD supports the <a href="Information_Security_Automation_Program" title="Information Security Automation Program">Information Security Automation Program</a> (ISAP). NVD is managed by the U.S. government agency the <a href="National_Institute_of_Standards_and_Technology" title="National Institute of Standards and Technology">National Institute of Standards and Technology</a> (NIST).
</p><p>On Friday March 8, 2013, the database was taken offline after it was discovered that the system used to run multiple government sites had been compromised by a software vulnerability of <a href="Adobe_ColdFusion" title="Adobe ColdFusion">Adobe ColdFusion</a>.<sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</p><p>The vulnerabilities in the NVD originate from the <a href="Common_Vulnerabilities_and_Exposures" title="Common Vulnerabilities and Exposures">Common Vulnerabilities and Exposures</a> (CVE) list, maintained by <a href="MITRE" class="mw-redirect" title="MITRE">MITRE</a>. New vulnerabilities are assigned by MITRE and CVE Numbering Authorities and subsequently added to the NVD.<sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup>
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="CVE_Enrichment">CVE Enrichment</h2></div>
<p>When vulnerabilities are added to the list of <a href="Common_Vulnerabilities_and_Exposures" title="Common Vulnerabilities and Exposures">Common Vulnerabilities and Exposures</a> (CVEs), the NVD assigns them a score using the <a href="Common_Vulnerability_Scoring_System" title="Common Vulnerability Scoring System">Common Vulnerability Scoring System (CVSS)</a>.<sup id="cite_ref-:1_4-0" class="reference"><a href="#cite_note-:1-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> This score is based on metrics such as access complexity and potential impact,<sup id="cite_ref-6" class="reference"><a href="#cite_note-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> allowing organizations to prioritize remediation efforts depending on the severity.<sup id="cite_ref-:1_4-1" class="reference"><a href="#cite_note-:1-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup>
</p><p>In June 2017, threat intel firm <a href="Recorded_Future" title="Recorded Future">Recorded Future</a> revealed that the median lag between a CVE being revealed to ultimately being published to the NVD is 7 days and that 75% of vulnerabilities are published unofficially before making it to the NVD, giving attackers time to exploit the vulnerability.<sup id="cite_ref-7" class="reference"><a href="#cite_note-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>
</p><p>In August 2023, the NVD initially marked an integer overflow bug in old versions of <a href="CURL" title="CURL">cURL</a> as a 9.8 out of 10 critical vulnerability. cURL lead developer <a href="Daniel_Stenberg" title="Daniel Stenberg">Daniel Stenberg</a> responded by saying this was not a security problem, the bug had been patched nearly 4 years prior, requested the CVE be rejected, and accused NVD of "scaremongering" and "grossly inflating the severity level of issues".<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> MITRE disagreed with Stenberg and denied his request to reject the CVE, noting that "there is a valid weakness ... which can lead to a valid security impact."<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup>
In September 2023, the issue was rescored by the NVD as a 3.3 "low" vulnerability, stating that "it may (in theory) cause a denial of service" for attacked systems, but that this attack vector "is not especially plausible".<sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<ul><li><a href="Common_Vulnerabilities_and_Exposures" title="Common Vulnerabilities and Exposures">Common Vulnerabilities and Exposures</a></li>
<li><a href="Common_Weakness_Enumeration" title="Common Weakness Enumeration">Common Weakness Enumeration</a></li>
<li><a href="European_Union_Vulnerability_Database" title="European Union Vulnerability Database">European Union Vulnerability Database</a></li>
<li><a href="Software_composition_analysis" title="Software composition analysis">Software composition analysis</a></li></ul>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */


.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}


/* end https://en.wikipedia.org/ */
</style><div class="reflist reflist-columns references-column-width" style="column-width: 30em;">
<ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-1">^</a></b></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */


