National Vulnerability Database
- Company typePrivate
- Founded2005
- HeadquartersGaithersburg, United States
- Headcount—
- GTM typeB2B
- OfferingSoftware
National Vulnerability Database firmographics
Firmographics- Name
- National Vulnerability Database
- Legal name
- National Vulnerability Database
- Website
- https://nist.gov
- Company type
- Private
- Founded year
- 2005
- Operating status
- Operating
- Ownership category
- akta.pro rank
National Vulnerability Database industry classification
Industry- Product category
- Vulnerability Management Database
- NAICS
- Security Systems Services (except Locksmiths) (561621), Security Systems Services (56162)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Vulnerability Assessment & Scanning (HDADAHAA)
- akta.pro secondary industry
- Exposure Analytics & Risk-Based Prioritization (RBVM) (HDADAHAF)
Keywords
Where National Vulnerability Database is headquartered
LocationHeadquarters
- HQ city
- Gaithersburg
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
National Vulnerability Database business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Infrastructure, Operations
Revenue model
- Public Government Service: The NVD is a free, publicly available government resource maintained by NIST. It operates under the federal government mission to provide standards-based vulnerability management data to the public. There is no commercial revenue model as this is a government service provided for national cybersecurity benefit.
Distribution channels2 records
Marketing channels1 record
National Vulnerability Database product offering
Product offeringCore offering
The National Vulnerability Database (NVD) is the U.S. government repository of standards-based vulnerability management data, maintained by the National Institute of Standards and Technology (NIST). It provides structured vulnerability records, including Common Vulnerabilities and Exposures (CVE) identifiers, Common Vulnerability Scoring System (CVSS) severity scores, Common Weakness Enumeration (CWE) classifications, and Common Platform Enumeration (CPE) product mappings to support automated security management, measurement, and compliance.
Product overview
The National Vulnerability Database (NVD) is a U.S. government-hosted repository of vulnerability management data maintained by NIST. It serves as the official source for vulnerability information in the national and international cybersecurity ecosystem. The NVD provides structured vulnerability records including CVE identifiers, severity scores (CVSS), affected products, and related references. It operates as a single, centralized database offering standardized vulnerability data for automated consumption, rather than as a commercial product with multiple modules or tiers.
Differentiator
Problem solved
Functional benefit
Products and services
- National Vulnerability Database (NVD) A comprehensive publicly available database of vulnerability management data, including CVE identifiers, CVSS severity scores, CWE weakness classifications, CPE product mappings, and security checklist references. Designed for federal agencies, cybersecurity professionals, and critical infrastructure operators to perform automated vulnerability management, security measurement, and compliance.
- NVD API
- NVD Data Feeds Downloadable data feeds providing machine-readable vulnerability data for integration into external security tools, vulnerability scanners, and compliance reporting systems.
Quantifiable outcome
- Authoritative source for vulnerability data used by security tools and government compliance frameworks
Companies that use National Vulnerability Database
Customer profileNamed customers3 records
Segments3 records
Ideal customer profiles3 records
National Vulnerability Database technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature1 record
National Vulnerability Database partnerships and signals
Strategic signalScale indicators3 records
Recent moves3 records
Expansion highlights3 records
National Vulnerability Database competitors and assessment
Company assessmentDirect peers
- MITRE Corporation: MITRE operates the CVE program and several related security standards (CWE). As the upstream originator of the CVE identifiers that NVD enriches, MITRE is the closest functional peer and a direct collaborator in the vulnerability management data ecosystem.
Broad incumbents
- Rapid7: Rapid7's InsightVM and Metasploit products ingest NVD feeds and serve vulnerability management use cases for the same enterprise security audience. It competes with NVD's standardization role via its own research and vulnerability prioritization.
- Tenable: Tenable (Nessus) is the leading commercial vulnerability management platform and one of the largest consumers and contributors to NVD's CPE/CVE data. It serves the same security teams with broader commercial vulnerability assessment capabilities.
