NIST is cataloging so many vulnerabilities that it can only assign severity scores to the highest priority threats.



  • NIST Changes National Vulnerability Database Enrichment Process Due to Increase in CVE Submissions
  • 263% increase from 2020; Priority is now given to KEV entries, federal software, and critical software per EO 14028.
  • Other CVEs are considered “lower priority,” but users can request enrichment via email if necessary

The number of reported vulnerabilities has increased so dramatically that it forced the National Institute of Standards and Technology (NIST) to change the way it “enriches” each entry.

Until now, NIST would take a basic CVE record and add structured analysis to make it more useful in the National Vulnerability Database (NVD). Typically, that includes severity score (CVSS), affected products (CPE), classification of weaknesses (CWE), and additional metadata.

Leave a Comment

Your email address will not be published. Required fields are marked *