Developer docs
API playgroundTry for free, no card

Search company profiles

National Vulnerability Database

Full company profile

uuid02m2qn6

Namestring
National Vulnerability Database
Legal namestring
National Vulnerability Database
Websiteurl
nist.gov
Company typeenum
Private
Founded yearint
2005
Operating statusenum
Operating
Ownership categoryenum
akta.pro rankint
HeadquartersGaithersburg, United States
HQ citystring
Gaithersburg
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
vulnerability management, CVE database, cybersecurity standards, security metrics, compliance data
Industry2 codes
1Vulnerability Assessment & Scanning
CodeHDADAHAAPrimaryYes
2Exposure Analytics & Risk-Based Prioritization (RBVM)
CodeHDADAHAFPrimaryNo
NAICS code2 codes
  • Security Systems Services (except Locksmiths)561621
  • Security Systems Services56162
SIC code1 code
  • Services-Computer Programming, Data Processing, Etc.7370
Product category
Vulnerability Management Database
Social media profiles5 records
Revenue model1 record
1Public Government Service
TypeLicensing Royalties
Description

The NVD is a free, publicly available government resource maintained by NIST. It operates under the federal government mission to provide standards-based vulnerability management data to the public. There is no commercial revenue model as this is a government service provided for national cybersecurity benefit.

nist.gov
Marketing channels1 record

Each record includes

Title, Type, Stage, Description, Source

Distribution channels2 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components4 values
Personnel, Technology or R&D, Infrastructure, Operations
GTM typeB2B
B2B
Offering typeSoftware
Software
Core offering1 text field

The National Vulnerability Database (NVD) is the U.S. government repository of standards-based vulnerability management data, maintained by the National Institute of Standards and Technology (NIST). It provides structured vulnerability records, including Common Vulnerabilities and Exposures (CVE) identifiers, Common Vulnerability Scoring System (CVSS) severity scores, Common Weakness Enumeration (CWE) classifications, and Common Platform Enumeration (CPE) product mappings to support automated security management, measurement, and compliance.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 value
  • Authoritative source for vulnerability data used by security tools and government compliance frameworks
Product overview1 text field

The National Vulnerability Database (NVD) is a U.S. government-hosted repository of vulnerability management data maintained by NIST. It serves as the official source for vulnerability information in the national and international cybersecurity ecosystem. The NVD provides structured vulnerability records including CVE identifiers, severity scores (CVSS), affected products, and related references. It operates as a single, centralized database offering standardized vulnerability data for automated consumption, rather than as a commercial product with multiple modules or tiers.

Product and service3 records
1National Vulnerability Database (NVD)
CategoryVulnerability Management Database
Description

A comprehensive publicly available database of vulnerability management data, including CVE identifiers, CVSS severity scores, CWE weakness classifications, CPE product mappings, and security checklist references. Designed for federal agencies, cybersecurity professionals, and critical infrastructure operators to perform automated vulnerability management, security measurement, and compliance.

2NVD API
3NVD Data Feeds
CategoryVulnerability Data Feeds
Description

Downloadable data feeds providing machine-readable vulnerability data for integration into external security tools, vulnerability scanners, and compliance reporting systems.

Scale indicator3 records

Each record includes

Type, Value, Description, Source

Recent move3 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight3 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

MITRE operates the CVE program and several related security standards (CWE). As the upstream originator of the CVE identifiers that NVD enriches, MITRE is the closest functional peer and a direct collaborator in the vulnerability management data ecosystem.

TypeBroad incumbent
Description

Rapid7's InsightVM and Metasploit products ingest NVD feeds and serve vulnerability management use cases for the same enterprise security audience. It competes with NVD's standardization role via its own research and vulnerability prioritization.

TypeBroad incumbent
Description

Tenable (Nessus) is the leading commercial vulnerability management platform and one of the largest consumers and contributors to NVD's CPE/CVE data. It serves the same security teams with broader commercial vulnerability assessment capabilities.

