Home / Companies / Socket / Blog / Post Details
Content Deep Dive

The Alarming NVD Backlog: Over 50% of Known Exploited Vulner...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
758
Company Posts That Month
20
Language
English
Hacker News Points
-
Post removed?
No
Summary

The National Vulnerability Database (NVD) is experiencing a significant backlog, with over 12,500 Common Vulnerabilities and Exposures (CVEs) awaiting analysis and more than 50% of known exploited vulnerabilities (KEVs) left unenriched since February 2024. This situation has prompted criticism and concerns over the reliability and trust in the NVD, as highlighted by a VulnCheck report which shows that a majority of serious threats remain unanalyzed. The National Institute of Standards and Technology (NIST), responsible for the NVD, has stated its focus on prioritizing the most significant vulnerabilities and is exploring long-term solutions with agency partners. In response to the backlog, the Cybersecurity and Infrastructure Security Agency (CISA) introduced the Vulnrichment project to enhance CVE records, but this has also led to a more fragmented approach requiring organizations to rely on multiple data sources. The evolving landscape suggests a potential shift towards a decentralized model, possibly aligning with an organic consortium approach, as NIST navigates transitioning its processes and infrastructure.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.