.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}


/* end https://en.wikipedia.org/ */
</style><cite id="CITEREFat_17:55" class="citation web cs1">at 17:55, Jack Clark in San Francisco 14 Mar 2013. <a rel="nofollow" class="external text" href="https://www.theregister.co.uk/2013/03/14/adobe_coldfusion_vulns_compromise_us_malware_catalog/">"Downed US vuln catalog infected for at least TWO MONTHS"</a>. <i>www.theregister.co.uk</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2019-10-29</span></span>.</cite><span class="cs1-maint citation-comment"><code class="cs1-code">{{cite web}}</code>: CS1 maint: numeric names: authors list (link)</span></span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-2">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://www.theregister.co.uk/2013/03/14/us_malware_catalogue_hacked/">"US national vulnerability database hacked."</a></span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-3">^</a></b></span> <span class="reference-text"><cite id="CITEREFNIST" class="citation web cs1"><a href="National_Institute_of_Standards_and_Technology" title="National Institute of Standards and Technology">NIST</a>. <a rel="nofollow" class="external text" href="https://nvd.nist.gov/general/cve-process">"CVEs and the NVD Process"</a>. <i>nvd.nist.gov</i>.</cite></span>
</li>
<li id="cite_note-:1-4"><span class="mw-cite-backlink">^ <a href="#cite_ref-:1_4-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:1_4-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFTownsend2024" class="citation news cs1">Townsend, Kevin (3 April 2024). <a rel="nofollow" class="external text" href="https://www.securityweek.com/cve-and-nvd-a-weak-and-fractured-source-of-vulnerability-truth/">"CVE and NVD – A Weak and Fractured Source of Vulnerability Truth"</a>. <i>SecurityWeek</i><span class="reference-accessdate">. Retrieved <span class="nowrap">28 May</span> 2025</span>.</cite></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text"><cite id="CITEREFZhangOuCaragea2015" class="citation journal cs1">Zhang, Su; Ou, Xinming; Caragea, Doina (2015-12-31). <span class="id-lock-subscription" title="Paid subscription required"><a rel="nofollow" class="external text" href="http://www.tandfonline.com/doi/full/10.1080/19393555.2015.1111961">"Predicting Cyber Risks through National Vulnerability Database"</a></span>. <i>Information Security Journal: A Global Perspective</i>. <b>24</b> (<span class="nowrap">4–</span>6): <span class="nowrap">194–</span>206. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1080%2F19393555.2015.1111961">10.1080/19393555.2015.1111961</a>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1939-3555">1939-3555</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:30587194">30587194</a>.</cite></span>
</li>
<li id="cite_note-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-6">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20131221044001/http://nvd.nist.gov/cvsseq2.htm">"NVD - CVSS v2 Equations"</a>. <i>nvd.nist.gov</i>. Archived from <a rel="nofollow" class="external text" href="http://nvd.nist.gov/cvsseq2.htm">the original</a> on 2013-12-21.</cite></span>
</li>
<li id="cite_note-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-7">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.darkreading.com/vulnerabilities---threats/75--of-vulns-shared-online-before-nvd-publication/d/d-id/1329066">"75% of Vulns Shared Online Before NVD Publication"</a>. <i>Dark Reading</i>. 7 June 2017<span class="reference-accessdate">. Retrieved <span class="nowrap">2019-10-29</span></span>.</cite></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-8">^</a></b></span> <span class="reference-text"><cite id="CITEREFStenberg2023" class="citation web cs1">Stenberg, Daniel (26 August 2023). <a rel="nofollow" class="external text" href="https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/">"CVE-2020-19909 is everything that is wrong with CVEs"</a>. <i>Daniel Stenberg's Blog</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2023-08-26</span></span>.</cite></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-9">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://curl.se/docs/CVE-2020-19909.html">"curl - Bogus report filed by anonymous - CVE-2020-19909"</a>. <i>curl.se</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2023-08-31</span></span>.</cite></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-10">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20230905213507/https://nvd.nist.gov/vuln/detail/CVE-2020-19909">"NVD - CVE-2020-19909"</a>. <i>nvd.nist.gov</i>. Archived from <a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2020-19909">the original</a> on 2023-09-05<span class="reference-accessdate">. Retrieved <span class="nowrap">2023-09-07</span></span>.</cite></span>
</li>
</ol></div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li><span class="official-website"><span class="url"><a rel="nofollow" class="external text" href="https://nvd.nist.gov/">Official website</a></span></span></li>
<li><a rel="nofollow" class="external text" href="https://csrc.nist.gov/projects/security-content-automation-protocol/">Security Content Automation Protocol (SCAP)</a></li>
<li><a rel="nofollow" class="external text" href="https://packetstormsecurity.com/">Packet Storm</a></li>
<li><a rel="nofollow" class="external text" href="https://www.exploit-db.com/">Exploit Database</a></li>
<li><a rel="nofollow" class="external text" href="https://vulners.com/">Security Content Database</a></li></ul>
<p><br>
</p>
<style data-mw-deduplicate="TemplateStyles:r1271159938">
/* start https://en.wikipedia.org/ */


.mw-parser-output .asbox{position:relative;overflow:hidden}.mw-parser-output .asbox table{background:transparent}.mw-parser-output .asbox p{margin:0}.mw-parser-output .asbox p+p{margin-top:0.25em}.mw-parser-output .asbox-body{font-style:italic}.mw-parser-output .asbox-note{font-size:smaller}.mw-parser-output .asbox .navbar{position:absolute;top:-0.75em;right:1em;display:none}.mw-parser-output :not(p):not(.asbox)+style+.asbox,.mw-parser-output :not(p):not(.asbox)+link+.asbox{margin-top:3em}


/* end https://en.wikipedia.org/ */
</style></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-06-28" href="https://en.wikipedia.org/wiki/?title=National_Vulnerability_Database&amp;oldid=1297750907">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>

</body></html>