NIST lists so many vulnerabilities that it can only assign severity scores to the highest priority threats.


  • NIST Modifies National Vulnerability Database Enrichment Process Due to Increase in CVE Submissions
  • 263% increase since 2020; priority is now given to KEV entries, federal software and critical software under EO 14028
  • Other CVEs deemed “lower priority”, but users can request enrichment by email if necessary

The number of reported vulnerabilities has increased so much that it has forced the National Institute of Standards and Technology (NIST) to change how it “enriches” each entry.

Until now, NIST took a basic CVE record and added a structured analysis to it, to make it more useful in the National Vulnerability Database (NVD). This typically includes Severity Score (CVSS), Affected Products (CPE), Weakness Classification (CWE), and additional metadata.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top