About the Project
The National Vulnerability Database (NVD) is the official US government repository managed by NIST. Essentially, it is a centralized repository of vulnerability data standardized using the Security Content Automation Protocol (SCAP). The main goal of the project is to automate the processes of vulnerability management, security assessment and compliance testing. NVD website. nist. gov is not a commercial product. This is a state resource, as confirmed by the . gov and using a secure HTTPS connection. It is important for users to understand that if you see a warning that you are viewing a page in an unauthorized frame, this is a built-in defense against potential clickjacking attacks. The site also requires JavaScript to be enabled for full functionality.
Main directions
NVD's content is built around several key databases. The project aggregates information about:
- Software errors:Detailed descriptions of software vulnerabilities, including their impact and metrics.
- Products:CPE (Common Platform Enumeration) directory, which allows you to accurately identify software products and versions.
- Metrics:Assessing the severity of threats through the CVSS (Common Vulnerability Scoring System) system. Calculators for versions 2.0, 3.x and the new 4.0 are available on the site.
- Checklists:Links to safety standards and checklists.
Users can search for data through statistics and visualization tools. Data is also provided in feeds format for automatic import into monitoring systems. Particular attention is paid to Weakness Types, which helps classify errors into categories.
Site Features
The NVD interface is aimed at a technical audience: cybersecurity specialists, auditors and developers. The key feature is the relevance of the data. The main page always displays the latest 20 indexed vulnerability IDs with a brief description and risk level (CVSS Severity). Analysis of recent updates shows a high density of publications. For example, at the end of December 2025 and the beginning of February 2026, many critical patches were recorded for popular products:
- Composer (PHP):Vulnerability that allows ANSI characters to be injected into terminal output.
- Dell Wyse Management Suite:A series of problems including XSS, security bypass, and unauthorized file uploads.
- Firefox and Thunderbird:Memory errors (use-after-free, out-of-bounds read), which could theoretically lead to the execution of arbitrary code.
- Google Chrome:Issues in the Media, Tint and DevTools components related to memory access and script injection.
- janet-lang:Out-of-bounds read errors in compilation and string functions.
This dynamic underscores the role of NVD as a rapid source of information about current threats. The site also provides tools for citing data, including DOI (Digital Object Identifier), which is important for scientific and reporting purposes.
Contact information
The project belongs to the US government. The official headquarters address is 100 Bureau Drive, Gaithersburg, MD 20899. For issues not directly related to the vulnerability database (such as incidents or technical support), the US-CERT Security Operations Center is available.
Email:Available on the website.
Phone:1-888-282-0870.
FAQ
FAQ
What is NVD and why is it needed?
NVD is a US national vulnerability database. It standardizes security error information using the SCAP protocol. This allows you to automate the verification of systems for compliance with standards and quickly respond to new threats.
How to assess the severity of a found vulnerability?
CVSS (Common Vulnerability Scoring System) metrics are used for this. On the nvd website. nist. gov, online calculators are available for all major versions of the standard: v2. 0, v3. x and the latest v4. 0.
Can NVD data be used in scientific work?
Yes. For correct database citation, NIST provides a Digital Object Identifier (DOI). Detailed instructions for creating links are available in the documentation section of the site.
Why does the site require JavaScript?
The functionality of the portal, including search, data visualization and CVSS calculators, is entirely dependent on client-side scripting. Without JavaScript enabled, access to the core tools will be limited.
Where should I contact if a cyber incident is detected?
If the question is not just about finding information about a vulnerability, but about an actual attack or technical security issue, you should contact the US-CERT Security Operations Center by calling 1-888-282-0870 or via their email.
.