- Snyk: Snyk focuses on developer-first vulnerability scanning (open source, containers, code) and maintains its own vulnerability database alongside NVD. It targets a related but more developer-centric slice of the same vulnerability intelligence market.
- Qualys: Qualys VMDR is a major enterprise vulnerability management platform that depends on NVD feeds for CVE matching and severity scoring, and addresses the same downstream use case of identifying and prioritizing vulnerabilities.
Emerging players
- VulnCheck: VulnCheck provides commercial, real-time, exploit-aware vulnerability intelligence that competes for the same downstream consumers (security teams, vulnerability management platforms) that integrate NVD data — a more agile, enriched alternative.
Regional players
- JVN (Japan Vulnerability Notes): JVN is the Japanese national vulnerability database operated by JPCERT/CC. It serves a similar authoritative-vulnerability-intelligence role for Japanese software disclosures and parallels NVD's domestic-coordinator function.
- CNNVD (China National Vulnerability Database): CNNVD is China's national vulnerability database, operated under CNCERT. It is the closest regional peer to NVD — performing the same authoritative vulnerability enumeration role for Chinese disclosures and serving Chinese government and critical infrastructure users.
Others
- GitHub Advisory Database: GitHub's Advisory Database curates open source vulnerability information and is increasingly a first-publisher for many CVEs. It overlaps with NVD's role in open source vulnerability tracking and serves a related ecosystem of developers and security teams.
- CISA Known Exploited Vulnerabilities (KEV) Catalog: CISA's KEV catalog is a U.S. government companion to NVD, layering exploitation evidence on top of CVE records. It serves the same federal and critical infrastructure audience with prioritized, exploitation-driven vulnerability intelligence.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat3 records
Key risks5 records
Key highlights6 records
Customer concentration
National Vulnerability Database social profiles
Digital presenceNational Vulnerability Database financial estimates
Financial estimateRevenue estimate
Valuation estimate
National Vulnerability Database leadership team
Management profileNumber of profiles
Profiles1 record
National Vulnerability Database funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
National Vulnerability Database M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about National Vulnerability Database
What does National Vulnerability Database do?
The National Vulnerability Database (NVD) is the U.S. government repository of standards-based vulnerability management data, maintained by the National Institute of Standards and Technology (NIST). It provides structured vulnerability records, including Common Vulnerabilities and Exposures (CVE) identifiers, Common Vulnerability Scoring System (CVSS) severity scores, Common Weakness Enumeration (CWE) classifications, and Common Platform Enumeration (CPE) product mappings to support automated security management, measurement, and compliance.
Is National Vulnerability Database a public or private company?
National Vulnerability Database is a private company. It is classified as state government owned and is currently operating.
When was National Vulnerability Database founded?
National Vulnerability Database was founded in 2005.
Where is National Vulnerability Database based?
National Vulnerability Database is headquartered in Gaithersburg, United States, in the North America region.
How does National Vulnerability Database make money?
One revenue line is on record: public Government Service.
Who are National Vulnerability Database's main competitors?
MITRE Corporation is listed as a direct peer. Broad incumbents are Rapid7, Tenable, Snyk and Qualys. VulnCheck is listed as an emerging player. Regional players are JVN (Japan Vulnerability Notes) and CNNVD (China National Vulnerability Database). Others are GitHub Advisory Database and CISA Known Exploited Vulnerabilities (KEV) Catalog.
Does National Vulnerability Database have an API?
No public API is recorded for National Vulnerability Database.
What industry is National Vulnerability Database in?
National Vulnerability Database's product category is Vulnerability Management Database. Its primary akta.pro industry code is HDADAHAA, Vulnerability Assessment & Scanning, with a secondary code of HDADAHAF, Exposure Analytics & Risk-Based Prioritization (RBVM). Its NAICS code is 561621 and its SIC code is 7370.