# National Vulnerability Database **Acronym:** NVD **Entity class:** Federal vulnerability repository ## Definition The **National Vulnerability Database (NVD)** is the [[wiki/NIST|National Institute of Standards and Technology]] repository of information about software and hardware flaws that can compromise computer security. NIST describes it as a key part of national cybersecurity infrastructure. ## Machine-readable role NVD enriches [[wiki/Common Vulnerabilities and Exposures|CVE]] records with structured information used by automated vulnerability-management systems. In 2026 NVD added [[wiki/Stakeholder-Specific Vulnerability Categorization|SSVC]] data and affected-product information to feeds and APIs, retained modification histories and timestamps for synchronization, and prioritized enrichment of vulnerabilities in the [[wiki/Known Exploited Vulnerabilities Catalog|KEV Catalog]], federal software, and critical software. ## Relationships - **maintainer:** [[wiki/NIST|NIST]]. - **record identity:** [[wiki/Common Vulnerabilities and Exposures|Common Vulnerabilities and Exposures]]. - **architecture:** [[wiki/Continuous Vulnerability Intelligence|Continuous Vulnerability Intelligence]]. - **neurosecurity relevance:** [[wiki/Medical Device Vulnerability Management|Medical Device Vulnerability Management]]. ## Sources / Provenance - National Institute of Standards and Technology, [National Vulnerability Database](https://www.nist.gov/itl/nvd), including April, June, and August 2026 operational updates (accessed 2026-09-23). **As of:** 2026-09-23