SECAI Core · phase 14 of 15 · noun
NIST National Vulnerability Database (NVD)
A US government-maintained, publicly accessible repository of standardized information about known cybersecurity vulnerabilities, built on the MITRE CVE list and enriched with severity scores, impact metrics, and other security data to help organizations assess and manage vulnerability risk
The Explain card
- Plain English
- The NVD is a US government repository that takes the MITRE CVE list and enriches each entry with severity scores, impact metrics and other structured data so organisations can assess and prioritise vulnerability risk.
- Example
- An AI platform team has thirty CVEs across their dependencies. Using NVD severity scores, they patch the critical remote code execution flaw in their model-serving framework first and schedule the low-severity issues for later.
- Why it matters
- Knowing a vulnerability exists is step one. NVD tells you how bad it is, which is what risk-based patching of AI infrastructure depends on.
- Hook
- CVE names the bug, NVD grades it.
Word knowledge
How the word is built, where it came from, and what it sits beside in memory.
In a sentence
A scanner matched the server's OpenSSL version to a CVE record in the NIST National Vulnerability Database (NVD) before the patch was approved.
Why these words
- NIST English initialism of National Institute of Standards and Technology, adopted in 1988 acts as an institutional modifier identifying the organization associated with the named resource
- National Latin nationalis, of a nation, through French marks the name as having nationwide institutional scope
- Vulnerability Late Latin vulnerabilis, wounding, from vulnus, wound, plus English -ity specifies the subject represented by the head noun
- Database English computing compound of data and base serves as the head noun of the phrase
- NVD English initialism formed from National Vulnerability Database provides the standard shortened form of the three-word name
Where it came from
- Origin
- American English institutional coinage formed from National, Vulnerability, and Database, with the NIST name prefixed
- Entered the language
- 2005
- What changed
- The name replaced the earlier ICAT Metabase label, while NVD became the conventional initialism and omitted the prefixed NIST.
How it is spelled
- Pattern
- Each principal word begins with a capital letter because the phrase is an official proper name.
- Pattern
- Vulnerability keeps the productive suffix -ity after vulnerable.
- Pattern
- Database is written as a closed compound of data and base.
- Pattern
- NVD takes the initial letters of National Vulnerability Database.
- Breaks the pattern
- The prefixed initialism NIST is not represented in the shorter initialism NVD.
Spelled like
- availability
- reliability
- dataset
- codebase
Broken into chunks
-
nation
- national
- nationality
- international
-
vulner
- vulnerable
- invulnerable
- vulnerability
-
-ability
- availability
- reliability
- scalability
-
data
- dataset
- datacenter
- metadata
-
base
- codebase
- knowledge base
- baseline
What it sits beside
Same subject
- Common Vulnerabilities and Exposures
- Common Vulnerability Scoring System
- Common Platform Enumeration
- Common Weakness Enumeration
Same shape
- NIST Cybersecurity Framework
- National Software Reference Library
- Common Vulnerabilities and Exposures
cybersecurity initialisms
- CVE
- CVSS
- CPE
- CWE
vulnerability resource names
- MITRE CVE List
- CISA Known Exploited Vulnerabilities Catalog
- NIST National Vulnerability Database
Where it sits in the deck
Phase 14: Incident Response, Evaluation, and Knowledge Bases
When detection fires, teams need structured response plans, scoring frameworks, and curated knowledge bases to triage, measure, and learn from AI security events.