# NVD

The National Vulnerability Database (NVD) is a U.S. government repository of vulnerability-management data covering software and hardware flaws, security misconfigurations, and related impact metrics.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## RBP Tracker: Counting the CVE IDs the CVE List Cannot See

DevFeed: [RBP Tracker: Counting the CVE IDs the CVE List Cannot See](<https://devfeed.tech/articles/rbp-tracker-counting-the-cve-ids-the-cve-list-cannot-see-27481.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2026/09/14/rbp-tracker-counting-the-cve-ids-the-cve-list-cannot-see/>)

Author: jgamblin

Published: 2026-09-14T14:16:42Z

Content type: article

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [NVD](<https://devfeed.tech/topics/nvd.md>), [API](<https://devfeed.tech/topics/api.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-list](<https://devfeed.tech/tags/cve-list.md>), [data](<https://devfeed.tech/tags/data.md>), [ids](<https://devfeed.tech/tags/ids.md>), [list](<https://devfeed.tech/tags/list.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [report](<https://devfeed.tech/tags/report.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [source](<https://devfeed.tech/tags/source.md>), [state](<https://devfeed.tech/tags/state.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>)

### AI overview

The article examines a corrected RogoLabs tracker for Reserved but Public CVE IDs. It explains that the CVE Services API returns 404 for reserved IDs, while a separate unauthenticated endpoint reveals their RESERVED state. The tracker lists IDs from public advisory feeds and describes how reserved records are absent from the bulk CVE List until publication.

### Source excerpt

A new RogoLabs site lists Reserved but Public CVE IDs: 2,315 of them on September 14, drawn from 17 public advisory feeds, refreshed every six hours, and held a week before they appear. The first version of this tracker reported that none of the CVE IDs it found existed in the CVE List, in any ... Read more

## Why Vulnerability Clearinghouses Alone Cannot Secure Open Source

DevFeed: [Why Vulnerability Clearinghouses Alone Cannot Secure Open Source](<https://devfeed.tech/articles/summer-of-clearinghouses-13244.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/summer-of-clearinghouses>)

Published: 2026-07-05T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [NVD](<https://devfeed.tech/topics/nvd.md>), [Unix](<https://devfeed.tech/topics/unix.md>)

Tags: [akrites](<https://devfeed.tech/tags/akrites.md>), [athena](<https://devfeed.tech/tags/athena.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [data](<https://devfeed.tech/tags/data.md>), [ibm-red-hat-project-lightwell](<https://devfeed.tech/tags/ibm-red-hat-project-lightwell.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [press-release](<https://devfeed.tech/tags/press-release.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [vulnerability-clearinghouse](<https://devfeed.tech/tags/vulnerability-clearinghouse.md>), [vulnerability-data](<https://devfeed.tech/tags/vulnerability-data.md>)

### AI overview

The article argues that vulnerability clearinghouses are primarily pools of data and are not the most important part of securing open source. It emphasizes actuation--turning findings into fixes--along with trusted builds and secure-by-design software.

### Source excerpt

Clearinghouses alone won't secure open source. Learn why actuation, trusted builds, and secure-by-design software matter more than vulnerability data.

## CNAScorecard.org Measures CVE Data Quality and Completeness

DevFeed: [CNAScorecard.org Measures CVE Data Quality and Completeness](<https://devfeed.tech/articles/a-new-era-of-transparency-for-cve-data-quality-27474.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2025/08/14/a-new-era-of-transparency-for-cve-data-quality/>)

Author: jgamblin

Published: 2025-08-14T00:43:12Z

Content type: opinion

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [Data Quality](<https://devfeed.tech/topics/data-quality.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [NVD](<https://devfeed.tech/topics/nvd.md>)

Tags: [alert-fatigue](<https://devfeed.tech/tags/alert-fatigue.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-data](<https://devfeed.tech/tags/cve-data.md>), [data-quality](<https://devfeed.tech/tags/data-quality.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article introduces CNAScorecard.org, a public scorecard intended to measure the quality and completeness of CVE data supplied by CVE Numbering Authorities. It describes missing or incomplete weakness, product, severity, and fix information as a practical vulnerability-management problem, and connects the effort to the NVD backlog.

