# National Vulnerability Database
**Acronym:** NVD
**Entity class:** Federal vulnerability repository
## Definition
The **National Vulnerability Database (NVD)** is the [[wiki/NIST|National Institute of Standards and Technology]] repository of information about software and hardware flaws that can compromise computer security. NIST describes it as a key part of national cybersecurity infrastructure.
## Machine-readable role
NVD enriches [[wiki/Common Vulnerabilities and Exposures|CVE]] records with structured information used by automated vulnerability-management systems. In 2026 NVD added [[wiki/Stakeholder-Specific Vulnerability Categorization|SSVC]] data and affected-product information to feeds and APIs, retained modification histories and timestamps for synchronization, and prioritized enrichment of vulnerabilities in the [[wiki/Known Exploited Vulnerabilities Catalog|KEV Catalog]], federal software, and critical software.
## Relationships
- **maintainer:** [[wiki/NIST|NIST]].
- **record identity:** [[wiki/Common Vulnerabilities and Exposures|Common Vulnerabilities and Exposures]].
- **architecture:** [[wiki/Continuous Vulnerability Intelligence|Continuous Vulnerability Intelligence]].
- **neurosecurity relevance:** [[wiki/Medical Device Vulnerability Management|Medical Device Vulnerability Management]].
## Sources / Provenance
- National Institute of Standards and Technology, [National Vulnerability Database](https://www.nist.gov/itl/nvd), including April, June, and August 2026 operational updates (accessed 2026-09-23).
**As of:** 2026-09-23