NVD Quietly Sweeps 100K+ CVEs Into a “Deferred” Black Hole -...
Blog post from Socket
The National Vulnerability Database (NVD) has begun designating over 100,000 pre-2018 Common Vulnerabilities and Exposures (CVEs) as "Deferred," indicating a halt in updating these older vulnerabilities with essential metadata such as CVSS scores and CWE classifications. This move, which has already reclassified 20,000 CVEs overnight, aims to clarify prioritization but has sparked concern and criticism from the security community due to a lack of transparency and the potential risk it poses by obscuring the true scale of unaddressed vulnerabilities. Critics argue that this reclassification reduces the apparent backlog without addressing underlying issues, leading to less comprehensive and reliable public data. As the NVD's role as a central source of vulnerability information becomes increasingly strained, security teams are urged to diversify their information sources and automate metadata enrichment to mitigate the operational risks associated with relying solely on NVD data.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.