TypeBroad incumbent
Description

Snyk focuses on developer-first vulnerability scanning (open source, containers, code) and maintains its own vulnerability database alongside NVD. It targets a related but more developer-centric slice of the same vulnerability intelligence market.

TypeBroad incumbent
Description

Qualys VMDR is a major enterprise vulnerability management platform that depends on NVD feeds for CVE matching and severity scoring, and addresses the same downstream use case of identifying and prioritizing vulnerabilities.

TypeEmerging player
Description

VulnCheck provides commercial, real-time, exploit-aware vulnerability intelligence that competes for the same downstream consumers (security teams, vulnerability management platforms) that integrate NVD data — a more agile, enriched alternative.

7JVN (Japan Vulnerability Notes)
TypeRegional player
Description

JVN is the Japanese national vulnerability database operated by JPCERT/CC. It serves a similar authoritative-vulnerability-intelligence role for Japanese software disclosures and parallels NVD's domestic-coordinator function.

TypeOthers
Description

GitHub's Advisory Database curates open source vulnerability information and is increasingly a first-publisher for many CVEs. It overlaps with NVD's role in open source vulnerability tracking and serves a related ecosystem of developers and security teams.

TypeOthers
Description

CISA's KEV catalog is a U.S. government companion to NVD, layering exploitation evidence on top of CVE records. It serves the same federal and critical infrastructure audience with prioritized, exploitation-driven vulnerability intelligence.

10CNNVD (China National Vulnerability Database)
TypeRegional player
Description

CNNVD is China's national vulnerability database, operated under CNCERT. It is the closest regional peer to NVD — performing the same authoritative vulnerability enumeration role for Chinese disclosures and serving Chinese government and critical infrastructure users.

Market position
Strengths4 records

Each record includes

Headline, Details, Source

Weaknesses4 records

Each record includes

Headline, Details, Source

Competitive moat3 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights6 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers3 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment3 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile3 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

AI maturity
App detail

Has app

Feature1 record

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles1 record

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

National Vulnerability Database

Vulnerability Management Databasenist.gov

National Vulnerability Database firmographics

Firmographics
Name
National Vulnerability Database
Legal name
National Vulnerability Database
Website
https://nist.gov
Company type
Private
Founded year
2005
Operating status
Operating
Ownership category
akta.pro rank

National Vulnerability Database industry classification

Industry
Product category
Vulnerability Management Database
NAICS
Security Systems Services (except Locksmiths) (561621), Security Systems Services (56162)
SIC
Services-Computer Programming, Data Processing, Etc. (7370)
akta.pro primary industry
Vulnerability Assessment & Scanning (HDADAHAA)
akta.pro secondary industry
Exposure Analytics & Risk-Based Prioritization (RBVM) (HDADAHAF)

Keywords

  • Vulnerability management
  • CVE database
  • Cybersecurity standards
  • Security metrics
  • Compliance data

Where National Vulnerability Database is headquartered

Location

Headquarters

HQ city
Gaithersburg
HQ country
United States
HQ region
North America

Offices1 record

Markets served

National Vulnerability Database business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Personnel, Technology or R&D, Infrastructure, Operations

Revenue model

  1. Public Government Service: The NVD is a free, publicly available government resource maintained by NIST. It operates under the federal government mission to provide standards-based vulnerability management data to the public. There is no commercial revenue model as this is a government service provided for national cybersecurity benefit.

Distribution channels2 records

Marketing channels1 record

National Vulnerability Database product offering

Product offering

Core offering

The National Vulnerability Database (NVD) is the U.S. government repository of standards-based vulnerability management data, maintained by the National Institute of Standards and Technology (NIST). It provides structured vulnerability records, including Common Vulnerabilities and Exposures (CVE) identifiers, Common Vulnerability Scoring System (CVSS) severity scores, Common Weakness Enumeration (CWE) classifications, and Common Platform Enumeration (CPE) product mappings to support automated security management, measurement, and compliance.

