nvd
Safeguard articles tagged "nvd" — guides, analysis, and best practices for software supply chain and application security.
25 articles
CVE scoring inconsistencies across vulnerability databases
Why the same CVE can carry three different severity scores across NVD, GitHub, and vendor advisories — and how to prioritize anyway.
NIST CVE Data Explained: How the NVD Works and Why the Backlog Matters
What NIST's role in CVE data actually is, how the NVD enriches records with CVSS and CPE, and why the 2024 analysis backlog changed how teams should consume it.
How Trivy sources vulnerability data (NVD, vendor advisor...
Trivy's CVE data comes from NVD, GHSA, and distro trackers compiled into a periodic snapshot — not kube-hunter. Here's how the pipeline really works, and where it lags.
CVSS 4.0 Release Date, Changes, and Adoption Status
The CVSS 4.0 release date was November 1, 2023 — here is what changed from v3.1, how the new metric groups work, and where real-world adoption stands.
What Does CVE Stand For? A Plain-Language Security Guide
CVE stands for Common Vulnerabilities and Exposures, the public catalog that gives every known security flaw a single, shareable name. Here is how the system works and why it matters.
CVE Vulnerability Database: How the CVE and NVD System Actually Works
What the CVE vulnerability database is, how MITRE and the NVD divide the work, what a CVE record contains, and how to use it without drowning in noise.
Open Source Vulnerability Database Comparison 2026
Comparing the major open source vulnerability databases in 2026: NVD, OSV, GHSA, GitLab Advisory, and ecosystem-specific feeds measured on coverage and freshness.
NIST NVD Recovery: The New Consortium Reshaping Vulnerability Data
After months of processing backlogs and community frustration, NIST announces a new consortium to modernize and sustain the National Vulnerability Database.
The National Vulnerability Database: How to Actually Use It
The National Vulnerability Database is the US government's CVE repository — here's how to search it, read its CVSS scores, and use it in a real workflow.
NIST NVD Slowdown: What the Vulnerability Enrichment Backlog Means for Security Teams
NIST's National Vulnerability Database nearly stopped enriching CVEs in early 2024, creating a growing backlog that left security teams without the severity scores and metadata they depend on.
OSV Schema: The Open Source Vulnerability Database Format Explained
OSV provides a standardized format for vulnerability data that is purpose-built for open-source ecosystems. Here is how it works and why it is better than NVD for dependency scanning.
What is a Vulnerability Database
CVE, NVD, OSV, GHSA, KEV — vulnerability databases power every scanner's severity score. Here's how they're built, enriched, and where they fall short.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.