The National Vulnerability Database (NVD) is a U.S. government project that was created to help individuals and companies research the automation of vulnerability management, along with other security and compliance goals. This database includes tabled information on different kinds of security threats and other factors in cybersecurity.


The National Vulnerability Database is a project of the Department of Homeland Security National Cyber Security Division/U.S. CERT. Users can access:

  • Searchable database of vulnerabilities
  • Checklists
  • Impact metrics
  • Relevant statistics

The National Vulnerability Database uses a protocol called Security Content Automation Protocol (SCAP). These solutions are intended to provide standardized and consistent models for automated vulnerability handling.

Reports have shown that the National Vulnerability Database itself has been hacked in the past, and that the project was briefly taken off-line in March of 2013.

Federal resources like these are part of a larger network of security standards and tools that developers and others use as they conduct a broader conversation about consistent and standardized security practices.