Product overview

The National Vulnerability Database (NVD) is a U.S. government-hosted repository of vulnerability management data maintained by NIST. It serves as the official source for vulnerability information in the national and international cybersecurity ecosystem. The NVD provides structured vulnerability records including CVE identifiers, severity scores (CVSS), affected products, and related references. It operates as a single, centralized database offering standardized vulnerability data for automated consumption, rather than as a commercial product with multiple modules or tiers.

Differentiator

Problem solved

Functional benefit

Products and services

  • National Vulnerability Database (NVD) A comprehensive publicly available database of vulnerability management data, including CVE identifiers, CVSS severity scores, CWE weakness classifications, CPE product mappings, and security checklist references. Designed for federal agencies, cybersecurity professionals, and critical infrastructure operators to perform automated vulnerability management, security measurement, and compliance.
  • NVD API
  • NVD Data Feeds Downloadable data feeds providing machine-readable vulnerability data for integration into external security tools, vulnerability scanners, and compliance reporting systems.

Quantifiable outcome

  • Authoritative source for vulnerability data used by security tools and government compliance frameworks

Companies that use National Vulnerability Database

Customer profile

Named customers3 records

Segments3 records

Ideal customer profiles3 records

National Vulnerability Database technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Feature1 record

National Vulnerability Database partnerships and signals

Strategic signal

Scale indicators3 records

Recent moves3 records

Expansion highlights3 records

National Vulnerability Database competitors and assessment

Company assessment

Direct peers

  • MITRE Corporation: MITRE operates the CVE program and several related security standards (CWE). As the upstream originator of the CVE identifiers that NVD enriches, MITRE is the closest functional peer and a direct collaborator in the vulnerability management data ecosystem.

Broad incumbents

  • Rapid7: Rapid7's InsightVM and Metasploit products ingest NVD feeds and serve vulnerability management use cases for the same enterprise security audience. It competes with NVD's standardization role via its own research and vulnerability prioritization.
  • Tenable: Tenable (Nessus) is the leading commercial vulnerability management platform and one of the largest consumers and contributors to NVD's CPE/CVE data. It serves the same security teams with broader commercial vulnerability assessment capabilities.
  • Snyk: Snyk focuses on developer-first vulnerability scanning (open source, containers, code) and maintains its own vulnerability database alongside NVD. It targets a related but more developer-centric slice of the same vulnerability intelligence market.
  • Qualys: Qualys VMDR is a major enterprise vulnerability management platform that depends on NVD feeds for CVE matching and severity scoring, and addresses the same downstream use case of identifying and prioritizing vulnerabilities.

Emerging players

  • VulnCheck: VulnCheck provides commercial, real-time, exploit-aware vulnerability intelligence that competes for the same downstream consumers (security teams, vulnerability management platforms) that integrate NVD data — a more agile, enriched alternative.

Regional players

  • JVN (Japan Vulnerability Notes): JVN is the Japanese national vulnerability database operated by JPCERT/CC. It serves a similar authoritative-vulnerability-intelligence role for Japanese software disclosures and parallels NVD's domestic-coordinator function.
  • CNNVD (China National Vulnerability Database): CNNVD is China's national vulnerability database, operated under CNCERT. It is the closest regional peer to NVD — performing the same authoritative vulnerability enumeration role for Chinese disclosures and serving Chinese government and critical infrastructure users.

Others

  • GitHub Advisory Database: GitHub's Advisory Database curates open source vulnerability information and is increasingly a first-publisher for many CVEs. It overlaps with NVD's role in open source vulnerability tracking and serves a related ecosystem of developers and security teams.
  • CISA Known Exploited Vulnerabilities (KEV) Catalog: CISA's KEV catalog is a U.S. government companion to NVD, layering exploitation evidence on top of CVE records. It serves the same federal and critical infrastructure audience with prioritized, exploitation-driven vulnerability intelligence.

