Surge in submissions forces NIST to change how it handles CVEs. Here's what it means for vulnerability management.
Blog post from Endor Labs
NIST has announced a significant change in the operation of the National Vulnerability Database (NVD), focusing enrichment efforts on CVEs that meet specific prioritization criteria, including those in CISA's Known Exploited Vulnerabilities catalog and critical software as defined by Executive Order 14028. This shift is a response to the overwhelming increase in vulnerability disclosures, with a 263% rise in CVE submissions projected between 2020 and 2025. The rapid pace of vulnerability discoveries, driven by AI-powered tools, has led to a submission rate that threatens to outstrip current enrichment capacities. The security community has expressed concern over the impending funding freeze of the CVE program in 2025, as many CVEs, especially those affecting open source software, will lack CVSS scores and other essential enrichments. This development underscores the fragility of relying solely on government databases for vulnerability intelligence, prompting organizations like Endor Labs to adopt independent monitoring and enrichment processes using AI and automation to maintain comprehensive vulnerability tracking. The need for scalable AI-driven enrichment systems is emphasized, as the landscape of vulnerability discovery and management continues to evolve rapidly.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Coding Assistant | 1 | 1,480 | 382 | 153 | +18% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.