### Source excerpt

I'm incredibly excited to finally share something I've been pouring my heart into at RogoLabs. For those of you who caught my talk at BSidesLV, you got a sneak peek, but today it's official: CNAScorecard.org is live! For years, the CVE program has been our shared language for identifying vulnerabilities. But lately, we've all felt ... Read more

## Get Smart in Five Minutes: What is a CVE and why care?

DevFeed: [Get Smart in Five Minutes: What is a CVE and why care?](<https://devfeed.tech/articles/get-smart-in-five-minutes-what-is-a-cve-and-why-care-13063.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/get-smart-in-five-minutes-what-is-a-cve-and-why-care>)

Published: 2024-08-08T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [NVD](<https://devfeed.tech/topics/nvd.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [exploit chaining](<https://devfeed.tech/topics/exploit-chaining.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [exploit-chaining](<https://devfeed.tech/tags/exploit-chaining.md>), [get-smart-in-five-minutes](<https://devfeed.tech/tags/get-smart-in-five-minutes.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [updates](<https://devfeed.tech/tags/updates.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This beginner-friendly article explains what Common Vulnerabilities and Exposures (CVEs) are, why their unique identifiers matter, and how they affect software supply chain security. It covers the CVE lifecycle, the role of the National Vulnerability Database, severity ratings, patching, and exploit chaining.

### Source excerpt

Learn the basics of CVEs, why they matter for cybersecurity, and how to stay protected in this quick teaser of the Get Smart series by Chainguard.

## NVD updates: CVSS v4.0, CISA data, and more

DevFeed: [NVD updates: CVSS v4.0, CISA data, and more](<https://devfeed.tech/articles/nvd-updates-cvss-v4-0-cisa-data-and-more-13192.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/nvd-updates-cvss-v4-0-cisa-data-and-more>)

Published: 2024-07-10T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [NVD](<https://devfeed.tech/topics/nvd.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [cisa](<https://devfeed.tech/tags/cisa.md>), [cvss-v4-0](<https://devfeed.tech/tags/cvss-v4-0.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [github](<https://devfeed.tech/tags/github.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnrichment](<https://devfeed.tech/tags/vulnrichment.md>)

### AI overview

The article explains recent updates to the National Vulnerability Database, including its integration of CISA's Vulnrichment project and enriched CVSS and CWE data. It describes how more complete vulnerability information can help security scanners and teams prioritize and manage vulnerabilities.

### Source excerpt

Learn about the NVD's recent updates, including CISA Vulnrichment data, CVSS v4.0 integration, and how they impact your vulnerability management workflow.

## Vulnerability fixes in plain sight: How your scanners are missing hundreds of vulnerabilities

DevFeed: [Vulnerability fixes in plain sight: How your scanners are missing hundreds of vulnerabilities](<https://devfeed.tech/articles/vulnerability-fixes-in-plain-sight-how-your-scanners-are-missing-hundreds-of-vulnerabilities-13312.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/vulnerability-fixes-in-plain-sight-how-your-scanners-are-missing-hundreds-of-vulnerabilities>)

Published: 2024-06-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [NVD](<https://devfeed.tech/topics/nvd.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-list](<https://devfeed.tech/tags/cve-list.md>), [cves](<https://devfeed.tech/tags/cves.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [remote-code-execution-vulnerability](<https://devfeed.tech/tags/remote-code-execution-vulnerability.md>), [research](<https://devfeed.tech/tags/research.md>), [sca](<https://devfeed.tech/tags/sca.md>), [security](<https://devfeed.tech/tags/security.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-fix](<https://devfeed.tech/tags/vulnerability-fix.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

An analysis of more than 600 Wolfi-packaged projects found over 100 security fixes without associated CVEs. Because vulnerability scanners and SCA tools rely on vulnerability databases such as the NVD, organizations may miss fixes unless they keep software updated.