Market position

Strengths4 records

Weaknesses4 records

Competitive moat3 records

Key risks5 records

Key highlights6 records

Customer concentration

National Vulnerability Database social profiles

Digital presence

National Vulnerability Database financial estimates

Financial estimate

Revenue estimate

Valuation estimate

National Vulnerability Database leadership team

Management profile

Number of profiles

Profiles1 record

National Vulnerability Database funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

National Vulnerability Database M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about National Vulnerability Database

What does National Vulnerability Database do?

The National Vulnerability Database (NVD) is the U.S. government repository of standards-based vulnerability management data, maintained by the National Institute of Standards and Technology (NIST). It provides structured vulnerability records, including Common Vulnerabilities and Exposures (CVE) identifiers, Common Vulnerability Scoring System (CVSS) severity scores, Common Weakness Enumeration (CWE) classifications, and Common Platform Enumeration (CPE) product mappings to support automated security management, measurement, and compliance.

Is National Vulnerability Database a public or private company?

National Vulnerability Database is a private company. It is classified as state government owned and is currently operating.

When was National Vulnerability Database founded?

National Vulnerability Database was founded in 2005.

Where is National Vulnerability Database based?

National Vulnerability Database is headquartered in Gaithersburg, United States, in the North America region.

How does National Vulnerability Database make money?

One revenue line is on record: public Government Service.

Who are National Vulnerability Database's main competitors?

MITRE Corporation is listed as a direct peer. Broad incumbents are Rapid7, Tenable, Snyk and Qualys. VulnCheck is listed as an emerging player. Regional players are JVN (Japan Vulnerability Notes) and CNNVD (China National Vulnerability Database). Others are GitHub Advisory Database and CISA Known Exploited Vulnerabilities (KEV) Catalog.

Does National Vulnerability Database have an API?

No public API is recorded for National Vulnerability Database.

What industry is National Vulnerability Database in?

National Vulnerability Database's product category is Vulnerability Management Database. Its primary akta.pro industry code is HDADAHAA, Vulnerability Assessment & Scanning, with a secondary code of HDADAHAF, Exposure Analytics & Risk-Based Prioritization (RBVM). Its NAICS code is 561621 and its SIC code is 7370.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
The Next WebChina's coding tools gain as Claude Code is flaggedChina's National Vulnerability Database flagged multiple versions of Claude Code as containing a back door that could send user locations and identifiers to remote servers without consent. Anthropic said the code was an experiment to prevent illicit model distillation and that its policy barred China-based users. Analysts expect Chinese developers to accelerate adoption of domestic coding tools like Trae, Qoder, and ZCode.Global TimesChina issues risk warning regarding OpenClaw application security in internet financial sectorChina's National Internet Finance Association (NIFA) issued a formal risk warning on Sunday urging financial institutions and consumers to guard against security vulnerabilities in OpenClaw, an open-source AI agent, citing risks of fund loss, data breaches, and transaction manipulation. The warning follows similar alerts from China's Ministry of Industry and Information Technology (MIIT), the National Vulnerability Database (NVDB), and the National Computer Network Emergency Response Technical Team (CNCERT), all highlighting that OpenClaw's default high system privileges and weak security configurations make it highly vulnerable to cyberattacks. Experts warn that for critical sectors like finance, these vulnerabilities could lead to leakage of core business data and trade secrets, or even paralyze entire business systems.Getastra35 Cyber Security Vulnerability Statistics, Facts In 2025A cybersecurity roundup compiles 30 vulnerability statistics for 2025, citing the National Vulnerability Database's 299,967 entries and 8,051 new listings in the first half. It notes 84% of companies have high-risk vulnerabilities fixable by a simple update, 60% of breaches stem from unpatched flaws, and 57% of attacks are phishing or social engineering.