SECAI Core · phase 14 of 15 · noun

NIST National Vulnerability Database (NVD)

A US government-maintained, publicly accessible repository of standardized information about known cybersecurity vulnerabilities, built on the MITRE CVE list and enriched with severity scores, impact metrics, and other security data to help organizations assess and manage vulnerability risk

The Explain card

Plain English
The NVD is a US government repository that takes the MITRE CVE list and enriches each entry with severity scores, impact metrics and other structured data so organisations can assess and prioritise vulnerability risk.
Example
An AI platform team has thirty CVEs across their dependencies. Using NVD severity scores, they patch the critical remote code execution flaw in their model-serving framework first and schedule the low-severity issues for later.
Why it matters
Knowing a vulnerability exists is step one. NVD tells you how bad it is, which is what risk-based patching of AI infrastructure depends on.
Hook
CVE names the bug, NVD grades it.

Word knowledge

How the word is built, where it came from, and what it sits beside in memory.

In a sentence

A scanner matched the server's OpenSSL version to a CVE record in the NIST National Vulnerability Database (NVD) before the patch was approved.

Why these words
  • NIST English initialism of National Institute of Standards and Technology, adopted in 1988 acts as an institutional modifier identifying the organization associated with the named resource
  • National Latin nationalis, of a nation, through French marks the name as having nationwide institutional scope
  • Vulnerability Late Latin vulnerabilis, wounding, from vulnus, wound, plus English -ity specifies the subject represented by the head noun
  • Database English computing compound of data and base serves as the head noun of the phrase
  • NVD English initialism formed from National Vulnerability Database provides the standard shortened form of the three-word name
Where it came from
Origin
American English institutional coinage formed from National, Vulnerability, and Database, with the NIST name prefixed
Entered the language
2005
What changed
The name replaced the earlier ICAT Metabase label, while NVD became the conventional initialism and omitted the prefixed NIST.
How it is spelled
Pattern
Each principal word begins with a capital letter because the phrase is an official proper name.
Pattern
Vulnerability keeps the productive suffix -ity after vulnerable.
Pattern
Database is written as a closed compound of data and base.
Pattern
NVD takes the initial letters of National Vulnerability Database.
Breaks the pattern
The prefixed initialism NIST is not represented in the shorter initialism NVD.

Spelled like

  • availability
  • reliability
  • dataset
  • codebase
Broken into chunks
  • nation
    • national
    • nationality
    • international
  • vulner
    • vulnerable
    • invulnerable
    • vulnerability
  • -ability
    • availability
    • reliability
    • scalability
  • data
    • dataset
    • datacenter
    • metadata
  • base
    • codebase
    • knowledge base
    • baseline
What it sits beside

Same subject

Same shape

cybersecurity initialisms

  • CVE
  • CVSS
  • CPE
  • CWE

vulnerability resource names

Where it sits in the deck

Phase 14: Incident Response, Evaluation, and Knowledge Bases

When detection fires, teams need structured response plans, scoring frameworks, and curated knowledge bases to triage, measure, and learn from AI security events.