### Source excerpt

Are your vulnerability scanners missing critical security flaws? Discover how Chainguard's research reveals hundreds of vulnerabilities hiding in plain sight.

## Software Bill of Materials

DevFeed: [Software Bill of Materials](<https://devfeed.tech/articles/software-bill-of-materials-13961.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/software-bill-of-materials/>)

Author: John Lee

Published: 2023-11-02T00:00:00Z

Content type: tutorial

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [ESP-IDF](<https://devfeed.tech/topics/esp-idf.md>), [Espressif](<https://devfeed.tech/topics/espressif.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [NVD](<https://devfeed.tech/topics/nvd.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [esp-idf](<https://devfeed.tech/tags/esp-idf.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [espressif](<https://devfeed.tech/tags/espressif.md>), [iot](<https://devfeed.tech/tags/iot.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [tools](<https://devfeed.tech/tags/tools.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article introduces software bills of materials (SBOMs), explains their structure and formats such as SPDX and CycloneDX, and presents Espressif's ESP-IDF-SBOM tool. The tool generates SPDX SBOMs for ESP-IDF-based applications and checks them against the National Vulnerability Database for known vulnerabilities.

### Source excerpt

Overview# The "software bill of materials" (SBOM) has emerged as a key building block in software security and software supply chain risk management. An SBOM is a comprehensive list of all the software components, dependencies, and metadata associated with an application. Espressif believes that this information is a key step towards ensuring the security of the connected devices. And as such, we have now enabled easy to use tools and solutions to track and analyze this information.

## How "junk CVEs" can misclassify ordinary bugs as vulnerabilities

DevFeed: [How "junk CVEs" can misclassify ordinary bugs as vulnerabilities](<https://devfeed.tech/articles/the-unmasking-of-the-phantom-s-masquerade-when-junk-cves-reveal-their-true-nature-13275.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-unmasking-of-the-phantoms-masquerade-when-junk-cves-reveal-their-true-nature>)

Published: 2023-10-17T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [NVD](<https://devfeed.tech/topics/nvd.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [code](<https://devfeed.tech/tags/code.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [developer](<https://devfeed.tech/tags/developer.md>), [false-negative](<https://devfeed.tech/tags/false-negative.md>), [false-positive](<https://devfeed.tech/tags/false-positive.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article explains the concept of "junk CVEs," in which scanners report ordinary bugs as vulnerabilities. Through a fictional Halloween story, it describes how maintainers may dispute these reports and promotes Chainguard Images as a way to reduce reported vulnerabilities.

### Source excerpt

Unveil 'junk CVEs' with Chainguard Images, your ally against disguised vulnerabilities, ensuring a secure codebase this Halloween.

## Fuzzy CVEs, tarfiles, and untrusted input

DevFeed: [Fuzzy CVEs, tarfiles, and untrusted input](<https://devfeed.tech/articles/fuzzy-cves-tarfiles-and-untrusted-input-13056.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fuzzy-cves-tarfiles-and-untrusted-input>)

Published: 2023-07-27T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [common vulnerabilities and exposures](<https://devfeed.tech/topics/common-vulnerabilities-and-exposures.md>), [Python](<https://devfeed.tech/topics/python.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [NVD](<https://devfeed.tech/topics/nvd.md>)

Tags: [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [go](<https://devfeed.tech/tags/go.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [python](<https://devfeed.tech/tags/python.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

This article examines CVE-2007-4559 in Python's tarfile module, why the 15-year-old issue may still appear in security scanners, and why its classification as a vulnerability is disputed. It discusses CVE processes, NVD entries, open-source maintainer constraints, and the risks of extracting untrusted tarfile inputs.

### Source excerpt

Navigate fuzzy CVEs, tarfiles, and untrusted input with Chainguard, paving the way to secure coding practices.