Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Surge in submissions forces NIST to change how it handles CVEs. Here's what it means for vulnerability management.

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Henrik Plate
Word Count
782
Company Posts That Month
35
Language
English
Hacker News Points
-
Post removed?
No
Summary

NIST has announced a significant change in the operation of the National Vulnerability Database (NVD), focusing enrichment efforts on CVEs that meet specific prioritization criteria, including those in CISA's Known Exploited Vulnerabilities catalog and critical software as defined by Executive Order 14028. This shift is a response to the overwhelming increase in vulnerability disclosures, with a 263% rise in CVE submissions projected between 2020 and 2025. The rapid pace of vulnerability discoveries, driven by AI-powered tools, has led to a submission rate that threatens to outstrip current enrichment capacities. The security community has expressed concern over the impending funding freeze of the CVE program in 2025, as many CVEs, especially those affecting open source software, will lack CVSS scores and other essential enrichments. This development underscores the fragility of relying solely on government databases for vulnerability intelligence, prompting organizations like Endor Labs to adopt independent monitoring and enrichment processes using AI and automation to maintain comprehensive vulnerability tracking. The need for scalable AI-driven enrichment systems is emphasized, as the landscape of vulnerability discovery and management continues to evolve rapidly.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Coding Assistant 1 1,480 382 153 +18%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.